---
title: Configuring just-in-time provisioning
description: PingFederate's just-in-time (JIT) provisioning allows service providers (SPs) to create user accounts on the fly during single sign-on (SSO) events, based on attributes received in SSO tokens from identity providers (IdPs).
component: pingfederate
version: 13.1
page_id: pingfederate:administrators_reference_guide:help_idpconnectionconfigtasklet_userprovisioningstate
canonical_url: https://docs.pingidentity.com/pingfederate/13.1/administrators_reference_guide/help_idpconnectionconfigtasklet_userprovisioningstate.html
llms_txt: https://docs.pingidentity.com/pingfederate/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: July 5, 2022
section_ids:
  about-this-task: About this task
  steps: Steps
---

# Configuring just-in-time provisioning

PingFederate's just-in-time (JIT) provisioning allows service providers (SPs) to create user accounts on the fly during single sign-on (SSO) events, based on attributes received in SSO tokens from identity providers (IdPs).

## About this task

An SP can also use JIT provisioning to update existing user records.

|   |                                                                                                                                                               |
| - | ------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | This configuration task is presented in the administrative console only when the **JIT Provisioning** checkbox is selected on the **Connection Options** tab. |

![Screen capture of the JIT Provisioning tab.](_images/tfn1564003508768.jpg)

## Steps

1. Go to **Authentication > Integration > IdP Connections**.

2. Create a new IdP connection or select an existing IdP connection .

3. On the **Connection Type** tab, select the **Browser SSO Profiles** checkbox and a protocol from the list.

4. On the **Connection Options** tab, select the **Browser SSO** checkbox and then the **JIT Provisioning** checkbox.

5. Complete the **Browser SSO** configuration.

6. On the **JIT Provisioning** tab, click **Configure User Provisioning** to begin the configuration of JIT provisioning.
