Steps: Migrate to UPA from Current User Sync Setup
- Workday to Adaptive Planning User Sync is configured. See Steps: Set Up SAML SSO into Adaptive Planning for Synced Users.
- Unified Access Management (UAM) is configured. See Steps: Set Up Unified Access Management (UAM).
- For Adaptive Planning multi-instance setup:
- The implementor (admin) needs to be part of the parent instance.
- The parent instance must be set up as the default instance.
- Security: These domains in the System functional area:
- Set Up: User Provisioning
- Report: User Provisioning Status
- Manage: Workday Adaptive Planning User Provisioning
If you have previously configured single sign-on (SSO) and user sync for Workday Adaptive Planning, then you can migrate to Unified User Provisioning and Authentication (UPA). UPA provides a more streamlined and secure method for managing user access. Key benefits include:
- Simplified administration: Centrally manage user access to Adaptive Planning instances through security groups.
- Enhanced User Sync:
- Real-time user sync for user-based security groups and hourly user sync for role-based security groups.
- Option to trigger full user sync to correct user discrepancies.
- Support for ISU users.
- Automated instance assignment through user sync configuration. You don't need to manually assign instances from the user profile or users list pages in Adaptive Planning.
- Improved user experience: Provide an enhanced and unified sign-in experience for users accessing Adaptive Planning.
- In Workday, configure access to User Provisioning Workspace (UPW).
- On the Workday Home page, from theGlobal Navigation Menu, access theManage User Provisioning for Workday Productsworklet. ClickUser Provisioning Workspace.
- From theProductspage, for each of your Adaptive Planning instances, selectConfigure.
- In the Configuration tab, clickMigrate.The migrate task syncs Adaptive Planning instance assignments with UPW and automatically creates security and provisioning groups based on existing Adaptive Planning configurations.
- Review the errors and clickContinue.
- ClickPreview and Approve:
- Use theGenerate Preview Reportto verify that all user information, security groups, and provisioning groups migrated correctly.
- If the data is accurate, clickApprove.
- After completing the migration for all your Adaptive Planning instances, clickEnable Sync for Adaptive Products.
- Select the options to confirm that your current SSO to Adaptive Planning and User Sync will be disabled and new worklets will be created for each Adaptive Planning instance. Then, clickConfirm and Enable.
- Validate that users are synced into Adaptive Planning:
- In Adaptive Planning, from the main menu, selectAdministration.
- UnderUsers and Permissions, click theUserslink.
- On the users list page, check theLast Sync Timecolumn.
- To make UAM aware of UPA users, access theMaintain UAM User Integrationtask and add all the security groups used in User Provisioning Workspace (UPW). If you have Adaptive Planning multi-instances, repeat this step for each instance.
- In Workday, access theEnable Adaptive Planning Setup for UPCtask and select the confirmation checkbox to switch over authentication to UPA. ClickOK.
- Authenticate to Adaptive Planning through UPA using either of these options:
- On the Workday Home page, from theGlobal Navigation Menu, clickMoreand then click an Adaptive Planning instance. You are logged in to Adaptive Planning using single sign-on (SSO).
- In Adaptive Planning, from the main menu, click . Copy and paste theApplication URLinto a browser tab. If you're not authenticated, you need to authenticate to Workday.