Skip to content

PingOne third-party & OAuth apps security checks

OAuth grants, marketplace apps, integrations, plugins and automations with standing access to company data — the SaaS-to-SaaS supply chain.

On PingOne, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the PingOne connector needs.

Checks (4)

severity: high Application Risky Grant Type fix difficulty: medium #

Remove implicit and ROPC (password) grant types from PingOne applications

  1. Open PingOne admin console > Applications and select the flagged app
  2. In the OIDC/OAuth settings, remove the Implicit and Password grant types
  3. Migrate to Authorization Code with PKCE

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-9.12

severity: medium Application Public Client Without Auth fix difficulty: medium #

Require client authentication on confidential PingOne applications

  1. Open PingOne admin console > Applications and select the flagged app
  2. Set a token endpoint authentication method other than NONE for confidential apps

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-9.12

severity: medium Application Wildcard Redirect URI fix difficulty: easy #

Replace wildcard and insecure redirect URIs with exact HTTPS URIs

  1. Open PingOne admin console > Applications and select the flagged app
  2. Replace wildcard (*) and non-localhost http:// redirect URIs with exact https:// URIs

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-9.12

severity: low Disabled Application Still Present fix difficulty: easy #

Remove stale disabled PingOne application registrations

  1. Open PingOne admin console > Applications and filter by disabled apps
  2. Confirm the registration is no longer needed
  3. Delete the application to reduce attack surface

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-9.12

More PingOne checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial