---
title: Configuring Provisioning for PingFederate
description: Provision user data between PingFederate and PingOne for Enterprise.
component: pingoneforenterprise
page_id: pingoneforenterprise:pingone_for_enterprise:p14e_configure_provisioning_pingfed
canonical_url: https://docs.pingidentity.com/pingoneforenterprise/pingone_for_enterprise/p14e_configure_provisioning_pingfed.html
revdate: January 21, 2025
section_ids:
  steps: Steps
  result: Result
---

# Configuring Provisioning for PingFederate

Provision user data between PingFederate and PingOne for Enterprise.

## Steps

1. From the PingFederate admin portal, go to **Applications > Integration > SP Connections**.

2. Click the **PingOne** connection and then click the **Connection Type** tab.

3. Select the **Outbound Provisioning** checkbox.

4. Click **Next** until you reach the **Outbound Provisioning** tab.

5. Click **Configure Provisioning**.

6. Click **Create**.

7. On the **Channel Info** tab, in the **Channel Name** field, enter a name for the provisioning channel. Click **Next**.

8. On the **Source** tab, in the **Active Data Store** list, select a data store.

   If you haven't configured a data store, click **Manage Data Stores** to create one. For more information, see [Adding a new datastore](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_datasourcetasklet_selectdatasourcetypestate.html).

9. Click **Next** until you reach the **Source Location** tab.

10. On the **Source Location** tab, enter the source record names for the user repository you've selected.

    These entries must be in the proper format for the repository. An LDAP repository requires Base DN and Users Group DN entries, for example: `DC=pingone,`, `CN=Users`, `CN=Builtin`, `DC=pingone`, `DC=com`.

    |   |                                                                                                                                                                                                                                                                                                                                                          |
    | - | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    |   | You must configure both user provisioning and group provisioning in PingFederate for PingOne for Enterprise provisioning to work. Learn more in [Specifying a source location](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_saaschanneltasklet_saassourcelocationstate.html) in the PingFederate documentation. |

    |   |                                                                                                                                                     |
    | - | --------------------------------------------------------------------------------------------------------------------------------------------------- |
    |   | Microsoft Active Directory administrators can use the `dsquery` command on the Active Directory host to find the Base DN and Users Group DN values. |

11. On the **Attribute Mapping** tab, change any attribute settings as needed. PingFederate automatically populates a valid configuration, but you can use this menu to add or modify attributes depending on your organization's needs. For more information, see [Mapping Attributes](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_saaschanneltasklet_saasattrmappingmgmtstate.html).

12. Click **Next**.

13. On the **Activation & Summary** tab, click **Active**, then click **Done**.

14. On the **Manage Channels** tab, click **Save**.

## Result

After completing your PingFederate SP outbound provisioning, you're returned to the **SP Connections** window.
