---
title: Enabling provisioning in PingFederate
description: To use PingFederate for provisioning, configure an external datastore.
component: dropbox
page_id: dropbox:setup:pf_dropbox_connector_enabling_provisioning_in_pf
canonical_url: https://docs.pingidentity.com/integrations/dropbox/setup/pf_dropbox_connector_enabling_provisioning_in_pf.html
revdate: June 11, 2024
section_ids:
  about-this-task: About this task
  steps: Steps
  choose-from: Choose from:
---

# Enabling provisioning in PingFederate

To use PingFederate for provisioning, configure an external datastore.

## About this task

Your external datastore acts as the source of data for provisioning. PingFederate also uses an internal datastore to store the state of synchronization between the source datastore and the target datastore.

Learn more in [Datastores](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_datastores.html) in the PingFederate documentation.

## Steps

1. Configure the datastore for PingFederate to use as the source of user data.

   Learn more in [Datastores](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_datastores.html) in the PingFederate documentation.

   |   |                                                                                                                                                                                                                                                                        |
   | - | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   |   | When targeting users and groups for provisioning, exclude the user account that you will use to administer users in your connection to Dropbox. This prevents the PingFederate provisioning engine from interfering with the account that provisions users and groups. |

2. Do one of the following:

   ### Choose from:

   * For PingFederate 10.1 or later: Go to **System > Server > Protocol Settings**.

   * For PingFederate 10.0 or earlier: Enable the identity provider (IdP) and outbound provisioning roles:

     1. Go to **System > Protocol Settings > Roles & Protocols**.

     2. Select **Enable Identity Provider IdP Role and Support the Following**.

     3. Select **Outbound Provisioning**. Click **Next**.

3. On the **Outbound Provisioning** tab, select the PingFederate internal datastore. Click **Save**.

   Learn more in [Configuring outbound provisioning settings](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_protocolsettingstasklet_saasglobalprovisioningsettingsstate.html) in the PingFederate documentation.
