---
title: Creating a provisioning connection
description: To allow PingFederate to manage users in the target service, create a service provider (SP) connection.
component: aquera
page_id: aquera:setup:pf_aquera_connector_creating_a_provisioning_connection
canonical_url: https://docs.pingidentity.com/integrations/aquera/setup/pf_aquera_connector_creating_a_provisioning_connection.html
revdate: June 27, 2024
section_ids:
  steps: Steps
  choose-from: Choose from:
---

# Creating a provisioning connection

To allow PingFederate to manage users in the target service, create a service provider (SP) connection.

## Steps

1. In the PingFederate administrator console, create a new SP connection:

   ### Choose from:

   * For PingFederate 10.1 or later: go to **Applications > Integration > SP Connections**. Click **Create Connection**.

   * For PingFederate 10.0 or earlier: go to **Identity Provider > SP Connections**. Click **Create Connection**.

2. Configure the basic connection details with the the target service quick connection template.

   1. On the **Connection Template** tab, select **Use a template for this connection**.

   2. From the **Connection Template** list, select **Aquera Provisioner**. Click **Next**.

   3. On the **Connection Type** tab select **Outbound Provisioning**. Click **Next**.

   4. On the **General Info** tab, in the **Connection Name** field, enter a name of your choosing. Click **Next**.

3. On the **Outbound Provisioning** tab, configure provisioning with the following details.

   Learn more in [Configuring outbound provisioning](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_spconnectionconfigtasklet_saasprovisioningstate.html) in the PingFederate documentation.

   1. On the **Target** page, enter the URL and authentication details that you noted in [Add an application in Aquera](pf_aquera_connector_add_an_application_in_aquera.html).

      |   |                                                                                                   |
      | - | ------------------------------------------------------------------------------------------------- |
      |   | PingFederate verifies the authentication details when you activate the channel and SP connection. |

   2. Under **Provisioning Options**, customize the provisioning connector behavior by referring to [Aquera Connector settings reference](pf_aquera_connector_aquera_connector_settings_reference.html). Click **Next**.

   3. On the **Manage Channels > Attribute Mapping** tab, at the end of the page, click **Refresh Fields**. Complete the required (`*`) attribute mappings and any optional mappings that you want.

      The **Refresh Fields** button causes PingFederate to get the attribute schema from the target service. The schema can include custom attributes (marked with `IANUser`) and standard SCIM attributes. Learn more about standard SCIM attributes in [Supported attributes reference](pf_aquera_connector_supported_attributes_reference.html).

      Learn about mapping attributes in [Managing channels](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_saasmanagementtasklet_saasmanagementstate.html) in the PingFederate documentation.

4. On the **Activation and Summary** tab, above the **Summary** section, click the toggle to turn on the connection. Click **Save**.
