Mapping the group attribute from an LDAP gateway
If the external directory includes group information in its security tokens, you can add a mapping between the External Group Names attribute in PingOne and the inbound attribute name from the external directory.
About this task
For Lightweight Directory Access Protocol (LDAP) gateway connections, the group associated with the user is provisioned to PingOne only on the initial user migration. |
Steps
-
Go to Integrations → Gateways.
-
Locate the appropriate gateway connection.
-
Click the gateway entry to open the gateway details panel.
-
Click the Lookup tab.
-
Click the options menu on the right, and then click Edit.
-
Under User Link Attributes, click Add Mapping.
-
For PingOne user profile attribute, select External Group Names.
-
For the external directory attribute, enter the inbound attribute name from the external directory. For example,
memberOf
for Microsoft Active Directory, andisMemberOf
for PingDirectory. -
Click Save.
Next steps
When a user signs on the first time, if the user doesn’t exist in PingOne, the gateway creates a user record in PingOne based on the mappings, including group membership. When you enable the Update PingOne user attributes as users sign on option, user attributes update each time a user signs on successfully through the LDAP gateway client. The groups associated with the user are also provisioned to PingOne each time the user signs on to PingOne.
Learn more in Adding a user type and Just-in-time provisioning of external groups.