Skip to main content
Workday User Guide
Laatst bijgewerkt: 2024-11-15
Troubleshooting: Single Sign-On (SSO) for Workday Strategic Sourcing

Troubleshooting: Single Sign-On (SSO) for Workday Strategic Sourcing

For all users, Workday displays an error indicating something went wrong.

Workday displays the error when all users click the Strategic Sourcing worklet or a Strategic Sourcing link.
You haven't activated account provisioning for Workday Strategic Sourcing.
Access and complete the
Activate Account Provisioning
task in Workday. See Steps: Configure Single Sign-On (SSO) for Workday Strategic Sourcing.

For some users, Workday displays an error indicating something went wrong.

Workday displays the error when some, but not all users click the Strategic Sourcing worklet or a Strategic Sourcing link.
Cause
Solution
The security group that's enabled in the
Activate Account Provisioning
task doesn't include the users.
  1. Access the
    Activate Account Provisioning
    task and select
    Strategic Sourcing
    in the
    Application
    field.
    Security:
    Set Up: Account Provisioning Applications
    domain in the System functional area
  2. Record the security group that's selected in the
    Users to Provision
    field.
  3. Access the
    View Security Groups for User
    task for a user who receives the error.
    Security:
    Security Administration
    domain in the System functional area.
  4. If the user's security groups don't include the security group you recorded, add the user to that security group.
If the user experiencing the issue is a contingent worker, you might need to create a security group that includes contingent workers. See Contingent workers don't have SSO access.
The users' work email addresses aren't set correctly on their Workday profiles.
Ensure that the users have valid work email addresses set in contact information on their worker profiles.
The domain security policy for the Set Up: Account Provisioning Applications domain doesn't exist or isn't configured correctly.
  1. Enter
    domain: Set Up: Account Provisioning Applications
    in global search.
  2. As a related action on the domain, select
    Domain
    Create Security Policy
    , or
    Domain
    Edit Security Policy Permissions
    if a policy exists.
    Security:
    Security Configuration
    domain in the System functional area.
  3. Ensure that these security groups are included in the
    Report/Task Permissions
    grid with
    View
    and
    Modify
    permissions selected:
    • The security group that's selected in the
      Users to Provision
      field on the
      Activate Account Provisioning
      task.
    • The All Employees security group.
    • The security group containing the user setting up the SSO connection. Example: The Implementers security group.
  4. Ensure that the security groups aren't included in the
    Integration Permissions
    grid.
  5. If you made any changes to the domain security permissions, access the
    Activate Pending Security Policy Changes
    task to activate the changes.
The users don't have necessary permissions on the Self-Service: Account domain.
  1. Enter
    domain: Self-Service: Account
    in global search.
  2. As a related action on the domain, select
    Domain
    Edit Domain Security Policy Permissions
    .
    Security:
    Security Configuration
    domain in the System functional area.
  3. Ensure that the users that need to authenticate are included in the
    Report/Task Permissions
    grid in a security group that has
    View
    permissions selected.
  4. If you made any changes to the domain security permissions, access the
    Activate Pending Security Policy Changes
    task to activate the changes.
The email domain of the users is different from your corporate email domain.
Have Workday Support configure the users' email domain as an Identity Connection in Workday Strategic Sourcing.

Contingent workers don't have SSO access.

The security group selected in the
Users to Provision
field on the
Activate Account Provisioning
task doesn't include contingent workers.
  1. Access the
    Create Security Group
    task, select
    Rule Based Security Group
    as the type of tenanted security group, and enter the name All Employees + CWs.
    Security:
    Security Configuration
    domain in the System functional area.
  2. Select
    All Users
    as the
    Baseline Security Group
    , and select
    Create Security Rule
    in the
    Include Members by Rule
    field.
  3. Ensure
    Worker
    is selected in the
    Business Object
    field, and click
    OK
    .
  4. Enter a description for the security rule, and add a rule condition to the
    Rule Conditions
    grid:
    Optie Omschrijving
    And/Or
    And
    Security Field
    Worker Type
    Relational Operator
    in the selection list
    Comparison Type
    Value specified in this filter
    Comparison Value
    Employee
    Contingent Worker
  5. Access the
    Activate Account Provisioning
    task and select
    All Employees + CWs
    in the
    Users to Provision
    field.
    Security:
    Set Up: Account Provisioning Applications
    domain in the System functional area.

Users sign in using SSO, but can't view SSO-synchronized data.

This data in Workday Strategic Sourcing doesn't display to a user:
  • Financial Company and Purchase Order (PO) spend amounts on a synchronized contract.
  • PO information on Supplier Profile.
  • Requisition information on the Project or Event.
The user isn't successfully signed into Workday Strategic Sourcing with Workday SSO.
  1. Ensure that the user has access to the data in Workday.
    Users won't have visibility to data in Workday Strategic Sourcing if they don't have access to it in Workday.
  2. Click
    Sign Out
    in Workday Strategic Sourcing to ensure that the user is signed out of Workday Strategic Sourcing.
  3. Click the Workday Strategic Sourcing worklet in Workday to access Strategic Sourcing.
  4. Confirm that the data is visible.

User timeouts are different between Strategic Sourcing and Workday.

The timeout for a user in Strategic Sourcing is different than timeout set in
Manage SSO Configuration
task.
Review if there are other timeout options set for your users.
  1. Access the
    Maintain Password Rules
    task.
  2. In the
    Default Session Timeout Minutes
    field, review whether the number entered is different from the one selected for the
    Manage SSO Connection
    task.
  3. If preferred, edit the time and use the radio buttons to choose either:
    • Users with no Individual Session Timeout
      . This selection is for users you haven't specified session timeout minutes on the
      Edit Workday Account
      task.
    • Override Session Timeout for All Users
      .