Workspace administrators can assign exception users within models. Exception users are users that can log in to Anaplan with either SSO or basic authentication (email address and password). 

Review these prerequisites before you assign exception users.

PrerequisiteNotes
Amount of exception users

We recommend that your company assigns at least one exception user. 

It's best practice to keep the number of exception users to a minimum, or instead use Certificate Authority authentication.

When to assign exception users

Your company should only assign exception users when:

  • You need a backup for when you log in to SSO (exception users can log in with both SSO and basic authentication).
  • You require basic authentication for APIs (though you can also use CA certifications).
Model requirementsBefore you assign an exception user, make sure to reload the model. This action unloads and loads the model back into memory so the Single Sign-on column in the Users list displays.
Friendly URLYour business must schedule an appropriate time to enforce SSO. It's crucial that your company explains to employees how to access the friendly URL. Note that the friendly URL format has specific configuration requirements.
MailboxException users must have access to an active mailbox to receive password reset emails.
Exception user assignment in Administration

If a tenant administrator turns on the Limit exception user assignment to Administration only switch in the Administration console, you're unable to assign exception users within models: 

  • Only tenant security administrators can assign exception users in Administration.
  • Workspace administrators are unable to select the model's Single Sign-on column (checkboxes). They also are unable to assign exception users within models.

To assign an exception user:

  1. Open a model.
  2. Select Manage models .
  3. Reload the model and reopen it.
  4. Select Users in the model settings bar.
  5. In Single Sign-on column, deselect the Single Sign-on checkbox to assign the exception user.
    Notes:
    • If you don't see the Single Sign-on column in the user table, scroll to the right. 
    • If you still don't see the column, see the Troubleshoot the Single Sign-on column section below.

You can remove exception user access. When you remove their access, they're limited to an SSO login.

To enforce SAML SSO authentication:

  1. Select Users in the model settings bar.
  2. In Single Sign-on column, select the Single Sign-on checkbox for the exception user that you want to enforce SSO authentication only.
    Note: Assigned exception users don't have the Single Sign-on checkbox selected.
  3. If you have more than one workspace, repeat this step for each workspace.

When you enable SSO authentication in your workspace, the Single Sign-on column may not display immediately. If the column doesn't display, close and reopen the model to reload it. When you reload a model, it unloads and loads it back into memory.

To reload the model:

  1. Select Manage models in the model settings bar.
  2. Select the Manage Tasks tab.
  3. Select the model you want to close and select Close Model.
  4. Reopen the model.
    The Single Sign-on column displays in the model.

To display the Single Sign-on column in all models in your workspace, have all your users logout from Anaplan to unload the models. If the Single Sign-on column still doesn't display, contact Anaplan Support.