If the external directory includes group information in its security tokens, you can add a mapping between the External Group Names attribute in PingOne and the inbound attribute name from the external directory.
For LDAP Gateway connections, the group associated with the user is provisioned to PingOne only on the initial user migration.
- Go to .
- Locate the appropriate gateway connection.
- Click the gateway entry to open the gateway details panel.
- Click the Lookup tab.
- Click the options menu on the right, and then click Edit.
- Under User Link Attributes, click + Add Mapping.
- For PingOne user profile attribute, select External Group Names.
For the external directory attribute, enter the inbound attribute name from the
external directory. For example,
memberOffor Microsoft Active Directory, and
When a user signs on the first time, if the user doesn’t exist in PingOne, the gateway creates a user record in PingOne based on the mappings, including group membership. This is a one-time event, not a continuous synchronization.
For more information, see Just-in-time provisioning of external groups.