Unified Access Management (UAM)
Preview Date: 2024-08-17. Production Date: 2025-06-13
We now enable Workday Adaptive Planning customers to:
- Create Adaptive Planning permission sets (action groups) in Workday.
- Assign permission sets to users based on security groups in Workday.
- Sync Workday security groups into Adaptive Planning to manage user access across the application.
Business Benefits
By centrally managing security groups in Workday, administrators can automate:
- Permission set assignment.
- User access to reports, dashboards, modeling, and other application areas.
Changes
You can manage permissions and access for synced Adaptive Planning users from Workday.
When users are assigned to synced Workday security groups, we now include those groups when we send notifications in these areas:
- Processes.
- Reports.
You can now view and select these groups when you:
- Assign process tasks.
- Send notifications to process assignees.
Deployment Considerations
- Test these changes in your non-production environment first. Ensure the new process is delivering the same results as previously.
- Review any existing documentation around permission sets.
- Ensure the Workday Security Administrators are aware of this process and security objects that will exist in the tenant.
What Do I Need to Do?
To request this feature, contact your Named Support Contact to submit a Workday Customer Care request.
Verify these prerequisites:
- User sync is enabled.
- Workday security domains:
- Unified Security Administration(Modify)
- Set Up: Adaptive Planning Group Sync(Modify)
- Adaptive Planning permissions:
- Admin Access>Users
- Admin Access>Permission Sets
Complete these steps in Workday:
- Run theMigrate Adaptive Planning Permission Sets and Assignmentstask.
- Run theUser Permission Comparison Reportto verify that permission set assignments match between Adaptive Planning and Workday.
- (Optional) Adjust any discrepancies in user permissions either in Workday or Adaptive Planning.
- (Optional) If you’re using ISU user:
- Create an ISU user group and add the ISU user to this group.
- Add the ISU user group to theMaintain UAM User Integrationtask.
- Run theActivate UAM Integration with Adaptive Planningtask.
- Run theSubscribe User Groups to Adaptive Planningtask and add security groups that you want to sync to Adaptive Planning.
- (Optional) If you want to sync UAM data to Adaptive Planning in real time, run theNotify Authorization Policy Changes to Adaptive Planningtask.
After you complete these configuration steps, user permissions will be managed from Workday and security groups will be synced to Adaptive Planning. You can then use synced Workday security groups in Adaptive Planning.
After implementing UAM, you can disable these APIs:
- permissionSets
- groups
What Happens If I Do Nothing?
You'll see no changes in Adaptive Planning. You’ll continue to manage permission sets, assignments, and user groups in Adaptive Planning.