Troubleshooting: Single Sign-On (SSO) for Workday Strategic Sourcing
This topic provides strategies for diagnosing and resolving these SSO for Workday Strategic Sourcing issues:
For all users, Workday displays an error indicating something went wrong.
Workday displays the error when all users click the Strategic Sourcing worklet or a Strategic Sourcing link.
You haven't activated account provisioning for Workday Strategic Sourcing.
Access and complete the
Activate Account Provisioning
task in Workday. See Steps: Configure Single Sign-On (SSO) for Workday Strategic Sourcing.For some users, Workday displays an error indicating something went wrong.
Workday displays the error when some, but not all users click the Strategic Sourcing worklet or a Strategic Sourcing link.
Cause | Solution |
|---|---|
The security group that's enabled in the Activate Account Provisioning task doesn't include the users. |
If the user experiencing the issue is a contingent worker, you might need to create a security group that includes contingent workers. See Contingent workers don't have SSO access. |
The users' work email addresses aren't set correctly on their Workday profiles. | Ensure that the users have valid work email addresses set in contact information on their worker profiles. |
The domain security policy for the Set Up: Account Provisioning Applications domain doesn't exist or isn't configured correctly. |
|
The users don't have necessary permissions on the Self-Service: Account domain. |
|
The email domain of the users is different from your corporate email domain. | Have Workday Support configure the users' email domain as an Identity Connection in Workday Strategic Sourcing. |
Contingent workers don't have SSO access.
The security group selected in the
Users to Provision
field on the Activate Account Provisioning
task doesn't include contingent workers.- Access theCreate Security Grouptask, selectRule Based Security Groupas the type of tenanted security group, and enter the name All Employees + CWs.Security:Security Configurationdomain in the System functional area.
- SelectAll Usersas theBaseline Security Group, and selectCreate Security Rulein theInclude Members by Rulefield.
- EnsureWorkeris selected in theBusiness Objectfield, and clickOK.
- Enter a description for the security rule, and add a rule condition to theRule Conditionsgrid:
Optie Omschrijving And/OrAndSecurity FieldWorker TypeRelational Operatorin the selection listComparison TypeValue specified in this filterComparison ValueEmployeeContingent Worker - Access theActivate Account Provisioningtask and selectAll Employees + CWsin theUsers to Provisionfield.Security:Set Up: Account Provisioning Applicationsdomain in the System functional area.
Users sign in using SSO, but can't view SSO-synchronized data.
This data in Workday Strategic Sourcing doesn't display to a user:
- Financial Company and Purchase Order (PO) spend amounts on a synchronized contract.
- PO information on Supplier Profile.
- Requisition information on the Project or Event.
The user isn't successfully signed into Workday Strategic Sourcing with Workday SSO.
- Ensure that the user has access to the data in Workday.Users won't have visibility to data in Workday Strategic Sourcing if they don't have access to it in Workday.
- ClickSign Outin Workday Strategic Sourcing to ensure that the user is signed out of Workday Strategic Sourcing.
- Click the Workday Strategic Sourcing worklet in Workday to access Strategic Sourcing.
- Confirm that the data is visible.
User timeouts are different between Strategic Sourcing and Workday.
The timeout for a user in Strategic Sourcing is different than timeout set in
Manage SSO Configuration
task. Review if there are other timeout options set for your users.
- Access theMaintain Password Rulestask.
- In theDefault Session Timeout Minutesfield, review whether the number entered is different from the one selected for theManage SSO Connectiontask.
- If preferred, edit the time and use the radio buttons to choose either:
- Users with no Individual Session Timeout. This selection is for users you haven't specified session timeout minutes on theEdit Workday Accounttask.
- Override Session Timeout for All Users.