---
title: Restricting a token processor to certain virtual server IDs
description: Virtual server IDs provide more configuration flexibility in cases where you need to identify your server differently when connecting to a partner in one connection for multiple environments or in multiple connections where the partner also supports multiple federation IDs. When you multiplex one connection for multiple environments, you can restrict each token processor added to a WS-Trust STS SP connection or IdP connection.
component: pingfederate
version: 13.1
page_id: pingfederate:administrators_reference_guide:help_wstrusttokenprocessormappingtasklet_virtualserveridmappingstate
canonical_url: https://docs.pingidentity.com/pingfederate/13.1/administrators_reference_guide/help_wstrusttokenprocessormappingtasklet_virtualserveridmappingstate.html
llms_txt: https://docs.pingidentity.com/pingfederate/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: July 5, 2022
section_ids:
  about-this-task: About this task
  steps: Steps
---

# Restricting a token processor to certain virtual server IDs

Virtual server IDs provide more configuration flexibility in cases where you need to identify your server differently when connecting to a partner in one connection for multiple environments or in multiple connections where the partner also supports multiple federation IDs. When you multiplex one connection for multiple environments, you can restrict each token processor added to a WS-Trust STS SP connection or IdP connection.

## About this task

When you multiplex one connection for multiple environments see [Multiple virtual server IDs](../introduction_to_pingfederate/virtual_server_id.html), you can enforce authentication requirements by restricting a token processor to certain virtual server IDs on the **Virtual Server IDs** tab. By default, no restriction is imposed.

|   |                                                                                                                                                                                 |
| - | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | If you are editing a currently mapped token processor instance, you can toggle the **Restrict Virtual Server IDs** setting. You can also change the allowed virtual server IDs. |

## Steps

1. In the **IdP Token Processor Mapping** configuration window, go to the **Virtual Server IDs** tab.

2. Select the **Restrict Virtual Server IDs** checkbox.

3. Select one or more virtual server IDs that you want to allow for this token processor.
