Steps: Set Up SAML SSO into Adaptive Planning for Synced Users
- This article provides instructions for configuring SSO and user sync between Workday and Adaptive Planning using the legacy method. Before you begin. consider these options:
- If you are implementing SSO and user sync for the very first time, we recommend the Unified User Provisioning and Authentication (UPA) method. See Steps: Configure UPA for Adaptive Planning (For First-Time Implementations).
- If you have already implemented SSO and user sync using the legacy method, you can migrate to UPA. See Steps: Migrate to UPA from Current User Sync Setup.
- If you are implementing only SSO without user sync, see Steps: Set Up SAML SSO into Adaptive Planning Without User Sync.
- You must work with a Workday-certified implementer to use or configure this feature. If you don't have access to a certified implementer, contact your Customer Success Manager to engage professional services.
- In Adaptive Planning:
- Configure an IdP provider, like Okta, in Adaptive Planning for signing in. Post-configuration, verify thatAllow only SAML SSOis selected under .
- Configure your instance for Workday using Workday Tenant ID, Environment, UI URL, and REST URL.
- Security:
- In Workday:
- Access Adaptive Planningdomain in the Adaptive Planning functional area.
- Set Up: Systemdomain in the System functional area.
- Set Up: Tenant Setup - Adaptive Planningdomain in the System functional area.
- Set Up: Tenant Setup - Generaldomain in the System functional area.
- In Adaptive Planning, verify that you have Admin Access with these permissions to enable user sign-in to configure Security Assertion Markup Language (SAML) Single Sign-On (SSO) in Workday:
- Users.
- SAML.
- Permission Sets.
- Manage Global User Groups.
- General Setup.
When you configure SAML SSO with user sync, you can automatically sync the Workday and Workday Adaptive Planning profiles of users who have access to:
- Both Workday and Adaptive Planning.
- TheAccess Adaptive Planningdomain in the System and Adaptive Planning functional areas of Workday.
Synced Workday users sign in to Adaptive Planning with a Workday worklet. You can configure the worklet to access Adaptive Planning with or without an IdP provider.
With user sync configured, you can:
- Receive all notifications in Workday.
- Publish plans to Workday.
- Sign in to OfficeConnect using your Workday credentials.
- Use Adaptive Planning public APIs with your Workday credentials.
If you configured SAML SSO to Workday, you must set it up again after the 2019.3 release because of feature improvements.
- In Workday, access theTenant Setupreport.
- (Optional) To enable users to sign in to OfficeConnect using a Workday idP, work with your IdP configurator to:
- Get the IdP sign in information for your Adaptive Planning instance.
- In theSecuritytab, enter the redirect URL information for:
- Login Redirect URL
- Mobile App Login Redirect URL
- Mobile Browser Login Redirect URL
- Select theAdaptive Planningtab.
- Select theUser Sign-Ontab.
- Copy this information:
- Your Workday ID.
- Your Workday Federation ID.
- In Adaptive Planning, selectAdministrationfrom the main menu.
- SelectUsersin theUsers and Permissionssection.
- Edit your user profile and enter this information to manually map your user profiles:
- Workday Federation ID.
- Workday ID.
- In Workday, access theTenant Setupreport.
- Select theAdaptive Planningtab.
- Select theUser Sign-Ontab.
- Use the task on theEnable User Sign-Onbutton to enable SAML SSO and user sync.
- (Optional) Set Up Worklets.If you don't use an IdP provider, configure theAdaptive Planningworklet to sign in users to Adaptive Planning.In theExternal Linkssection for the worklet, you can either:
- SelectSAML SSO link created.
- SelectCreate Quicklink, then enter the name and URL for your Adaptive Planning instance.
In Workday, sync the Workday and Adaptive Planning user profiles of your planners using the
User Sync
tab on the Tenant Setup
report. See Sync Users with Adaptive Planning. After configuring user sync, you can manage permissions and access for synced Adaptive Planning users from Workday. See: