You need to configure PingFederate for PingIntelligence policy to be able to extract the username from the incoming token. Complete the following steps to configure PingFederate to extract token attributes:
  1. While configuring Access Token Management in PingFederate, add all the attributes that should be exposed for the token. PingFederate provides these attribute values to PingAccess for OAuth tokens.
  2. Click Access Token Attribute Contract under Access token management Instance and add the required attributes. Make sure to at least add username.
  3. After Adding the required attributes, configure the attribute sources:
    1. Click Access Token Mapping
    2. Select the relevant Context
    3. Click Contract Fulfilment