This glossary explains terms used with Single Sign-on (SSO).

SSO termExplanation
AuthnRequestThe outbound request from Anaplan to client.
AuthnResponseThe inbound request from client to Anaplan.
Exception UserA user that still able use the standard login mechanism at the Anaplan URL, which is useful if the Friendly URL is not working properly. This must be an Anaplan Workspace Administrator.
Friendly URLThe URL created by Anaplan for an SSO server. This URL is required by the client and should be positioned on the client intranet. Click this link to start an SP initiated request. Note that the Friendly URL format has specific configuration requirements.

Identity Provider (IdP)


An entity that generates an authentication assertion as proof that a user has been authenticated.
Identity Provider (IdP) initiated SAML AuthenticationSAML Authentication starts at the Identity Provider, which is the client. The client sends a SAML Response that contains all necessary authentication information. An IdP initiated SAML Authentication contains only a Response, rather than a Request and a Response.
Relying PartyA term for the Service Provider as an entity trusting the Identity Provider to authenticate users.
SAMLSecurity Assertion Markup Language is an authentication protocol. Anaplan has implemented the standard SAML 2.0 framework. Further information on SAML can be found on Wikipedia http://en.wikipedia.org/ wiki/Security_Assertion_Markup_Language.
Server TypeAnaplan can deal with two distinct authentication protocols. The Anaplan SSO and SAML2.0. Choosing the "SAML" server type shows other fields to further define how the client's SAML SSO Server is configured.
Service Provider (SP)An entity providing a service (Anaplan is a Service Provider). To provide the service, the SP must receive authentication and authorization from the IdP.
Service Provider (SP) initiated SAML AuthenticationSAML Authentication starts at the Service Provider, which is Anaplan. This triggers an AuthnRequest to a client. The client replies with a SAML Response. An SP Initiated SAML Authentication encapsulates both a Request and Response.
Single Sign On (SSO) ServerThis can be provided by the SAML 2.0 protocol or through a custom built Anaplan SSO.
SSO UserAny client user that clicks on the "Friendly link" to access their models through SSO (SAML).