---
title: User management
description: The PingID Provisioner synchronizes users from your datastore to PingOne for Enterprise. The following describes the behavior of each provisioning capability.
component: pingid
page_id: pingid::pf_pid_connector_user_management
canonical_url: https://docs.pingidentity.com/integrations/pingid/pf_pid_connector_user_management.html
revdate: June 19, 2024
section_ids:
  synchronizing-existing-users: Synchronizing existing users
  user-provisioning: User provisioning
  user-updates: User updates
  user-deprovisioning: User deprovisioning
---

# User management

The PingID Provisioner synchronizes users from your datastore to PingOne for Enterprise. The following describes the behavior of each provisioning capability.

|   |                                                                                                                                                                                                                                       |
| - | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | You can configure the following capabilities and specify which users to provision when you get to the [Creating a provisioning connection](setup/pf_pid_connector_creating_a_provisioning_connection.html) part of the setup process. |

## Synchronizing existing users

PingFederate synchronizes users based on the `username` attribute in PingOne for Enterprise. If a user already exists in your datastore and PingOne for Enterprise, mapping this attribute correctly links the two records together.

For example:

* In PingOne for Enterprise, Janet's `username` is `jsmith`.

* In your datastore, Janet's `sAMAccountName` is `jsmith`.

* On the **Attribute Mapping** tab of your provisioning connection configuration, map the `username` attribute to `sAMAccountName`.

* When the provisioning connector runs, the datastore user is provisioned with a `username` of `jsmith`. That matches Janet's existing `username` in PingOne for Enterprise, so her information in the datastore is synchronized to her PingOne for Enterprise account.

## User provisioning

PingFederate provisions users when any of the following happens:

* A user is added to the datastore group or filter that is targeted by the provisioning connector.

* A user with `disabled` status is added to the datastore group or filter that is targeted by the provisioning connector, and the **Provision disabled users** provisioning option is enabled. This feature is not available in all provisioning connectors.

|   |                                                                                                                                                |
| - | ---------------------------------------------------------------------------------------------------------------------------------------------- |
|   | You can define which users PingFederate targets for provisioning on the **Source Location** tab of your provisioning connection configuration. |

## User updates

PingFederate updates users when a user attribute changes in your datastore.

|   |                                                                                                                                                   |
| - | ------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | You can define which attributes PingFederate monitors for changes on the **Attribute Mapping** tab of your provisioning connection configuration. |

## User deprovisioning

PingFederate deprovisions users when any of the following happens:

* A user is deleted from the user store.

* A user is disabled in the user store.

* A user is removed from the datastore group or filter that is targeted by the provisioning connector.
