For LDAP Gateway connections, the group associated with the user is provisioned to PingOne only on the initial user migration.

  1. Go to Integrations > Gateways.
  2. Locate the appropriate gateway connection.
  3. Click the gateway entry to open the gateway details panel.
  4. Click the Lookup tab.
  5. Click the options menu on the right, and then click Edit.
  6. Under User Link Attributes, click + Add Mapping.
  7. For PingOne user profile attribute, select External Group Names.
  8. For the external directory attribute, enter the inbound attribute name from the external directory. For example, memberOf for Microsoft Active Directory, and isMemberOf for PingDirectory.
  9. Click Save.

    When a user signs on the first time, if the user doesn’t exist in PingOne, the gateway creates a user record in PingOne based on the mappings, including group membership. This is a one-time event, not a continuous synchronization.

    For more information, see Just-in-time provisioning of external groups.