Steps: Set Up SAML SSO into Adaptive Planning Without User Sync
- You must work with a Workday-certified implementer to use or configure this feature. If you don't have access to a certified implementer, contact your Customer Success Manager to engage professional services.
- In Adaptive Planning:
- Configure an IdP provider, like Okta, in Adaptive Planning for signing in. Post-configuration, verify thatAllow only SAML SSOis selected under .
- Configure your instance for Workday using Workday Tenant ID, Environment, UI URL, and REST URL.
- Security:
- Access Adaptive Planningdomain in the Adaptive Planning functional area of Workday.
- In Adaptive Planning, verify that you have Admin Access with these permissions to enable user sign-in to configure Security Assertion Markup Language (SAML) Single Sign-On (SSO) in Workday.
- Users.
- SAML.
- Permission Sets.
- Manage Global User Groups.
- General Setup.
This SSO configuration is valid when:
- You only want to use SSO from Workday.Users can access Adaptive Planning with either theAdaptive Planningworklet on their WorkdayHomepage or through their IdP provider.
- You want to:
- Manually maintain both the Workday and Adaptive Planning user profile for each user independently from each other.
- Continue to receive Adaptive Planning alerts as emails.
- Continue to use your Adaptive Planning credentials for OfficeConnect and public APIs.
- You don't want to publish plans to HCM and Financials.
- As a security admin, verify you copied and edited theAll Workday Accountsstandard report with additional row columns for theWorkday IDfield.Use information from this report to obtain the Workday Federation ID for every planning user requiring SSO into Adaptive Planning. The username is part of the Workday Federation ID, which follows this pattern: workdayUserName@TenantID.EnvironmentSecurity:Workday Accountsdomain in the System functional area.
- Sign in to Adaptive Planning as a user with administrative privileges.
- SelectAdministrationfrom the main menu.
- SelectUsersin theUsers and Permissionssection.
- Find and edit the administrator user and enter their Workday ID.The administrator user is the Workday security admin doing the SSO configuration.
- Enter the Workday Federation ID for all users and the security administrator enabling SSO.
- In Workday, access theTenant Setupreport.Security:
- Set Up: Systemin the System functional area.
- Set Up: Tenant Setup - Adaptive Planningin the System functional area.
- Set Up: Tenant Setup - Generalin the System functional area.
- Select theAdaptive Planningtab.
- Select theUser Sign-Ontab.
- Use the task on theEnable User Sign-Onbutton to enable SAML SSO.