Skip to content


Using the Provisioning on Hire2Retire you can provision and deprovision users on PingIdentity. Read the official documentation of PingIdentity here.

PingIdentity Application on Hire2Retire

Figure 1. PingIdentity Application on Hire2Retire

Define Role Definition

Provisioning Type

Define Role(s)

You can assign a Role to any user based on their AD attributes. You can define complex conditions using AND and OR logic. You can also use thee Group memberships in AD to define Roles. For example:In Figure 2, user(s) with Department "Product" will get provisioned. Only users who get a Role assigned based on the conditions, will be provisioned. If the user is unassigned from a role based on their updated profile in AD, and you have selected to deprovision using Hire2Retire, user will be deprovisioned from PingIdentity.

PingIdentity ScimManager Table1

Figure 2. Provision users with following rule definitions

Process All Employees

All user(s) will be provisioned on PingIdentity.

PingIdentity Process All Employees

Figure 3. Process All Employees

Provision User

You can decide to either provision or deprovision using Provisioning.

You can provision one or more user(s) according to the requirement. User(s) can be created, updated or reactivated in provisioning operation. You can deprovision one or more user(s) according to the requirement. User(s) can be terminated in deprovisioning operation.

PingIdentity Form Operations

Figure 4. Configure lifecycle operations for PingIdentity

Map attributes on PingIdentity

You can populate a user's profile in PingIdentity by mapping attributes incoming from the AD. You can also use Hire2Retire's powerful data transformation capabilities using Excel Style functions.

PingIdentity Form Attributes

Figure 5. Select PingIdentity attributes