PingOne Advanced Identity Cloud is Ping Identity’s single-tenant software-as-a-service identity platform, which Ping Identity says is the new name for the ForgeRock Identity Cloud.[10] Ping Identity’s licensing guide describes it together with PingOne Advanced Services as single-tenant SaaS offerings, in contrast to the multi-tenant PingOne platform.[1] By default a customer receives a dedicated tenant with three environments (Dev, Staging and Prod) operated by Ping Identity.[1] This article covers the packaging and metrics of that offering, the related PingOne Advanced Services and Ping Government Identity Cloud, and the contract documents that apply to each.
Editions and packaging
The licensing guide splits PingOne Advanced Identity Cloud into two families, each with its own unit of measure.
Customer identity (CIAM) packages
The CIAM offering is packaged as a Core subscription with optional add-on packages (Access Plus, Personalization, Organizations, Edge and Sync) and is licensed per Annual Active User.[1] The guide describes the components as follows.[1]
| Package | Content in the guide |
|---|---|
| Core | Authentication journeys, session and SSO, multi-factor and strong authentication, SAML, OIDC and OAuth 2.0 federation, web and Java agents, identity lifecycle and self-service, social login, LDAP directory services, basic reporting |
| Access Plus | Fine-grained, transactional and continuous authorization, application MFA, WebAuthn passwordless |
| Edge | Identity gateway and microservices gateway based on PingGateway |
| Personalization | Profile and privacy dashboard, consent and preference management, custom relationships |
| Organizations | Organization hierarchies, multi-brand capabilities, customer delegated administration |
| Sync | Synchronization, password synchronization, reconciliation, outbound provisioning, connectors, pass-through authentication and just-in-time migration |
| Advanced Reporting | Paid reporting tier with custom reports, near real-time latency and 90 days of data retention |
| Agent IAM Core | Governed AI agent identities |
Basic reporting is included at no additional charge, with standard reports refreshed every 1 to 2 hours and 30 days of retention.[1] The catalog row PingOne Advanced Identity Cloud Core records this package.
Workforce and B2B packages
The Workforce and B2B offerings use a Managed (Stored) Identity as the unit, defined in the guide as a unique identifier for a device or user that is managed by the products, regardless of activity.[1] The packages listed are Workforce Core, Access Management (including WS-Federation and WS-Trust, all MFA including passwordless, context nodes and coarse and fine-grained authorization), Edge, Enterprise Connect, Enterprise Connect Passwordless, Lifecycle Automation, Identity Workflow, Access Request, Access Review (certifications), Segregation of Duties, Role Modeling and Agent IAM Core.[1] Identity Workflow is described as a prerequisite for the other identity governance and administration modules.[1] The guide’s archive section lists a standalone Governance product (access request and access review) among components no longer offered to net-new customers.[13]
The difference between an active-user and a stored-identity metric matters at renewal. An Annual Active User counts only identities that did something during the year, whereas a Managed (Stored) Identity counts records held, whether or not they were used. A customer migrating from one family to another needs to rebuild the count from the platform’s data rather than from billing history.
Metrics and counting
The guide states that all single-tenant SaaS licensed identities and transactions in production count fully against contracted limits.[1] It adds that there are no hard limits in the system that automatically shut off PingOne Advanced Identity Cloud capabilities, and that in development and sandbox environments infrastructure limits usage to 10,000 objects.[1] The absence of a technical stop does not remove the contractual limit. The Identity Cloud agreement grants a right for Authorized Users to use the service to manage Identities for the Designated System, limited to the number of Identities purchased under the relevant Order Form, and states that each Identity is specific to a unique identifier for a user or device and may not be transferred to, shared among or used by different users or devices.[4]
That agreement, version 20230425 and still listed among Ping Identity’s ForgeRock legal documents,[11] defines an Active External Identity as an External Identity that accesses the Identity Cloud, or systems supported by it, at least once in a twelve-month period.[4] It separates Internal Identities, controlled by the customer, from External Identities and Business Partner Identities.[4] Fees are based upon the number of Identities purchased, even if actual usage is lower.[4] The Order Form, and in newer contracts the Product Specific Terms, control which of these definitions apply, including the Monthly Active Identity overage rule of two times the annual rate.[8] Which agreement governs a customer depends on the Order Form: the current Subscription Agreement also covers hosted Services.[12]
Environments and infrastructure add-ons
Beyond the three default environments, the guide lists infrastructure add-ons.[1]
| Add-on | Description in the guide |
|---|---|
| Additional sandbox environment | Standalone sandbox tenant outside the dev, stage and prod chain, tracking the rapid release channel |
| Additional pre-production environment | Extra user acceptance testing tenant between development and staging |
| Additional production tenant | A further production tenant with Dev, Stage and Prod, fully isolated, not replicated with the primary tenant |
| Multi-region high availability | Active/standby capacity across regions with defined RTO and RPO |
| Secure Connect | Private network connectivity, for example through Equinix |
| Disaster recovery testing in staging or production | One inter-regional DR test per year per add-on |
The Product Specific Terms describe the “FIP-Cloud-Additional Sandbox” order form item: a standalone environment, separate from development, staging and production, that entitles one non-production environment of PingOne Advanced Identity Cloud expressly without personally identifiable information and is provided as is.[8] The catalog records this in the rule Additional Sandbox is a PII-free non-production environment.
