Optionally, go to OAuth settings > Token & Attribute Mapping > IdP Adapter Mapping to remove any existing identity provicer (IdP) adapter mappings.

  1. In PingFederate, go to Authentication > OAuth > Policy Contract Grant Mapping.
  2. In the Mappings section, in the Policy Contract list, select the authentication policy contract that you created earlier and click Add Mapping.
  3. Click Next.
  4. On the Contract Fulfillment tab, in the USER_KEY row:
    • In the Source list, select Authentication Policy Contract.
    • In the Value list, select subject.
  5. In the USER_NAME row:
    • In the Source list, select Authentication Policy Contract.
    • In the Value list, select subject.
  6. Click Next until you reach the Summary tab.
  7. Click Save.