# Introduction

For an overall understanding of the SAML authentication feature, read the [overview](https://docs.sonarsource.com/sonarqube-server/2025.2/instance-administration/authentication/saml/overview "mention") page.

To set up SAML with PingOne or PingFederate:

1. If you want to use Just-in-Time provisioning with the group synchronization feature, verify the user groups in SonarQube Server so that the automatic group synchronization can take place properly. See **Just-in-Time provisioning > Group synchronization** in [overview](https://docs.sonarsource.com/sonarqube-server/2025.2/instance-administration/authentication/overview "mention").
2. Make sure your [server-base-url](https://docs.sonarsource.com/sonarqube-server/2025.2/instance-administration/server-base-url "mention").
3. [setup-in-ping-identity](https://docs.sonarsource.com/sonarqube-server/2025.2/instance-administration/authentication/saml/ping-identity/setup-in-ping-identity "mention").
4. [setup-in-sq](https://docs.sonarsource.com/sonarqube-server/2025.2/instance-administration/authentication/saml/ping-identity/setup-in-sq "mention").
5. Optionally, [optional-security-features](https://docs.sonarsource.com/sonarqube-server/2025.2/instance-administration/authentication/saml/ping-identity/optional-security-features "mention").

{% hint style="info" %}
Starting in [Enterprise Edition](https://www.sonarsource.com/plans-and-pricing/enterprise/), in addition to the SAML setup, you can configure SCIM to automatically provision users and groups to SonarQube. For more information, see [overview](https://docs.sonarsource.com/sonarqube-server/2025.2/instance-administration/authentication/saml/scim/overview "mention").
{% endhint %}
