Cross-Service Access Reviews with PingOne
Step-by-step configuration for access reviews spanning PingOne and other integrated systems
Overview
This guide shows how to configure access reviews that span PingOne and other integrated systems using cross-service identity mapping.
For background on PingOne's cross-service capabilities, see PingOne Cross-Service Identity Mapping.
Prerequisites
PingOne integration configured and extracting data
Target systems (Azure AD, applications, databases) integrated and extracting data
Custom Identity Mappings configured between systems
Identity correlation verified and working
Review Configuration Examples
Azure AD Users to PingOne Applications
Review Scope: Azure AD users and their access to PingOne applications
Navigate to Access Reviews → Create New Configuration
Query Builder:
Source: Azure AD User
Destination: PingOne User
Filters: Apply department, location, or other attribute filters as needed
Reviewers: Assign application owners or managers
Save and launch review
PingOne Users to Downstream Applications
Review Scope: PingOne users and their access to mapped downstream systems
Access Reviews → Create New Configuration
Query Builder:
Source: PingOne User
Destination: Target application (Snowflake, AWS IAM, etc.)
Filters: Filter by PingOne groups or user attributes if needed
Reviewers: Assign based on downstream application ownership
Save and launch review
Cross-Service Group Membership
Review Scope: User membership in mapped groups across systems
Access Reviews → Create New Configuration
Query Builder:
Source: Azure AD User
Destination: PingOne Group
Relationship: Optionally specify group types or patterns
Reviewers: Assign group owners or IT administrators
Save and launch review
Last updated
Was this helpful?