---
title: Configure provisioning
description: To configure a connection for outbound provisioning to Concur, follow the instructions in this section.
component: concur
page_id: concur:setup:pf_concur_connector_configure_provisioning
canonical_url: https://docs.pingidentity.com/integrations/concur/setup/pf_concur_connector_configure_provisioning.html
revdate: June 26, 2024
section_ids:
  about-this-task: About this task
  steps: Steps
---

# Configure provisioning

## About this task

To configure a connection for outbound provisioning to Concur, follow the instructions in this section.

Outbound provisioning details are managed within a service provider (SP) connection. You can configure outbound provisioning with or without Browser SSO, WS-Trust STS, or both when you create a new SP connection. You can also add outbound provisioning to an existing SP connection.

## Steps

1. In the PingFederate administrative console, configure the datastore that PingFederate will use as the source of user data. Learn more in [Datastores](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_managedatasourcestasklet_managedatasourcesstate.html) in the PingFederate documentation.

   * When targeting users and groups for provisioning, exclude the user account that you will use to administer users in your connection to Concur. This prevents the PingFederate provisioning engine from interfering with the account that provisions users and groups.

2. Create a new SP connection or select an existing SP connection from the **SP Configuration** menu.

3. On the **Connection Template** page, select **Use a template for this connection** and select **Concur** in the **Connection Template** drop-down list. When asked during the connection configuration steps, import the `saml-metadata.xml` packaged with this connector.

   ![An image of the Connection Template screen.](_images/kgo1563995204444.png)

   |   |                                                                                                 |
   | - | ----------------------------------------------------------------------------------------------- |
   |   | If this selection is not available, verify the connector installation and restart PingFederate. |

4. On the **Connection Type** page, ensure the **Outbound Provisioning** checkbox is selected, and the **Browser SSO Profiles** checkbox is cleared (if appropriate).

5. On the **General Info** page, the default values are taken from the metadata file you selected in step 2. We recommend using the metadata default values.

   ![An image of the General Info screen.](_images/mey1563995205457.png)

6. Follow the connection wizard to configure the connection.

7. On the **Outbound Provisioning** page, click **Configure Provisioning**.

8. On the **Target** page, enter the values for each field as required by the Concur Connector.

   ![An image of the Target screen.](_images/urm1563995207208.png)

   | Field Name               | Description                                                                                                                                                                                                                  |
   | ------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | **OAUTH\_ACCESS\_TOKEN** | The OAuth access token for the Concur account.Learn more in [Obtain key and secret](pf_concur_connector_obtain_key_and_secret.html) and [Generate OAuth access token](pf_concur_connector_generate_oauth_access_token.html). |

9. Click **Next** to continue the provisioning configuration. Learn more in the following sections under [Outbound provisioning for IdPs](https://docs.pingidentity.com/pingfederate/latest/introduction_to_pingfederate/pf_outboun_provis_for_idp.html) in the PingFederate documentation:

   * [Managing channels](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_saasmanagementtasklet_saasmanagementstate.html)

   * [Specifying channel information](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_saaschanneltasklet_saasgeneralinfostate.html)

   * [Identifying the source datastore](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_saaschanneltasklet_saassourceselectionstate.html)

   * [Modifying source settings](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_saaschanneltasklet_saassourcesettingsstate.html)

   * [Specifying a source location](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_saaschanneltasklet_saassourcelocationstate.html)

   * [Mapping attributes](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_saaschanneltasklet_saasattrmappingmgmtstate.html)

   * [Reviewing channel settings](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_saaschanneltasklet_saasactivationstate.html)

     |   |                                                                                                                                              |
     | - | -------------------------------------------------------------------------------------------------------------------------------------------- |
     |   | Many fields are required based on your Concur account configuration. Ensure that you are sending data for all user fields that are required. |

     |   |                                                                                                                     |
     | - | ------------------------------------------------------------------------------------------------------------------- |
     |   | Credentials will be verified when the channel and SP connection is set to **Active** and provisioning is initiated. |

     |   |                                                                                                                                                                                                                                                          |
     | - | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
     |   | If you are not ready to complete the provisioning configuration, you can click **Save** and return to the configuration page later. To return to the configuration page, select the connection from **Identity Provider > SP Connections > Manage All**. |
