1. Administration and security
  2. Administration
  3. Self Service SAML
  4. Manage your Anaplan SSO certificate
  5. Rotate an Anaplan certificate

Once you receive a notification email from Anaplan, your tenant security administrator should rotate to update your Anaplan certificate before the expiry date.

When you rotate your Anaplan certificate, you automatically download the latest Anaplan X509 certificate. You must then upload that certificate to your associated identity service provider (ISP). 

Important: You must update your account with your ISP to use your new Anaplan certificate. You may be locked out of Anaplan if you do not update your ISP account.

To rotate your Anaplan certificate:

  1. Navigate to Security > Single Sign-on
  2. Select your connection
  3. Select the Metadata tab
  4. Under Anaplan X509 certificate, click Rotate
    The Rotate SSO certificate dialog displays.
  5. Click Rotate certificate
    The confirmation dialog displays.
  6. Click Close to close the confirmation dialog.
  7. Log into your ISP, such as Okta or Azure Active Directory, and update your Anaplan certificate in their interface. 
The Metadata tab in Single Sign-on with the Rotate link for Anaplan X509 certificate highlighted.

The screenshot below is the next step you would take within Okta.

An example screenshot from the Okta ISP where you can upload a certificate.


We may update our documentation occasionally, but will only do so in a way that does not negatively affect the features and functionality of the Anaplan service.