Skip to main content
Administrator Guide
Last Updated: 2026-06-26
Steps: Connect SSO Strategic Sourcing with Workday

Steps: Connect SSO Strategic Sourcing with Workday

You need to engage Workday Professional Services:
  • During deployment to set up SSO for Workday Strategic Sourcing completely
  • When transitioning from the legacy Workday SSO.
    Note: Workday Professional Services must set up tenant mapping for your Workday tenant in Workday Strategic Sourcing before you can proceed with this procedure.
Implementers can follow the full steps in the SSO Connecting Strategic Sourcing with Workday Community article to complete and troubleshoot connecting SSO.
Security admins can work with implementers to connect a Workday tenant with Workday Strategic Sourcing (WSS).
UPC SSO replaces the Legacy Workday SSO to establish a unified flow between systems. This updated SSO method improves your configuration through:
  • Centralized management: Connects infrastructure directly to your tenant through the User Provisioning Workspace (UPW).
  • Role mapping: Provisions specific tenanted security groups to defined roles.
  • Universal authentication: Consolidates access paths for users.
Workday recommends UPC SSO for all WSS.
  1. To complete setting up tenant mapping for your tenant in Workday Strategic Sourcing, engage:
    1. Your implementation partner if you're in implementation.
    2. The Workday Support Team if you are actively deployed.
    • Security:
      Set Up: User Provisioning
      domain in the System functional area.
    • Security:
      Report: User Provisioning
      Status domain in the System functional area.
    • Security:
      Manage: Workday Strategic Sourcing User Provisioning
      domain in the System functional area.
  2. Access the
    Create Security Group
    task. For
    Type of Tenanted Security Group
    select either:
    1. Role-Based Security Group (Unconstrained)
    2. User-Based Security Group
    Workday recommends provisioning a subset of employee users (or contingent workers) with SSO access to WSS.
    Note: UPW allows mapping of unconstrained security groups to a WSS role. Workday suggests building out role-based security groups for this use case.
  3. Access the
    Set Up Security Groups for User Provisioning
    task and select the security group you created.
  4. Select
    Workday Global Navigation Sidebar > Configuration > Manage User Provisioning for Workday Products >User Provisioning Workspace
    1. In the
      Strategic Sourcing
      tile, click
      Configure
      .
    2. In the
      Provision Users
      section, click
      Create/Edit Provisioning Group
      .
    3. Add the security group you created.
    4. Map security groups to the associated WSS role.
      Note: Don't map an Implementers security group to any WSS roles.
    5. Click
      Update Provisioning Group
      .
    6. Click the
      Preview and Enable Sync
      button to review.
    7. Select the checkbox.
    8. Select
      Enable Sync
      .
  5. (Optional) If you have the legacy SSO, you can disable it by completing these steps:
    1. Access the
      Manage Workday SSO Configuration
      task.
      Security:
      Security Administration
      domain in the system functional area.
    2. Select the
      Disable
      checkbox.
      If this option isn’t available, the legacy Workday SSO was not configured in this tenant and no action is needed.
    3. Select
      OK
      .
      Note: This step should be completed only after at least one Workday user has successfully synced to WSS, as an Admin, through UPW. Admin access may be lost during the transition otherwise.
On the first login attempt, provisioned users receive an email to confirm ownership of their address. Users must confirm their email address through the provided link to successfully log in to WSS. If a user does not receive the email within 2 hours, they must check their spam folder or click Did not receive confirmation instructions? on the WSS login screen.
Once completed, users can access the WSS product from the Workday tenant global navigation sidebar.
When you complete this procedure, notify:
  • Your implementation partner if you're in implementation.
  • The Workday Support Team if you are actively deployed.