If you choose to have PingFederate initiate user provisioning every time your site receives an SSO token, for all SSO tokens, an existing user account is always updated with incoming attributes.

Scree capture of the Event Trigger tab showing the two trigger options.

This tab does not appear for a Microsoft SQL Server datastore if provisioning is accomplished using a stored procedure, because the procedure is always called for all SSO tokens. The procedure should handle both provisioning new users and updating existing ones.

  • On the Event Trigger tab, in the Specify the trigger that initiates a user-provisioning event section, select one of the following:
    • Only SAML Assertations Containing a New User ID
    • All SAML Assertations