Skip to main content
Administrator Guide
Last Updated: 2026-07-24
FAQ: Unified User Provisioning and Authentication: Instance Assignment

FAQ: Unified User Provisioning and Authentication: Instance Assignment

Today, I manually assign users with correct instances in a multi-instance hierarchy. How does it change with Unified Provisioning and Authentication System (UPAS)?
For UPAS, you don't need to configure instance assignment in a multi-instance hierarchy. The instance assignment happens automatically based on the provisioning groups in the User Provisioning Workspace (UPW).
What’s the impact of Unified Provisioning and Authentication System (UPAS) on Integration System Users (ISU)?
With UPAS, you can sync ISU users from Workday to Adaptive Planning through UPW. You don't need to manually add ISU users to the Tenant Setup Report.
What changes do I need to make for API authentication?
You don't need to make any changes for API authentication.
What changes do end users experience with UPAS?
End-user sign-in experience is enhanced. They can sign in using either method:
  • Sign in to Workday HCM or Financials and then SSO into Adaptive Planning.
  • Use the Adaptive Planning instance specific URL and authenticate through Workday HCM or Financials.
What happens to the security groups used for the current user sync method?
Nothing happens. UPAS configuration doesn’t impact these security groups.
How are UPW and UAM security groups related?
They aren't related. You can use the same or different security groups for UPW and UAM.
In which environment do I test UPAS? Can I use Sandbox for the test?
No, we recommend using an IMPL environment for testing the UPAS implementation. You shouldn't use a sandbox environment because it gets refreshed every week. During refresh, the UPAS and Unified Access Management (UAM) policies get wiped out from production.
How do I check or know if my tenant is UPAS enabled?
When UPAS is enabled and working, you can view an additional
BeaconID
field on the All Users list page in Adaptive Planning. The BeaconID is an internal ID that links users between Workday and Adaptive Planning.
Why don't I see a migration button on UPW?
The migration option is only required for tenants that are already configured with existing user sync. If your tenant was never configured for user sync, then you don’t see the migration option.
Can I reverse or disable UPAS after enabling it?
No. After enabling UPAS, you can't disable it and revert back to legacy user sync.
What happens when a user is terminated in Workday HCM after being synced into Adaptive Planning?
If users are removed from Workday, they're also removed from Adaptive Planning automatically.
What’s the purpose of the preview report?
The preview report pulls user data from Adaptive Planning and compares it with the user data in the provisioning group in UPW. The preview report also resets and forces a full user sync.