Defining a unique group ID
On the Unique Group ID tab, you can create an LDAP filter to resolve groups for System for Cross-domain Identity Management (SCIM) operations.
About this task
PingFederate uses this LDAP filter in conjunction with the Base DN value, defined on the Location tab, to add new groups.
|
This tab appears only if you are configuring an LDAP user store for provisioning and you have selected the User and Group Support option on the Connection Type tab. |
Steps
-
Enter the statement in the Filter text field.The filter is in the form:
attribute=$\{value}whereattributeis an attribute in your user-datastore andvalueis the attribute value or values passed in from the SCIM request. To see a list of available attributes in your user-datastore, click View List of Available LDAP Attributes. Variables for these attributes, including the correct syntax, are listed under SCIM Attributes.
|
Unlike filters used to retrieve LDAP attributes for adapter mapping, do not enclose the statement in parentheses. |
|
You can reference attribute values in the form of If you are unfamiliar with writing LDAP queries, see the documentation accompanying your LDAP installation. |