Steps: Connect SSO Strategic Sourcing with Workday
You need to engage Workday Professional Services:
- During deployment to set up SSO for Workday Strategic Sourcing completely
- When transitioning from the legacy Workday SSO.Note: Workday Professional Services must set up tenant mapping for your Workday tenant in Workday Strategic Sourcing before you can proceed with this procedure.
Implementers can follow the full steps in the SSO Connecting Strategic Sourcing with Workday Community article to complete and troubleshoot connecting SSO.
Security admins can work with implementers to connect a Workday tenant with Workday Strategic Sourcing (WSS).
UPC SSO replaces the Legacy Workday SSO to establish a unified flow between systems. This updated SSO method improves your configuration through:
- Centralized management: Connects infrastructure directly to your tenant through the User Provisioning Workspace (UPW).
- Role mapping: Provisions specific tenanted security groups to defined roles.
- Universal authentication: Consolidates access paths for users.
Workday recommends UPC SSO for all WSS.
- To complete setting up tenant mapping for your tenant in Workday Strategic Sourcing, engage:
- Your implementation partner if you're in implementation.
- The Workday Support Team if you are actively deployed.
- Security:Set Up: User Provisioningdomain in the System functional area.
- Security:Report: User ProvisioningStatus domain in the System functional area.
- Security:Manage: Workday Strategic Sourcing User Provisioningdomain in the System functional area.
- Access theCreate Security Grouptask. ForType of Tenanted Security Groupselect either:
- Role-Based Security Group (Unconstrained)
- User-Based Security Group
Workday recommends provisioning a subset of employee users (or contingent workers) with SSO access to WSS.Note: UPW allows mapping of unconstrained security groups to a WSS role. Workday suggests building out role-based security groups for this use case. - Access theSet Up Security Groups for User Provisioningtask and select the security group you created.
- SelectWorkday Global Navigation Sidebar > Configuration > Manage User Provisioning for Workday Products >User Provisioning Workspace
- In theStrategic Sourcingtile, clickConfigure.
- In theProvision Userssection, clickCreate/Edit Provisioning Group.
- Add the security group you created.
- Map security groups to the associated WSS role.Note: Don't map an Implementers security group to any WSS roles.
- ClickUpdate Provisioning Group.
- Click thePreview and Enable Syncbutton to review.
- Select the checkbox.
- SelectEnable Sync.
- (Optional) If you have the legacy SSO, you can disable it by completing these steps:
- Access theManage Workday SSO Configurationtask.Security:Security Administrationdomain in the system functional area.
- Select theDisablecheckbox.If this option isn’t available, the legacy Workday SSO was not configured in this tenant and no action is needed.
- SelectOK.Note: This step should be completed only after at least one Workday user has successfully synced to WSS, as an Admin, through UPW. Admin access may be lost during the transition otherwise.
On the first login attempt, provisioned users receive an email to confirm ownership of their address. Users must confirm their email address through the provided link to successfully log in to WSS. If a user does not receive the email within 2 hours, they must check their spam folder or click Did not receive confirmation instructions? on the WSS login screen.
Once completed, users can access the WSS product from the Workday tenant global navigation sidebar.
When you complete this procedure, notify:
- Your implementation partner if you're in implementation.
- The Workday Support Team if you are actively deployed.