Skip to content

The 15 PingOne security checks Black Cat runs

Black Cat SSPM evaluates 15 security policies against your PingOne configuration on every scan, classifies each finding by risk, and provides remediation steps. Below is the full list, grouped by category.

authentication

highSign-On Policy Without MFA

Require MFA in the PingOne sign-on (authentication) policy

highDefault Sign-On Policy Without MFA

Require MFA in the environment-default PingOne sign-on policy

identity

lowDisabled User Still Present

Remove or review disabled PingOne accounts that remain provisioned

mediumDormant User

Disable or remove PingOne accounts that have never signed on or are long-inactive

infoEmpty Group

Review or remove PingOne groups with no members

mfa

highUser Without MFA

Enforce MFA enrollment for PingOne users

highEnvironment MFA Disabled

Enable MFA at the PingOne environment level

oauth

highApplication Risky Grant Type

Remove implicit and ROPC (password) grant types from PingOne applications

mediumApplication Public Client Without Auth

Require client authentication on confidential PingOne applications

mediumApplication Wildcard Redirect URI

Replace wildcard and insecure redirect URIs with exact HTTPS URIs

lowDisabled Application Still Present

Remove stale disabled PingOne application registrations

password policy

mediumWeak Password Policy

Strengthen the PingOne password policy minimum length

mediumPassword Policy Without History

Enable password history to prevent reuse in PingOne

lowPassword Policy Without Expiry

Review password expiry settings against your password rotation policy

mediumPassword Policy Low Complexity

Require multiple character classes in the PingOne password policy

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial