> For the complete documentation index, see [llms.txt](https://docs.keeper.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.keeper.io/sso-connect-cloud/jp/identity-provider-setup/pingone.md).

# PingOne

{% hint style="success" %}
最初に[管理コンソールの設定](/sso-connect-cloud/jp/admin-console-configuration.md)の手順を完了してください。PingOneを使用していない従来のPing Identityユーザーは、[Ping Identityのドキュメント](/sso-connect-cloud/jp/identity-provider-setup/ping-identity-keeper.md)をご参照ください。
{% endhint %}

### PingOne

PingOneポータル (<https://admin.pingone.com/>) にログインします。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2Fy7LxL1zk69eHMS2v59ln%2Fimage.png?alt=media&#x26;token=5bd4bc0f-8ea1-4edc-abcc-dac8d6595547" alt=""><figcaption><p>PingOneにログイン</p></figcaption></figure>

**PingOne** コンソールメニューから、**\[Applications]** > **\[Application Catalog]** を選択します。

「**Keeper**」を検索し、**Keeper Password Manager - Cloud SSO**リンクをクリックして**Keeper Password Manager**アプリケーションを追加します。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2Feehk83wLYjvAQgWzO7Dd%2Fimage.png?alt=media&#x26;token=9ae9b3b3-57f4-4f8a-9fda-56fa1760ec65" alt=""><figcaption><p>PingOneにKeeper Password Managerを追加</p></figcaption></figure>

**\[Setup]** をクリックして以下の手順に進みます。

**\[Continue to Next Step]** をクリックします。

**Keeper管理コンソール**で、PingOne用のクラウドSSOコネクトエントリーを表示し、**\[Export Metadata]** をクリックして安全な場所に保存します。**\[Export SP Cert]** もクリックし、`.crt` ファイルを保存します。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2FlkWKfiIDdh4SRaPuZ1h0%2Fimage.png?alt=media&#x26;token=2452a42a-e0a9-44aa-825a-18c4a60e0224" alt=""><figcaption><p>Keeper管理コンソールでメタデータとSP証明書をエクスポート</p></figcaption></figure>

PingOne管理コンソールで、**Upload Metadata** の横の **\[Select File]** をクリックし、**Keeper管理コンソール**から保存したメタデータファイルを参照します。これにより **ACS URL** と **Entity ID** フィールドが自動入力されます。

**Primary Verification Certificate** の横の **\[Choose File]** をクリックし、保存した `.crt` ファイルを参照します。**Encrypt Assertion** のチェックボックスをオンにし、**Encryption Certificate** の横の **\[Choose File]** をクリックして同じ `.crt` ファイルを参照します。

証明書を検証し、**\[Continue to Next Step]** をクリックします。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2FcLfvAHIjM1OuNcVqRWj0%2Fimage.png?alt=media&#x26;token=6cbbd8b7-08d6-4a49-b4c3-3bd7879df195" alt=""><figcaption><p>PingOneにKeeperメタデータと証明書をアップロード</p></figcaption></figure>

各属性に適切な値を入力し (下の画像を参照)、**\[Continue to Next Step]** をクリックします。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2FUdKrofgdJKXq3ufIjMpg%2Fimage.png?alt=media&#x26;token=761db347-1288-45a2-816a-ada05f85eb10" alt=""><figcaption><p>属性を設定</p></figcaption></figure>

**Name** を **Keeper管理コンソール**の SSO ノードの構成名に合わせて変更し、**\[Continue to Next Step]** をクリックします。

必要に応じて PingOne ユーザーグループをアプリケーションに追加します。追加するグループの横の **\[Add]** をクリックし、**\[Continue to Next Step]** をクリックします。

{% hint style="info" %}
PingOneユーザーは、デフォルトでKeeper Password Managerにアクセスできます。Keeper Password Managerにグループを割り当てると、アクセスをそのグループに限定できます。
{% endhint %}

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2FatpCxqjSj8GQWA0A0UGd%2Fimage.png?alt=media&#x26;token=36e995b8-642b-4b60-8e58-670c92a363bf" alt=""><figcaption><p>必要に応じてPingOneユーザーグループを追加</p></figcaption></figure>

**SAML Metadata** の横の **\[Download]** をクリックし、`.xml` ファイルを安全な場所に保存します。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2Fm2JJ0kQwIL4sg5tHZKZY%2Fimage.png?alt=media&#x26;token=878c75bd-b7cf-44ec-881c-058b97db9d9e" alt=""><figcaption><p>PingOneからメタデータをダウンロード</p></figcaption></figure>

**\[Finish]** をクリックしてアプリケーションのセットアップウィザードを完了します。

**Keeper管理コンソール**のクラウドSSOコネクトプロビジョニングの **\[Edit Configuration]** 画面で、**IDP Type** に **\[PingOne]** を選択します。

前の手順でダウンロードした SAML メタデータファイルを参照するか、**\[SAML Metadata]** セクションにドラッグアンドドロップして、Keeper SSOコネクトインターフェースにアップロードします。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2FjnuQULrZsdHhhJJNLBwH%2Fimage.png?alt=media&#x26;token=d096c054-62bf-4191-9d5e-6ef6ad52923d" alt=""><figcaption><p>PingOneのメタデータをKeeperにアップロード</p></figcaption></figure>

PingOne用の KeeperクラウドSSOコネクトエントリーが **\[Active]** と表示されます。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2Fbz0rKkKASr7Ve9nH0MZP%2Fimage.png?alt=media&#x26;token=3a4f1096-f458-431f-959f-03a73a16dd5b" alt=""><figcaption><p>Activeと表示されたKeeper SSOコネクトエントリー</p></figcaption></figure>

PingOne用KeeperクラウドSSOコネクトの設定が完了しました。

#### 既存のユーザー/初期管理者をSSO認証に移行

ルートノード (最上位) で作成されたユーザーは、SSOが設定されたサブノードに移行する必要があります。ユーザーがルートノードに残っている場合、ボルトや管理コンソールにアクセスする際にマスターパスワードの入力を求められます。

{% hint style="warning" %}
管理者は、SSOが有効になっているノードに自分自身を移動できません。この操作を行うには別の管理者が必要となります。
{% endhint %}

ユーザーがSSO対応ノードに移動した後、最初に **\[法人SSOログイン]** のプルダウンからSSO統合で設定した法人ドメインを入力し、Keeperボルトにログインする必要があります。また、マスターパスワード入力による確認を求められる場合があります。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2FbFfZY4rbYjOifBvaah9Y%2FJP_EG_EnterpriseSsoLogin1.png?alt=media&#x26;token=3c39d50f-e749-4a05-8883-9afa927613f1" alt=""><figcaption><p>まず[法人SSOログイン]を選択</p></figcaption></figure>

SSOで認証されると、それ以降はメールアドレスだけでSSO認証を開始できます。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2FoaGsiuYsApEp4F3pzZDj%2FJP_EG_EnterpriseSsoLogin2.png?alt=media&#x26;token=f8c42ae7-f133-4690-bcbf-6c8e6b539eca" alt=""><figcaption></figcaption></figure>

法人ドメインの入力は不要です。メールアドレスを入力して **\[次へ]** をクリックしても目的のSSOにルーティングされない場合は、Keeper SSO設定でジャストインタイムプロビジョニングが有効になっていることと、メールドメインがKeeperによって予約されていることを確認してください。ルーティングとドメイン予約について詳しくは、[こちら](/enterprise-guide/jp/domain-reservation.md)をご参照ください。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.keeper.io/sso-connect-cloud/jp/identity-provider-setup/pingone.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
