Mapping the group attribute from an external identity provider - PingOne - PingOne Cloud Platform

PingOne Cloud Platform

bundle
pingone
ft:publication_title
PingOne Cloud Platform
Product_Version_ce
PingOne
PingOne Cloud Platform
category
Administratorguide
ContentType
Guide
Product
Productdocumentation
p1
p1cloudplatform
ContentType_ce
Product documentation
Guide > Administrator Guide
Guide

If the external identity provider includes group information in its security tokens (ID tokens from an OIDC identity provider or assertions from a SAML identity provider), you can add a mapping between the External Group Names attribute in PingOne and the inbound attribute name from the external identity provider.

  1. Go to Integrations > External IDPs.
  2. Locate the appropriate identity provider.
  3. Click the Details icon to expand the identity provider, and then click the pencil icon.
  4. Click the Attributes tab.
  5. Click + Add Attribute.
  6. For PingOne user profile attribute, select External Group Names.
  7. For the external identity provider attribute, enter the inbound attribute name from the external identity provider.
  8. For Update condition, select one of the following:
    • Always. Update the group information in PingOne every time the user authenticates from the external identity provider.
    • Empty only. Update the group information in PingOne only if there is no value for the attribute in PingOne.
  9. Click Save.