CP-PingOne-AIC
Certified Professional - PingOne Advanced Identity Cloud
Part of Certified Professional - PingOne Advanced Identity Cloud
Proctored by Kryterion. Credential valid for 2 years. Validates configure, administer, troubleshoot, and maintain for Advanced Identity Cloud tenants (formerly ForgeRock Identity Cloud). Official recommended training: Getting Started With PingOne Advanced Identity Cloud for Administrators; PingOne Advanced Identity Cloud Deep Dive: Access Management; PingOne Advanced Identity Cloud Deep Dive: Identity Management.
Independent study aid built from the public exam blueprint. Not affiliated with, authorized by, or endorsed by ping. Objectives are transcribed and mapped by hand, so this page may contain mistakes or may have fallen behind the vendor's current material: exam objectives, versions, numbering and availability all change without notice. Treat ping's own certification portal as the source of truth and verify against it before you book anything.
Section 1: Managing Advanced Identity Cloud Tenants
1.01 Explain the environment and roles for managing Advanced Identity Cloud
What to know:- Managed cloud tenant: development, staging, production environments
- AM, IDM, DS delivered as a service - no infrastructure to run
- Tenant admin roles vs delegated realm roles
- Promotion of config between environments
1.02 Manage administrative access
What to know:- Tenant admin, and scoped roles for teams
- SSO for administrators into the tenant
- Break-glass and least-privilege for admin access
1.03 Perform general administrative tasks
What to know:- Config-as-code exports and promotion pipeline
- Scheduled tasks and tenant settings
- Certificate and secret management in-tenant
Section 2: Managing User Identities
2.01 Model identity objects
What to know:- managed alpha_user / alpha_role realm objects
- Schema extension via custom properties
- Searchable and encrypted property flags
On this site: The JSON Grammar: Six Types and a Few Strict Rules2.02 Manage event hooks
What to know:- Event hooks fire scripts on object lifecycle events
- postCreate/postUpdate/postDelete scripting
- Outbound integration triggered by identity changes
2.03 Import and sync identities
What to know:- CSV/bulk import into managed identities
- Reconciliation against connected systems
- Scheduling recurring sync jobs
Tools: ldap-filter-explainer2.04 Manage provisioning roles and assignments with Advanced Identity Cloud
What to know:- Provisioning roles carry assignments to target apps
- Conditional membership by query filter
- Assignment attributes flow on grant, revoke on removal
2.05 Manage custom objects and properties
What to know:- Custom managed objects beyond user/role
- Custom properties with policy and validation
- Relationships to core objects
Section 3: Managing User Journeys
3.01 Describe the purpose of the default user journeys
What to know:- Default journeys: Login, Registration, Reset Password, Progressive Profile
- Starting points to clone and customize
- Realm-scoped journey assignment
3.02 Modify Journeys
What to know:- Add/remove/rearrange nodes in the journey editor
- Inner journeys for reuse
- Success/failure outcome wiring
3.03 Configure self-service journeys
What to know:- Self-service: registration, password reset, profile update journeys
- Email/OTP verification nodes
- Progressive profiling to collect data over time
3.04 Configure Advanced Identity Cloud to use social registration and authentication
What to know:- Social identity provider nodes (Google, Apple, etc.)
- Provider client credentials and scopes
- Account claiming/linking to existing identities
On this site: OAuth flows: choosing the grant in 2026Tools: oauth-flow-chooser
Section 4: Integrating Applications and Gateways
4.01 Describe the role of an application in Advanced Identity Cloud
What to know:- Applications represent OAuth/OIDC/SAML integrations
- Managed application catalog and custom apps
- Bind journeys and access policies to applications
On this site: Açık ile gizli istemciler ve PKCE'nin yeri4.02 Manage an application client profile
What to know:- Client profile: redirect URIs, grants, scopes, token settings
- Confidential vs public client configuration
- Token lifetimes and refresh behavior
On this site: OAuth flows: choosing the grant in 2026, Erişim token'ları, yenileme token'ları ve kimlik token'larıTools: oauth-flow-chooser4.03 Integrate PingGateway
What to know:- PingGateway fronts legacy/on-prem apps for the cloud tenant
- Route protection consuming tenant tokens
- Hybrid bridge between cloud identity and on-prem resources
Section 5: Managing Federation
5.01 Integrate Advanced Identity Cloud with third-party services using SAML
What to know:- Tenant as SAML IdP or SP with third parties
- Metadata exchange and signing keys
- Attribute mapping into assertions
On this site: F5 BIG-IP APM as a SAML Proxy: SP and IdP ModesTools: saml-decoder5.02 Integrate Advanced Identity Cloud with third-party services using OIDC/OAuth
What to know:- Tenant as OIDC/OAuth provider to third parties
- Client registration and scope design
- Token and claim configuration for partners
On this site: The OIDC Authorization Code FlowTools: jwt
Public sources, used in good faith
These guides are independent study aids built from publicly available material: published exam blueprints, official product documentation, and vendor training catalogues. Product names, exam codes, and trademarks belong to their owners and are used only to identify the subject being taught. This site is not affiliated with or endorsed by any vendor named here. If you hold rights in material published on this page and believe it should be removed or corrected, please send the exact URL and a short note on the issue through the contact page; requests are reviewed promptly and in good faith. Read the full disclaimer →