Prepare for Single Sign-On (SSO) > PingFederate Configuration
  
PingFederate Configuration
* 
Do not change any of the PingFederate configuration options you previously selected for ThingWorx.
The configuration described in this section must be performed in PingFederate after installing and configuring the ThingWorx server for SSO and prior to installing and configuring the Experience Service. These configuration changes will be made to the same PingFederate instance that was installed when you configured the ThingWorx server to use SSO.
* 
We recommend that you are running PingFederate 11 or later. While an Experience Service will work with PingFederate 9.3.3, we do no recommend it, as PingFederate has discontinued security support for it as of June 2022.
Complete the following steps to configure PingFederate.
1. Identify values for SSO configuration parameters.
2. Enable OpenID Connect.
3. Configure OpenID Policy.
4. Configure Scopes.
5. Configure the Experience Service client.
6. Configure the Vuforia Studio client.
7. Configure the ThingWorx client.
8. Configure trust for the PingFederate certificate for Vuforia Studio and Vuforia View.
9. Manage sessions.