---
title: Configure IdP token processor mapping
description: Click Map New Token Processor Instance and select a configured Username Token Processor as the Token Processor Instance.
component: dynamicscrm
page_id: dynamicscrm:pingfederate_configuration:pf_dynamicscrm_integration_configure_idp_token_processor_mapping
canonical_url: https://docs.pingidentity.com/integrations/dynamicscrm/pingfederate_configuration/pf_dynamicscrm_integration_configure_idp_token_processor_mapping.html
revdate: June 18, 2024
section_ids:
  steps: Steps
---

# Configure IdP token processor mapping

## Steps

1. Click **Map New Token Processor Instance** and select a configured Username Token Processor as the Token Processor Instance.

2. On the Attribute Retrieval screen, select the option to retrieve additional attributes from data stores to fulfill the attribute contract.

3. In the **Attribute Sources & User Lookup** screen, configure the LDAP data store that will return the upn attribute for the corresponding user, adding userPrincipalName as an additional attribute and including a filter value such as` sAMAccountName=${username}`.

4. On the Attribute Contract Fulfillment screen, select **Text** as the Source for SAML\_SUBJECT and enter an unused value. Select **LDAP** as the Source for upn and select **userPrincipalName** as the value.

5. Configure issuance criteria, if necessary.
