---
title: Configure WS-Trust STS
description: "If you are not using active federation (for native client cases such as the Dynamics CRM plug-in for Outlook), then you do not need to configure WS-Trust STS settings: skip ahead to Configure credentials. If the task bar is showing WS-Trust STS, return to the Connection Type screen and clear the WS-Trust check box. Then go to the Credentials screen."
component: dynamicscrm
page_id: dynamicscrm:pingfederate_configuration:pf_dynamicscrm_integration_configure_ws_trust_sts
canonical_url: https://docs.pingidentity.com/integrations/dynamicscrm/pingfederate_configuration/pf_dynamicscrm_integration_configure_ws_trust_sts.html
revdate: July 3, 2024
section_ids:
  about-this-task: About this task
  steps: Steps
---

# Configure WS-Trust STS

## About this task

|   |                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| - | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | If you are not using active federation (for native client cases such as the Dynamics CRM plug-in for Outlook), then you do not need to configure WS-Trust STS settings: skip ahead to [Configure credentials](pf_dynamicscrm_integration_configure_credentials.html). If the task bar is showing `WS-Trust STS`, return to the **Connection Type** screen and clear the WS-Trust check box. Then go to the **Credentials** screen. |

## Steps

1. Click **Configure WS-Trust STS**.

2. Enter the base URL of your Dynamics CRM Web site on the **Protocols Settings** screen.

   For example:

   ```
   https://ping.crm.com
   ```

3. Select the **Generate Key for SAML Holder of Key Subject Confirmation Method** check box.

4. When configuring token creation, extend the attribute contract on the **Attribute Contract** screen by adding `upn` and selecting `http://schemas.xmlsoap.org/ws/2005/05/identity/claims` as the attribute name format.
