---
title: Zscaler Internet Access Provisioner
description: The Zscaler Internet Access Provisioner allows PingFederate to integrate with Zscaler Internet Access for user and group provisioning and single sign-on (SSO).
component: zscaler
page_id: zscaler:zscaler_internet_access_provisioner:pf_zscaler_zia_connector
canonical_url: https://docs.pingidentity.com/integrations/zscaler/zscaler_internet_access_provisioner/pf_zscaler_zia_connector.html
revdate: June 18, 2024
section_ids:
  features: Features
  intended-audience: Intended audience
  system-requirements: System requirements
---

# Zscaler Internet Access Provisioner

The Zscaler Internet Access Provisioner allows PingFederate to integrate with Zscaler Internet Access for user and group provisioning and single sign-on (SSO).

## Features

* Manages users and groups in Zscaler Internet Access based on changes in an external data store that is attached to PingFederate.

  * Creates, updates, and deletes users

  * Allows you to enable the create, update, and delete capabilities independently

  * Creates groups and updates group memberships

* Supports browser-based SSO initiated by the service provider (SP) or identity provider (IdP)

* Pre-populates some connection settings with the included quick connection template

## Intended audience

This document is intended for PingFederate administrators.

If you need help during the setup process, see the following resources:

* The following sections of the Zscaler Internet Access documentation:

  * [About SAML](https://help.zscaler.com/zia/about-saml)

  * [Configuring SAML](https://help.zscaler.com/zia/configuring-saml)

  * [About SCIM](https://help.zscaler.com/zia/about-scim)

  * [Configuring SCIM](https://help.zscaler.com/zia/configuring-scim)

* The following sections of the PingFederate documentation:

  * [Datastores](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_datastores.html)

  * [Configuring outbound provisioning](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_spconnectionconfigtasklet_saasprovisioningstate.html)

  * [Configuring outbound provisioning settings](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_protocolsettingstasklet_saasglobalprovisioningsettingsstate.html)

  * [Identity provider SSO configuration](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_ident_provid_sso_config.html)

  * [Managing digital signing certificates and decryption keys](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_certmanagementtasklet_dsigsigningcert_certmanagementstate.html)

  * [SP connection management](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_sp_connect_management.html)

## System requirements

* PingFederate 9.0 or later.

* A Zscaler Internet Access administrator account.

* To allow PingFederate to make outbound HTTPS connections, you might need to allow the following host names in your firewall:

  * https\://scim.*\<your\_Zscaler\_domain>*.net
