Configuring provisioning to PingID - PingFederate - 11.2

PingFederate Server

bundle
pingfederate-112
ft:publication_title
PingFederate Server
Product_Version_ce
PingFederate 11.2
category
Administrator
Administratorguide
Audience
Capability
ContentType
DeploymentMethod
Guide
Product
Productdocumentation
SingleSignonSSO
Software
SystemAdministrator
pf-112
pingfederate
ContentType_ce
Guide
Guide > Administrator Guide
Product documentation

If you have chosen to connect PingFederate to a directory server, the Provisioning tab becomes available.

On the Provisioning tab, you have the option to enable provisioning of users from your directory server to PingID. In this configuration, specify the group where PingFederate should look for member users and update PingID when their email address, first name, or last name has changed.

Note:

This provisioning capability is designed to manage existing PingID accounts. It does not create new PingID users. When PingFederate detects that a user has been removed from the specified group or disabled in the directory server, PingFederate sends an update to PingID to disable the PingID service for that account.

  1. Select the Configure Provisioning check box.
  2. In the PingID Group DN field, enter the distinguished name (DN) of the applicable group.
    Note:

    The specified group must reside under the hierarchy of the previously-defined Search Base value.

  3. If you want PingFederate to monitor changes for users through nested group membership, select the Nested check box. Click Next.