Skip to main content
Administrator Guide
Last Updated: 2024-11-15
Steps: Set Up User Provision for Strategic Sourcing

Steps: Set Up User Provision for Strategic Sourcing

Enable Single-Sign On for Workday Strategic Sourcing.
If you don't enable Workday SSO, Strategic Sourcing sends an invitation email to each user that has been invited to Strategic Sourcing with the User Provision Workspace.
Security:
  • Set Up: User Provisioning
    domain in the System functional area.
  • Manage: Workday Strategic Sourcing User Provisioning
    domain in the System functional area.
  • Report: User Provisioning Status
    domain in the System functional area.
The User Provisioning Workspace (UPW) enables you to authenticate, provision, and sync users to Workday Strategic Sourcing.
Workday recommends using roles like security administrator to set up the UPW, while account managers can configure supported products and view error reports.
You must have Workday SSO enabled before you can provision accounts with the UPW. If you have existing connectors with Workday in place, Workday SSO is likely also enabled.
When you enable UPW, all existing users are prompted to do a one-time email address confirmation the next time they sign in to Strategic Sourcing.
When you enable UPW in your Strategic Sourcing Sandbox, no changes should be made to the Workday tenant connected to the Sandbox. Any changes may result in different Workday IDs between systems and difficulty signing into Strategic Sourcing.
A user's Strategic Sourcing account email address must match their Primary Work Email in Workday. If users have different email addresses associated with Workday and Strategic Sourcing, they can’t be provisioned. To resolve this, we recommend changing email addresses in Workday. Email addresses in Strategic Sourcing can't be automatically updated.
When you have Workday SSO enabled for users with your organization’s email domain that is set in the Strategic Sourcing identity connection, individual users are not sent sign-in email notifications when they're added to Strategic Sourcing with the UPW. Workday recommends testing Workday SSO to ensure it is set up correctly to avoid triggering email notifications.
  1. In Workday, create a user-based security group. You can use an existing group for this task.
    You can also use a role-based security group, but expect up to an hour delay for security group membership changes to be reflected in Strategic Sourcing. User-based security group changes will be reflected in near real-time.
  2. Edit the security policy permissions for the security group. Provide that group
    View
    and
    Modify
    access in the
    Report/Task Permissions
    section. Configure these domains in the System functional area:
    • Set Up: User Provisioning
      . This domain provides access to a task for configuring security groups, for use in the User Provisioning Workspace (UPW).
    • Manage: Workday Strategic Sourcing User Provisioning
      . This domain provides access to UPW and enables you to configure user provisioning for Strategic Sourcing.
    • Reports: User Provisioning Status
      . This domain enables users to view the Sync Report in UPW.
  3. Access the
    Activate All Pending Authentication Policy Changes
    task. Add a required comment on the page and click
    Okay
    .
  4. Configuring this task enables users from the security group to automatically sync with the UPW, which then syncs with Strategic Sourcing.
  5. Create provisioning groups, populate them with security groups, and associate those provisioning groups with Strategic Sourcing in the Workspace.
  6. Create a Preview Report and enable sync between Strategic Sourcing and Workday.
    The Preview Report labels users who are already registered in Strategic Sourcing as
    Not in Provisioning Group
    . These users remain in Strategic Sourcing but their User ID isn’t synced with Workday, because they aren't included in an allowed Provisioning Group. Workday recommends adding the security groups of these users to the UPW.
    In the report, the Error Type column defines whether the error is a data or system error. Address any data errors that occur. System errors will attempt to self-correct within a few hours.
    A common error is Invalid resource: Username is required. When you receive this error, the user's Primary Work Email hasn't been set in Workday or doesn't match the domain set up in the Strategic Sourcing identity connection.
  7. To sync users, select
    Preview and Enable Sync
    from the
    Configuration
    page of Strategic Sourcing in Workday. Click both the check box and
    Enable Sync
    options to proceed with synchronization.
  8. In Strategic Sourcing, access the
    User List
    in your settings to modify the
    User Type
    of your provisioned users.
Access
Settings
User List
in Strategic Sourcing to verify that users have been provisioned. The UPW provisions all new users as stakeholders. A company administrator will need to upgrade access for licensed users.