---
title: Identifying an LDAP user-record location
description: After choosing a datastore, you can indicate where in the datastore user and group records exist so PingFederate can create, read, update, or delete or disable them.
component: pingfederate
version: 13.1
page_id: pingfederate:administrators_reference_guide:help_inboundprovisioningtasklet_configuserprovisioningldapdirsearchstate
canonical_url: https://docs.pingidentity.com/pingfederate/13.1/administrators_reference_guide/help_inboundprovisioningtasklet_configuserprovisioningldapdirsearchstate.html
llms_txt: https://docs.pingidentity.com/pingfederate/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: July 5, 2022
section_ids:
  about-this-task: About this task
  steps: Steps
---

# Identifying an LDAP user-record location

After choosing a datastore, you can indicate where in the datastore user and group records exist so PingFederate can create, read, update, or delete or disable them.

## About this task

These settings can be configured on the **Location** tab.

![Screen capture of the Location tab.](_images/vyp1564003525315.jpg)

|   |                                                                                   |
| - | --------------------------------------------------------------------------------- |
|   | This tab appears only if you are configuring an LDAP user store for provisioning. |

## Steps

* Enter the base distinguished name (DN) of the tree structure where user records are stored in the **Base DN** field.

  |   |                                                                                                 |
  | - | ----------------------------------------------------------------------------------------------- |
  |   | PingFederate looks only at this node level or below it for user accounts that need provisioning |
