Known issues

  • Values for the roles attribute are not shown in the Workspace UI or API response.

Known limitations

  • Due to a limitation in PingFederate, once a user attribute is set, it can be updated but not cleared.
  • Due to a limitation with PingFederate 9.0 and 9.0.1, the manager attribute cannot be mapped and used. There is no impact to other functionality.
  • In PingFederate 8.1 and earlier, when you configure a second SP connection with the provisioning connector, the second connection might be pre-populated with the channel from the first connection. To avoid conflicts, remove this pre-populated channel and create a unique channel for each connection.
  • Workplace does not support single logout (SLO).
  • When using the default mapping for the manager attribute, the process for adding a manager involves an Active Directory search, followed by a call to Workplace by Facebook. This might diminish initial synchronization provisioning performance. To improve performance, you can use a custom attribute mapping to link the manager attribute to a manager’s email.