Skip to main content
Administrator Guide
Last Updated: 2026-06-26
Steps: Set Up User Provisioning for Workday Learning Powered by Sana

Steps: Set Up User Provisioning for Workday Learning Powered by Sana

You might need to take additional steps to enable this feature based on your organization's subscription service agreement. Your organization is either on the Main Service Agreement (MSA) or the Universal Main Service Agreement (UMSA). To determine your organization's subscription service agreement:
  1. Select your profile avatar on
    Workday Community
    .
  2. Select
    Profile
    .
  3. On your profile page, select your organization's name, which is beneath your name and next to your job title.
  4. View your
    Subscription Service Agreement
    value.
If the value is:
Note: UMSA customers don't have Innovation Services tasks and reports in their tenants as these are for MSA customers only. UMSA customers can ignore all information regarding Innovation Services.
  • Your organization must have a Workday Learning, powered by Sana subscription, and your Workday and Sana Learn tenants must be linked.
  • Set up content creators. See Steps: Set Up Learning Content Creators.
  • Confirm Learning Administrator and learner security groups on the
    Learning Access
    domain match your design before you map roles.
User provisioning connects workers in Workday Learning to the integrated Sana Learn authoring and learning experience. You configure provisioning in Workday using the
Manage User Provisioning for Workday Products
worklet and
User Provisioning Workspace
.
Workers need both Workday security access such as the
Manage: Learning Native Content
domain for content creators and provisioned integrated access before they can use
Sana Create
or consume Sana content.
Enabling sync provisions the user accounts in the integrated Sana Learn environment. Review the preview report carefully before you enable sync.
  1. Configure the
    Manage: Sana Learn User Provisioning
    domain.
    1. Access the
      Domain Security Policies for Functional Area
      report or the
      View Domain
      report.
    2. Open the
      Manage: Sana Learn User Provisioning
      domain.
    3. From the related actions menu, select
      Domain Security Policy
      Create Security Policy
      .
    4. Add a security group for workers who will configure Sana Learn provisioning and grant
      View
      and
      Modify
      access.
    5. Activate Pending Security Policy Changes.
  2. Add the
    Manage User Provisioning for Workday Products
    worklet to the global navigation sidebar.
    1. On the global navigation sidebar, click the
      Settings
      icon.
    2. Click
      Add Menu Items
      .
    3. Search and select
      Manage User Provisioning for Workday Products
      .
    4. Click
      Add Item
      and
      Save Changes
      .
  3. Configure the
    Setup: Security Groups for User Provisioning
    domain and register security groups.
    1. Access the
      Domain Security Policies for Functional Area
      report or the
      View Domain
      report.
    2. Open the
      Setup: Security Groups for User Provisioning
      domain.
    3. From the related actions menu, select
      Domain Security Policy
      Create Security Policy
      .
    4. Add your security administrator group with
      View
      and
      Modify
      access.
    5. Access the
      Set Up Security Groups for User Provisioning
      task.
    6. Add these security groups:
      • Learning Administrator
      • Learning Content Creator
      • Learner groups on the
        Learning Access
        domain. Example: All Employees, if that group is on your
        Learning Access
        domain policy.
  4. Map Sana Learn roles to Workday security groups.
    1. In Workday, select the
      Manage User Provisioning for Workday Products
      worklet.
    2. From the
      User Provisioning Workspace Links
      section, click
      User Provisioning Workspace
      .
    3. From the
      Products
      section of the Workspace landing page, click
      Configure
      on the Sana Learn.
    4. Using the
      Workday Security Groups
      drop-down, add one or more security groups to the provisioning group. Only security groups that you enabled for user provisioning in the
      Manage User Provisioning for Workday Products
      worklet are available in the drop-down.
      Application role
      Workday security group
      Administrator
      Learning Administrator
      Content creator
      Learning Content Creator or your custom content creator group.
      Learner
      Security groups on the
      Learning Access
      domain.
    5. Click
      Update Provisioning Group
      .
  5. Preview and enable sync.
    1. Access the
      Preview Report
      in the
      Configuration
      tab of a provisioning group.
    2. Click
      Preview and Enable Sync
      .
    3. Click
      Generate Preview Report
      . It can take time for the report to generate. You can safely exit out of the User Provisioning Workspace and check back later for the results of the report.
    4. Review the report to confirm:
      • Expected workers appear.
      • Each worker has the correct role.
      • Workers who shouldn't be provisioned aren't listed.
    5. Select the acknowledgment checkbox for enabling sync.
    6. Click
      Enable Sync
      . The
      Sync
      label will change from
      Off
      to
      On
      once synchronization is complete. You can also access the
      Sync Report
      tab to assess any provisioning or deprovisioning errors during synchronization.
Provisioned workers can authenticate into the integrated Sana Learn experience from Workday Learning. Workers with content creator security access can use
Sana Create
from the
Learning Admin Hub
. Learners can open the
Sana Content
lesson from Workday Learning courses.
Next Steps