For LDAP gateway connections, the group associated with the user is provisioned to PingOne only on the initial user migration.

  1. Go to Integrations > Gateways.
  2. Locate the appropriate gateway connection.
  3. Click the gateway entry to open the gateway details panel.
  4. Click the Lookup tab.
  5. Click the options menu on the right, and then click Edit.
  6. Under User Link Attributes, click + Add Mapping.
  7. For PingOne user profile attribute, select External Group Names.
  8. For the external directory attribute, enter the inbound attribute name from the external directory. For example, memberOf for Microsoft Active Directory, and isMemberOf for PingDirectory.
  9. Click Save.

When a user signs on the first time, if the user doesn’t exist in PingOne, the gateway creates a user record in PingOne based on the mappings, including group membership. When you enable the Update PingOne user attributes as users sign on option, user attributes update each time a user signs on successfully through the LDAP gateway client. The groups associated with the user are also provisioned to PingOne each time the user signs on to PingOne.

Learn more in Adding a user type and Just-in-time provisioning of external groups.