Configure User Provisioning for Adaptive Planning
- Enable Workday SSO. If you have existing connectors with Workday in place, Workday SSO is likely also enabled.
- Security: These domains in the System functional area:
- Set Up: User Provisioning
- Manage: Workday Adaptive Planning User Provisioning
- Report: User Provisioning Status
The User Provisioning Workspace (UPW) enables you to authenticate, provision, and sync users to Workday Adaptive Planning. Workday recommends using roles like security administrator to set up the UPW, while account managers can configure supported products and view error reports.
When configuring access to UPW, Workday recommends that you create user-based security groups. If you use role-based security groups, you can expect up to an hour delay for security group membership changes to reflect in Adaptive Planning. User-based security group changes reflect in near real-time.
- In Workday, create a user-based security group. You can use an existing group for this task.See dan1370796695367.
- Edit the security policy permissions for the security group. In theReport/Task Permissionssection, provide the security group withViewandModifyaccess. See dan1370797389950.
- Access theActivate All Pending Authentication Policy Changestask. Add a required comment on the page and clickOkay.
- Configure User Provisioning Workspace (UPW) to access the workspace. See Set Up Access to User Provisioning.
- In UPW, create provisioning groups, populate them with security groups, and associate these provisioning groups with Adaptive Planning instances in the User Provisioning Workspace. See Create User Provisioning Groups.
- Run thePreview Reportto identify any issues in the provisioning process:
- Users in theUsers Not in Provisioning Grouphave accounts in Adaptive Planning but their user IDs aren't synced with Workday. To resolve this issue, add the security groups of these users to the UPW.
- Review theError Typecolumn to see if an error is a system or data error. Address all data errors. System errors self-correct in a few hours.
- If you receive the "Invalid resource: Username is required" error, then the user's primary work email hasn't been set up in Workday.
- To sync users:
- Navigate to an Adaptive Planning instance and clickConfigure.
- ClickPreview and Enable Sync.
- SelectI understand that enabling sync may have irreversible impacts.
- ClickEnable Sync.
- Validate that users are synced into Adaptive Planning:
- In Adaptive Planning, from the main menu, selectAdministration.
- UnderUsers and Permissions, click theUserslink.
- On the users list page, check theLast Sync Timecolumn.
- To make UAM aware of UPA users, access theMaintain UAM User Integrationtask and add all the security groups used in User Provisioning Workspace (UPW). If you have Adaptive Planning multi-instances, repeat this step for each instance.