PingOne identity, MFA & sign-in security checks
Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
On PingOne, Black Cat runs 11 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the PingOne connector needs.
Checks (11)
severity: high User Without MFA fix difficulty: medium #
Enforce MFA enrollment for PingOne users
- Open the PingOne admin console > Identities > Users and select the flagged user
- Confirm the environment MFA policy requires enrollment
- Enroll the user in an MFA device (or require enrollment at next sign-on)
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: low Disabled User Still Present fix difficulty: easy #
Remove or review disabled PingOne accounts that remain provisioned
- Open PingOne admin console > Identities > Users and filter by disabled accounts
- Confirm the account is intentionally retained (e.g. legal hold)
- Delete or fully offboard accounts no longer needed
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: medium Dormant User fix difficulty: easy #
Disable or remove PingOne accounts that have never signed on or are long-inactive
- Open PingOne admin console > Identities > Users and sort by last sign-on
- Review accounts that have never signed on or are inactive past your threshold
- Disable or offboard as appropriate
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: info Empty Group fix difficulty: easy #
Review or remove PingOne groups with no members
- Open PingOne admin console > Identities > Groups and select the flagged group
- Confirm the group is intentional (e.g. a placeholder) or remove it
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: medium Weak Password Policy fix difficulty: easy #
Strengthen the PingOne password policy minimum length
- Open PingOne admin console > Authentication > Password Policies
- Set minimum length to 12 or more characters
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Password Policy Without History fix difficulty: easy #
Enable password history to prevent reuse in PingOne
- Open PingOne admin console > Authentication > Password Policies
- Set a non-zero password history (prior-password) count
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: low Password Policy Without Expiry fix difficulty: easy #
Review password expiry settings against your password rotation policy
- Open PingOne admin console > Authentication > Password Policies
- Decide whether forced rotation is appropriate for your framework
- Set a maximum password age if rotation is required
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Password Policy Low Complexity fix difficulty: easy #
Require multiple character classes in the PingOne password policy
- Open PingOne admin console > Authentication > Password Policies
- Require at least three character classes (upper, lower, digit, special)
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high Sign-On Policy Without MFA fix difficulty: medium #
Require MFA in the PingOne sign-on (authentication) policy
- Open PingOne admin console > Authentication > Policies
- Edit the policy to require an MFA step
- Assign the MFA-enforcing policy to applications
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high Default Sign-On Policy Without MFA fix difficulty: medium #
Require MFA in the environment-default PingOne sign-on policy
- Open PingOne admin console > Authentication > Policies
- Edit the default policy to require an MFA step
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high Environment MFA Disabled fix difficulty: medium #
Enable MFA at the PingOne environment level
- Open PingOne admin console > Authentication > MFA
- Enable MFA and configure allowed device types
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4