Concept: Unified Provisioning and Authentication System
Unified Provisioning and Authentication System (UPAS) provides these main capabilities for Workday Adaptive Planning:
- User Provisioning Workspace (UPW) for configuring and managing user provisioning.
- Single sign-on (SSO) from Workday to Adaptive Planning. User can sign in:
- Directly to individual Adaptive Planning instances without having to go through a worklet.
- Using either the Workday UI or the Adaptive Planning instance-specific URL or vanity URL.
- A migration task in UPW to update user instance assignment information in Workday. This task automatically generates the necessary security and provisioning groups.
- Enhanced authentication experience with a cleaner interface, improved security, and new password recovery options in Workday:
- Updates to the native sign-in page.
- Improved SMS enrollment flow.
- New password reset option based on phone-number.
- Authentication for Adaptive Planning APIs that work with OAuth 2.0. You can authenticate to the Adaptive Planning APIs in exactly the same way you authenticate to Workday APIs.
UPAS Configuration
Depending on whether you're configuring SSO and user sync for the first time or not, you can pursue either option:
- If you are configuring SSO and user sync for the first time, then you can follow the recommended UPAS method. See Steps: Configure UPAS for Adaptive Planning (For First-Time Implementations).
- If you have already configured SSO and user sync using the legacy method, then you can migrate to UPAS. See Steps: Migrate to UPAS from Current User Sync Setup .