On the Mapping Method screen, you select if and how PingFederate should query local datastores to help fulfill the attribute contract in conjunction with attribute values from the authentication source.

To determine whether you need to look up additional values, compare the attribute contract against the adapter contract or the authentication policy contract. If the attribute contract requires more information, determine whether local datastores can supply it.


Alternatively, you may configure datastore queries as part of the fulfillment configuration for the applicable IdP adapter contract or authentication policy contract. If so, you do not need to set up datastore query on the connection level.

For more information, see Defining the IdP adapter contract or Applying policy contracts or identity profiles to authentication policies.

  • Select the Retrieve additional attributes from multiple data stores using one mapping option if you want to configure one or more datastores to look up attribute for a single mapping.
  • Select the Retrieve additional attributes from a data store—includes options to use alternate data stores and/or a failsafe mapping option if you want to define alternate datastores to look up attribute and a failsafe mapping configuration.

    When selected, the token authorization framework (through issuance criteria) does not apply. For more information, see About token authorization and Selecting an attribute mapping method.

  • Select the Use only ... option if you do not require connection-level datastore query.

If you are editing a currently mapped adapter instance or APC, you can change the mapping method, which may require additional configuration changes in subsequent tasks.