Skip to content
Notifications
Clear all

Migrated from Azure AD to Ping Identity for a federal contractor - challenges

1 Posts
1 Users
0 Reactions
50 Views
(@code_weaver_max)
Reputable Member
Joined: 4 months ago
Posts: 370
Topic starter   [#19772]

Just finished a major IAM migration for a federal contractor client (DoD IL4 environment). We moved their workforce identities from Azure AD to Ping Identity (PingOne and PingFederate). While the end state is solid, the journey had some... *character-building* moments. Sharing here for anyone considering a similar path, especially under compliance frameworks.

The core technical challenge was replicating the "batteries-included" feel of Azure AD. For example, we had to build a custom SCIM connector for their legacy HRIS, as the out-of-box one didn't map some custom attributes needed for group provisioning. Ping's APIs are robust, but it meant writing more glue code than anticipated.

```python
# Simplified snippet of our custom SCIM user processing logic
def transform_to_scim(hr_user):
"""Maps custom HR fields to PingOne SCIM schema + custom extension"""
scim_user = {
"userName": hr_user["email"],
"name": {
"givenName": hr_user["first"],
"familyName": hr_user["last"]
},
"urn:ietf:params:scim:schemas:extension:custom:2.0:User": {
"clearanceLevel": hr_user["clearance_code"], # Custom attr
"contractorId": hr_user["contract_number"]
}
}
# Group assignment logic based on clearance and contract
scim_user["groups"] = assign_entitlements(hr_user)
return scim_user
```

Other key hurdles:
* **Session Management:** Configuring PingFederate for step-up authentication (MFA for sensitive apps) required very precise adapter and policy configuration. The policy trees are powerful but complex.
* **Developer Onboarding:** Moving from Microsoft's ecosystem meant our devs lost the seamless Visual Studio/Azure AD integration. We had to standardize on OIDC with Ping, creating detailed guides for local testing with Ping's SDK.
* **Cost Surprise:** Not the licensing, but the operational lift. We needed a dedicated FTE for the first 3 months for fine-tuning policies, logging, and troubleshooting SSO integrations that were "one-click" in Azure.

Overall, the control and flexibility are now huge assets for their compliance needs. The policy engine is unmatched. But the migration was a stark reminder that moving from a monolithic cloud provider to a best-of-breed suite shifts integration work from the vendor to your team. Plan your sprints accordingly!

Would love to hear from others who've made this switch—especially on managing hybrid environments (Ping + remaining Azure resources). How did you handle conditional access policies?

-- Weave


Prompt engineering is the new debugging


   
Quote