---
title: Workplace from Facebook Provisioner
description: The Workplace from Facebook Provisioner allows PingFederate to integrate with Workplace for user provisioning and single sign-on (SSO).
component: facebook
page_id: facebook:workplace_from_facebook_provisioner:pf_workplace_connector
canonical_url: https://docs.pingidentity.com/integrations/facebook/workplace_from_facebook_provisioner/pf_workplace_connector.html
revdate: June 11, 2024
section_ids:
  components: Components
  intended-audience: Intended audience
  system-requirements: System requirements
  features: Features
---

# Workplace from Facebook Provisioner

The Workplace from Facebook Provisioner allows PingFederate to integrate with Workplace for user provisioning and single sign-on (SSO) *(tooltip: \<div class="paragraph">
\<p>The process of authenticating an identity (signing on) at one website (usually with a user ID and password) and then accessing resources secured by other domains without reauthenticating.\</p>
\</div>)*.

## Components

Workplace from Facebook provisioning and SSO connector:

* Allows PingFederate to manage users in Workplace based on changes in an external user datastore.

* Optional configuration allows PingFederate to create an SSO connection to Workplace.

* Includes a quick-connection template that pre-populates some configuration settings.

## Intended audience

This document is intended for PingFederate administrators. Before you start, you should be familiar with the following:

* The following sections of the PingFederate documentation:

  * [Identity provider SSO configuration](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_ident_provid_sso_config.html)

  * [Datastores](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_managedatasourcestasklet_managedatasourcesstate.html)

  * [Managing IdP adapters](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_managing_idp_adapters.html)

  * [Managing digital signing certificates and decryption keys](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_certmanagementtasklet_dsigsigningcert_certmanagementstate.html)

  * [SP connection management](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_sp_connect_management.html)

  * [Configuring outbound provisioning](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_spconnectionconfigtasklet_saasprovisioningstate.html)

  * [Configuring outbound provisioning settings](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_protocolsettingstasklet_saasglobalprovisioningsettingsstate.html)

* The following sections in the Workplace from Facebook documentation:

  * [Getting Started](https://www.workplace.com/workplace/resources/getting-started)

  * [Workplace Help Center](https://www.workplace.com/help/work/)

  * [Technical Resources](https://www.workplace.com/workplace/resources/tech)

  * [Account management](https://www.workplace.com/workplace/resources/tech/account-management/intro)

  * [Configuring single sign-on (SSO) for Workplace](https://fb.workplace.com/help/work/1645025008878272)

  * [Account Management API](https://developers.facebook.com/docs/workplace/reference/account-management-api)

  * [Custom Integrations](https://developers.facebook.com/docs/workplace/custom-integrations-new)

  * [Custom integration deactivation policy](https://developers.facebook.com/docs/workplace/custom-integrations-new/deactivation-policy)

* [Known issues and limitations](pf_workplace_connector_known_issues_and_limitations.html)

## System requirements

* PingFederate 9.0 or later.

* A Workplace system administrator account.

* To allow PingFederate to make outbound connections to the Workplace API, you might need to whitelist the following domain in your firewall: https\://scim.workplace.com/

## Features

* Manages users in Workplace based on changes in an external datastore that is attached to PingFederate

  * Creates, updates, and disables users

  * Allows you to enable the create, update, and disable capabilities independently

  * Provisions disabled users

* Browser-based SSO initiated by the service provider (SP) *(tooltip: \<div class="paragraph">
  \<p>In SAML, an entity that receives and accepts an authentication assertion issued by an IdP, typically for the purpose of allowing access to a protected resource.\</p>
  \</div>)* or identity provider (IdP) *(tooltip: \<div class="paragraph">
  \<p>A service that manages identity information and provides authentication services to relying clients or SPs within a federated or distributed network.\</p>
  \</div>)*
