---
title: Choosing IdP connection options
description: On the Connection Optionstab, shown only for browser-based single sign-on (SSO) connections, you can enable browser-based SSO in conjunction with Just-in-Time (JIT) provisioning. Additionally, you can also choose to map user attributes for persistent grants used by the optional PingFederate OAuth authorization server.
component: pingfederate
version: 13.1
page_id: pingfederate:administrators_reference_guide:help_idpconnectionconfigtasklet_connectionoptionsstate
canonical_url: https://docs.pingidentity.com/pingfederate/13.1/administrators_reference_guide/help_idpconnectionconfigtasklet_connectionoptionsstate.html
llms_txt: https://docs.pingidentity.com/pingfederate/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: July 5, 2022
section_ids:
  about-this-task: About this task
  steps: Steps
---

# Choosing IdP connection options

On the **Connection Options**tab, shown only for browser-based single sign-on (SSO) connections, you can enable browser-based SSO in conjunction with Just-in-Time (JIT) provisioning. Additionally, you can also choose to map user attributes for persistent grants used by the optional PingFederate OAuth authorization server.

## About this task

For SAML 2.0, you can configure the **Attribute Query** profile with or without the browser-based SSO.

## Steps

* On the **Connection Options** tab, make the appropriate selections for your configuration.

  | Choice                                                                  | Action                                                                                                                                                   |
  | ----------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
  | Create a connection for browser-based SSO.                              | Select the **Browser SSO** checkbox.                                                                                                                     |
  | Enable JIT provisioning, OAuth attribute mapping, or both.              | Select the appropriate checkbox after selecting the **Browser SSO** checkbox.                                                                            |
  | Create a connection to facilitate the SAML 2.0 Attribute Query profile. | Select the **Attribute Query** checkbox. For more information, see [Attribute Query and XASP](../introduction_to_pingfederate/pf_attrib_query_xasp.html) |
