Zum Hauptinhalt wechseln
Adaptive Planning
Steps: Set Up SAML SSO into Adaptive Planning Without User Sync

Steps: Set Up SAML SSO into Adaptive Planning Without User Sync

  • You must work with a Workday-certified implementer to use or configure this feature. If you don't have access to a certified implementer, contact your Customer Success Manager to engage professional services.
  • In Adaptive Planning:
    • Configure an IdP provider, like Okta, in Adaptive Planning for signing in. Post-configuration, verify that
      Allow only SAML SSO
      is selected under
      Administration
      SAML SSO Settings
      Enable SAML
      .
    • Configure your instance for Workday using Workday Tenant ID, Environment, UI URL, and REST URL.
  • Security:
    • Access Adaptive Planning
      domain in the Adaptive Planning functional area of Workday.
    • In Adaptive Planning, verify that you have Admin Access with these permissions to enable user sign-in to configure Security Assertion Markup Language (SAML) Single Sign-On (SSO) in Workday.
      • Users
        .
      • SAML
        .
      • Permission Sets
        .
      • Manage Global User Groups
        .
      • General Setup
        .
This SSO configuration is valid when:
  • You only want to use SSO from Workday.
    Users can access Adaptive Planning with either the
    Adaptive Planning
    worklet on their Workday
    Home
    page or through their IdP provider.
  • You want to:
    • Manually maintain both the Workday and Adaptive Planning user profile for each user independently from each other.
    • Continue to receive Adaptive Planning alerts as emails.
    • Continue to use your Adaptive Planning credentials for OfficeConnect and public APIs.
  • You don't want to publish plans to HCM and Financials.
The only other SSO configuration we support is with user sync.
  1. As a security admin, verify you copied and edited the
    All Workday Accounts
    standard report with additional row columns for the
    Workday ID
    field.
    Use information from this report to obtain the Workday Federation ID for every planning user requiring SSO into Adaptive Planning. The username is part of the Workday Federation ID, which follows this pattern: workdayUserName@TenantID.Environment
    Security:
    Workday Accounts
    domain in the System functional area.
  2. Sign in to Adaptive Planning as a user with administrative privileges.
  3. Select
    Administration
    from the main menu.
  4. Select
    Users
    in the
    Users and Permissions
    section.
  5. Find and edit the administrator user and enter their Workday ID.
    The administrator user is the Workday security admin doing the SSO configuration.
  6. Enter the Workday Federation ID for all users and the security administrator enabling SSO.
  7. In Workday, access the
    Tenant Setup
    report.
    Security:
    • Set Up: System
      in the System functional area.
    • Set Up: Tenant Setup - Adaptive Planning
      in the System functional area.
    • Set Up: Tenant Setup - General
      in the System functional area.
  8. Select the
    Adaptive Planning
    tab.
  9. Select the
    User Sign-On
    tab.
  10. Use the task on the
    Enable User Sign-On
    button to enable SAML SSO.