Skip to main content
Administrator Guide
Last Updated: 2026-07-24
Steps: Migrate to UPAS from Current User Sync Setup

Steps: Migrate to UPAS from Current User Sync Setup

  • Workday to Adaptive Planning User Sync is configured. See Steps: Set Up SAML SSO into Adaptive Planning for Synced Users.
  • Unified Access Management (UAM) is configured. See Steps: Set Up Unified Access Management (UAM).
  • For Adaptive Planning multi-instance setup:
    • The implementor (admin) needs to be part of the parent instance.
    • The parent instance must be set up as the default instance.
  • Enable the Adaptive Planning functional area.
  • If you haven't already enabled global navigation in core Workday:
    1. Access the
      Maintain Feature Opt-Ins
      report.
    2. Search for
      Global Navigation Menu Categories
      under
      Features
      and select
      Opt In to Feature
      .
    3. Sign in and sign out to see the new navigation menu.
  • Security: These domains in the System functional area:
    • Set Up: User Provisioning
    • Report: User Provisioning Status
    • Manage: Workday Adaptive Planning User Provisioning
If you have previously configured single sign-on (SSO) and user sync for Workday Adaptive Planning, then you can migrate to Unified Provisioning and Authentication System (UPAS). UPAS provides a more streamlined and secure method for managing user access. Key benefits include:
  • Simplified administration: Centrally manage user access to Adaptive Planning instances through security groups.
  • Enhanced User Sync:
    • Real-time user sync for user-based security groups and hourly user sync for role-based security groups.
    • Option to trigger full user sync to correct user discrepancies.
    • Support for ISU users.
  • Automated instance assignment through user sync configuration. You don't need to manually assign instances from the user profile or users list pages in Adaptive Planning.
  • Improved user experience: Provide an enhanced and unified sign-in experience for users accessing Adaptive Planning.
To enable UPAS for a non-production environment, use a Workday IMPL tenant rather than Sandbox. Due to the weekly tenant refresh, Sandbox tenants are wiped of any changes you make to authentication. This results in users not being able sign in.
During the migration steps, after you confirm the authentication switch over to UPAS, the Tenant Setup report reflects these UI changes:
  • The Adaptive Planning tab becomes simplified into a single tab for connected functionalities.
  • The Single Sign On and User Sync tabs are removed because UPAS doesn't require these configurations.
  • The Public APIs with ISU users is removed because UPAS handles public APIs similar to Workday APIs. You can now configure API Clients directly in Workday.
  • The Adaptive Planning Publish Plans OAuth Client is no longer needed and is removed.
  1. In Workday, configure access to User Provisioning Workspace (UPW).
  2. On the Workday Home page, from the
    Global Navigation Menu
    , access the
    Manage User Provisioning for Workday Products
    worklet. Click
    User Provisioning Workspace
    .
  3. From the
    Products
    page, for each of your Adaptive Planning instances, select
    Configure
    .
  4. In the Configuration tab, click
    Migrate
    .
    The migrate task syncs Adaptive Planning instance assignments with UPW and automatically creates security and provisioning groups based on existing Adaptive Planning configurations.
  5. Review the errors and click
    Continue
    .
  6. Click
    Preview and Approve
    :
    1. Use the
      Generate Preview Report
      to verify that all user information, security groups, and provisioning groups migrated correctly.
    2. If the data is accurate, click
      Approve
      .
  7. After completing the migration for all your Adaptive Planning instances, click
    Enable Sync for Adaptive Products
    .
  8. Select the options to confirm that your current SSO to Adaptive Planning and User Sync will be disabled and new worklets will be created for each Adaptive Planning instance. Then, click
    Confirm and Enable
    .
  9. Validate that users are synced into Adaptive Planning:
    1. In Adaptive Planning, from the main menu, select
      Administration
      .
    2. Under
      Users and Permissions
      , click the
      Users
      link.
    3. On the users list page, check the
      Last Sync Time
      column.
  10. To make UAM aware of UPAS users, access the
    Maintain UAM User Integration
    task and add all the security groups used in User Provisioning Workspace (UPW). If you have Adaptive Planning multi-instances, repeat this step for each instance.
  11. In Workday, access the
    Enable Adaptive Planning Authentication with UPAS
    task and select the confirmation checkbox to switch over authentication to UPAS. Click
    OK
    .
  12. (Optional) To enable users to sign in to the OfficeConnect add-in, add these users to the
    Access Adaptive Planning
    domain in the Adaptive Planning functional area.
  13. Authenticate to Adaptive Planning through UPAS using either of these options:
    • On the Workday Home page, from the
      Global Navigation Menu
      , click
      More
      and then click an Adaptive Planning instance. You are logged in to Adaptive Planning using single sign-on (SSO).
    • In Adaptive Planning, from the main menu, click
      Administration
      System
      General Setup
      . Copy and paste the
      Application URL
      into a browser tab. If you're not authenticated, you need to authenticate to Workday.