Workspace administrators can assign exception users within models. Exception users are users that can log in to Anaplan with either SSO or basic authentication (email address and password).
Prerequisites
Review these prerequisites before you assign exception users.
| Prerequisite | Notes |
| Amount of exception users | We recommend that your company assigns at least one exception user. It's best practice to keep the number of exception users to a minimum, or instead use Certificate Authority authentication. |
| When to assign exception users | Your company should only assign exception users when:
|
| Model requirements | Before you assign an exception user, make sure to reload the model. This action unloads and loads the model back into memory so the Single Sign-on column in the Users list displays. |
| Friendly URL | Your business must schedule an appropriate time to enforce SSO. It's crucial that your company explains to employees how to access the friendly URL. Note that the friendly URL format has specific configuration requirements. |
| Mailbox | Exception users must have access to an active mailbox to receive password reset emails. |
| Exception user assignment in Administration | If a tenant administrator turns on the Limit exception user assignment to Administration only switch in the Administration console, you're unable to assign exception users within models:
|
Assign exception users
To assign an exception user:
- Open a model.
- Select Manage models .
- Reload the model and reopen it.
- Select Users in the model settings bar.
- In Single Sign-on column, deselect the Single Sign-on checkbox to assign the exception user.
Notes:- If you don't see the Single Sign-on column in the user table, scroll to the right.
- If you still don't see the column, see the Troubleshoot the Single Sign-on column section below.
Remove exception user access
You can remove exception user access. When you remove their access, they're limited to an SSO login.
To enforce SAML SSO authentication:
- Select Users in the model settings bar.
- In Single Sign-on column, select the Single Sign-on checkbox for the exception user that you want to enforce SSO authentication only.
Note: Assigned exception users don't have the Single Sign-on checkbox selected. - If you have more than one workspace, repeat this step for each workspace.
Troubleshoot the Single Sign-on column
When you enable SSO authentication in your workspace, the Single Sign-on column may not display immediately. If the column doesn't display, close and reopen the model to reload it. When you reload a model, it unloads and loads it back into memory.
To reload the model:
- Select Manage models in the model settings bar.
- Select the Manage Tasks tab.
- Select the model you want to close and select Close Model.
- Reopen the model.
The Single Sign-on column displays in the model.
To display the Single Sign-on column in all models in your workspace, have all your users logout from Anaplan to unload the models. If the Single Sign-on column still doesn't display, contact Anaplan Support.