You can indicate on the Source Location tab where PingFederate should look for user records in the datastore.
The same location can be used to retrieve user-group distinguished names (DNs) for maintaining corresponding groups at the service provider (SP).
After specifying the required base DN, you can provision users, and groups when applicable, based on group membership information or LDAP search results.
Groups provisioning is supported for System for Cross-domain Identity Management (SCIM) and the Google Apps Connector (version 2.0 and higher) but might not be supported for other software as a service (SaaS) Connectors. If not, the associated fields under Groups on the Source Location tab are inactive. Support for the feature might become available in future SaaS Connector releases. See the documentation in your add-on distribution package.