Identity & Access ManagementPing Identity

Ping Identity Platform (PingOne and PingFederate) Review 2026

4.3/ 5.0 from 1,480 verified reviews
Vendor
Ping Identity Holding Corp. (Thoma Bravo)
Pricing
Per user / month, from $3 (PingOne Workforce Essential)
Deployment
Cloud (PingOne) and On-Premise (PingFederate)
Best For
Large enterprises with on-premises federation and CIAM needs
Industries
Banking, insurance, telecom, healthcare, government
Implementation
3–12 months typical

Overview

Ping Identity provides a hybrid identity platform spanning the PingOne cloud service and the long-standing PingFederate, PingAccess, and PingDirectory on-premises products. Following Thoma Bravo's 2022 take-private and the 2023 ForgeRock acquisition, Ping is positioned as the principal enterprise alternative to Microsoft Entra ID and Okta for organisations that require deep federation, customer identity at scale, and the ability to run identity services in their own infrastructure or VPC.

Ping is the default choice for banks, insurers, and government agencies that already run PingFederate for SAML and OIDC federation and need a managed cloud overlay. The PingOne service offers SSO, MFA, risk evaluation, and identity verification, while PingOne Advanced Identity Cloud (the former ForgeRock platform) targets very large CIAM deployments. The platform is commonly chosen when other suites cannot meet data residency, customisation, or transaction-volume requirements.

Key Features

  • PingFederate SAML, OIDC, OAuth, and WS-Fed federation server
  • PingOne cloud SSO and MFA delivered as multi-tenant SaaS
  • PingID adaptive MFA with risk policies and device posture
  • PingDirectory high-performance LDAP and SCIM directory
  • PingAccess web access gateway for header-based and API authentication
  • PingOne DaVinci no-code orchestration for identity journeys
  • PingOne Verify identity proofing with document and biometric checks
  • PingOne Fraud behavioural risk detection
  • PingOne Authorize policy decision point for dynamic authorisation
  • PingOne Advanced Identity Cloud (formerly ForgeRock) for large CIAM
  • Self-hosted, single-tenant cloud, and multi-tenant cloud deployment options
  • FIDO2 passkey and certificate-based authentication

Pricing

EditionModelTypical Cost
PingOne for Workforce EssentialPer user / month$3 (5,000-user minimum)
PingOne for Workforce PlusPer user / month$6
PingOne for CustomersAnnual subscriptionFrom $35K / year (MAU-based)
PingFederate self-hostedAnnual licenceCustom quote

Pricing verified from pingidentity.com May 2026. Workforce SKUs require an annual contract with a 5,000-user minimum on Essential. Customer identity pricing is based on monthly active users and selected modules.

Strengths

  • Deepest federation feature set in the market; PingFederate is widely embedded in financial services
  • Hybrid deployment model supports on-premises, single-tenant cloud, and multi-tenant cloud
  • PingOne DaVinci provides a no-code orchestration layer that is among the best for complex identity journeys
  • Combined with ForgeRock, Ping now covers the largest CIAM deployments in banking and telecom
  • Strong support for regulated industries with FedRAMP and FAPI compliance

Limitations

  • Pre-built SSO app catalogue is smaller than Okta's, requiring more custom federation work
  • Pricing model is opaque and minimums make Ping unsuitable for organisations under 1,000 users
  • Integration between PingOne and the former ForgeRock platform is still in progress as of 2026
  • Implementation typically requires Ping-certified consultants, increasing total cost of ownership
  • Administrative UX is split across several consoles (PingOne, PingFederate admin, ForgeRock console)

Alternatives

Better pre-built SaaS catalogue and developer experience
4.4
Default option for Microsoft 365 estates
4.5
Stronger developer experience for B2C and B2B SaaS
4.4
Pair with Ping for deep governance
4.3
Modern IGA stack often deployed alongside Ping
4.2

Compare Ping Identity Platform

Ping Identity vs Okta → Ping Identity vs Entra ID → Ping Identity vs Auth0 →

Frequently Asked Questions

What happened to ForgeRock after the Ping acquisition?
ForgeRock was acquired by Thoma Bravo in August 2023 and combined with Ping Identity. The former ForgeRock Identity Platform is now sold as PingOne Advanced Identity Cloud. Ping has committed to maintaining the on-premises ForgeRock stack and is gradually unifying admin consoles and shared services.
Should we run PingFederate on-premises or use PingOne in the cloud?
Most new deployments use the PingOne cloud service for workforce SSO and reserve PingFederate on-premises for federation scenarios that require co-location with legacy directories or strict data residency. Many customers run both, with PingFederate as a downstream IdP federated into PingOne.
Is Ping a good fit for organisations under 1,000 users?
Not typically. PingOne for Workforce has a 5,000-user minimum on the Essential tier, and the platform's enterprise feature set tends to be over-specified for small estates. JumpCloud, OneLogin, or Entra ID are usually a better fit below 1,000 users.
How does PingOne DaVinci compare with Okta Workflows?
PingOne DaVinci is purpose-built for identity journey orchestration with a node-based visual editor, while Okta Workflows is a more general-purpose no-code automation engine. DaVinci tends to be stronger for complex multi-step authentication and registration flows; Workflows is broader for everyday IT automation.
Last updated: May 2026
Last updated: