You have a requirement to configure a vCenter Identity Provider (IDP) for PingFederate using the SAML 2.0 protocol and are unable to use OpenID Connect (OIDC).
vCenter Server 8.0
In vCenter 8, SAML 2.0 is unsupported when configuring PingFederate. OIDC is the only supported authentication protocol when using PingFederate.
Starting with vCenter 8.0 U3 you can change vCenter's identity provider through the UI. Reference Configuring vCenter Server Identity Provider for PingFederate for more information.
Starting in VCF 9, it is supported to configure PingFederate with SAML 2.0: