English

When you assign a workspace to single sign-on (SSO), all users become SSO users by default.

Once SSO is set up, exception users can log in with SSO or log in with the standard login mechanism at this Anaplan URL: https://sdp.anaplan.com/frontdoor/login.

Your organization should only use exception users for:

  • Users who run v2 and v1.3 APIs and authenticate using basic authentication
  • Support situations

It's a best practice to keep the number of exception users to a minimum or instead use Certificate Authority authentication.

Note: Once SSO is set up, users can only access Anaplan with SSO unless they are an exception user. We recommend that your organization assigns at least one exception user.

Your business must schedule an appropriate time to enforce SSO. It is essential that your organization educates end users on how to access the friendly URL. Note that the friendly URL format has specific configuration requirements.

To assign a user as an exception user:

  1. Select Users in the model settings bar.
  2. In Single Sign-on column, clear the Single Sign-on checkbox for the exception user.
    If you don't see the Single Sign-on column in the user table, scroll to the right.
    If you still don't see the column, see the Troubleshoot display of the Single Sign-on checkbox section below.

Enforce SSO authentication

You can change the exception user access so the user account has to use SSO authentication. For example, you might choose a different exception user account in your organization and want the previous exception user to adhere to SSO authentication.

You can enforce SAML SSO authentication for an exception user so that they can no longer use the standard login mechanism at the Anaplan URL.

Note: This associates SSO with a model to which the user has access in the workspace. Once SSO is enforced for a user, they cannot log in with their user name and password at the Anaplan URL.

To enforce SAML SSO authentication for an exception user:

  1. Select Users in the model settings bar.
  2. In Single Sign-on column, select the Single Sign-on checkbox for the exception user user for which you want to enforce SSO.
  3. If you have more than one workspace, repeat this step for each workspace.

Troubleshoot display of the Single Sign-on checkbox

When you enable SSO authentication in your workspace, the Single Sign-on column may not immediately display.  If the column doesn't display, close the model and reopen it. 

To display the Single Sign-on column in your model after you enable SSO:

  1. Select Manage models in the model settings bar.
  2. Select the Manage Tasks tab.
  3. Select the model you want to close and select Close Model.
  4. Reopen the model.
    The Single Sign-on column displays in the model.

To display the Single Sign-on column in all models in your workspace, have all your users logout from Anaplan to unload the models. If the Single Sign-on column doesn't display, contact Support.

Disclaimer

We update Anapedia content regularly to provide the most up-to-date instructions.