Downloadable components and on-premises software
Customers who buy a SKU that includes downloadable software use it under the Downloadable Components Supplement.[4] The supplement, revision 20220817, defines the components as Identity Gateway, Microservices Security, Policy Agents, Remote Connector Server, IDM Connector and Enterprise Connect.[5] The licence is world-wide, non-exclusive and non-transferable, for the subscription term and solely in connection with the customer’s implementation and use of the Identity Cloud, and use and documentation must be deleted when the agreement or Order Form ends.[5]
A separate On-Premise Software Addendum, revision 20220131, lets a customer buy a licence to ForgeRock’s on-premises software under the Identity Cloud agreement.[6] It supersedes the Downloadable Components Supplement for a customer that holds both, and permits installation at the customer’s facilities, a customer-controlled space in a third-party data centre, or a third-party hosting provider under a customer-controlled account, for the number of Identities for which Identity Licenses were purchased and only in connection with use of the Identity Cloud.[6] On request, no more than once per calendar quarter, the customer reports actual usage of the software under each Order Form, and promptly notifies Ping Identity of any increase in use above the Identity Licenses purchased.[6] The self-managed software article returns to the on-premises licences.
Push notification, support and maintenance
The Identity Cloud agreement states that the push notification service is provided by Amazon Simple Notification Service and subject to the Amazon SNS service terms, with support on a commercially reasonable basis.[4] The current Product Specific Terms repeat the clause using the PingOne Advanced Identity Cloud name.[8]
The Support Policy Addendum for Single-Tenant Services, effective 2025-08-25, applies to PingOne Advanced Identity Cloud and PingOne Advanced Services and prevails over the general Support Policy in a conflict.[7] It requires the customer to notify Ping Identity in advance of material changes that could affect volume or throughput, such as adding a significant number of applications or a significant enrollment event, to test planned upgrades in lower environments, and to give written notice of production-impacting issues at least three business days before a scheduled production upgrade.[7] The customer must always run supported releases of the software programs underlying the services.[7] The general Support Policy commits to Uptime Availability for the Service of 99.99 percent.[9]
PingOne Advanced Services
PingOne Advanced Services is a dedicated SaaS platform tenant with a separate platform fee SKU, into which PingAccess, PingCentral, PingDirectory and PingFederate can be added.[2] By default the customer receives a tenant with two environments, Dev and Production.[2] It is licensed on AAU or MAU, and the guide defines the Annual Average Monthly Active User as the average of the 12 MAU values for the 12 months of each contract year.[2] Production identities count fully against contracted limits; non-production environments are for development and testing under the fair-use policies of the Product Specific Terms.[2] Infrastructure add-ons are an additional test environment, an additional stage environment, an additional region, a weekend upgrade SKU and disaster recovery testing in staging or production.[2] The guide also lists PingFederate Agent IAM Core for governing AI agent identities.[2]
Ping Government Identity Cloud
The Ping Government Identity Cloud supports PingAccess, PingAuthorize, PingCentral, PingDirectory, PingFederate, PingAM, PingDS, PingGateway, PingIDM and Governance, operated by Ping Identity with multiregion availability and, by default, production and non-production environments.[3] It uses the managed (stored) identity unit, counted once per contract year.[3] An add-on provides additional non-production environments while preserving FedRAMP and Impact Level 5 controls.[3]
Secure Containers
Secure Containers are hardened container images of Ping Identity software, which customers can run in their own infrastructure, deployed by the customer, a third party or Ping Identity.[3] They are licensed per Ping Identity product and per customer segment (Workforce, CIAM, Partner or others on the order form), not by runtime replica, pod or container instance count unless the order form states otherwise.[3] They are an add-on: customers must first license the underlying Ping Government Identity Cloud software for the product they plan to run.[3] For a container estate, the practical counting question is therefore the number of product and segment combinations, not the number of pods.
Audit and renewal
The Identity Cloud agreement gives ForgeRock a right to audit, or have an independent certified public accountant audit, the customer’s records and books related to the service to verify use, on at least ten business days’ written notice and during normal business hours.[4] Each Order Form renews automatically for periods equal to the initial term unless either party gives notice of non-renewal at least 90 days before the end of the term, and the vendor reserves the right to modify fees at renewal.[4] The Subscription Agreement has comparable renewal wording.[12]
Out of scope
This article does not describe the technical architecture of the offerings, the service level credits, or pricing, which Ping Identity does not publish for these offerings. The PingOne multi-tenant services, including the PingOne DaVinci and PingOne Protect fair-use limits, are covered in the PingOne article.