FAQ
General
Q: What is Planview Admin
A: Planview Admin gives administrators a centralized place to manage users, authentication, and common settings across connected Planview products. Because it's centralized it was intended to be intuitive, self-serviceable, and
User Identity
Users will have a single / common user ID across all Planview applications. Applications such as Roadmaps and OKRs require this common user ID to enable better integrations and reporting. User roles for Roadmaps (and coming soon IdeaPlace) are also managed from Planview Admin.
User Authentication
By using Planview Admin as a common authentication source for all Planview Applications, a user can navigate between applications without having to log in each time. For example, a user can navigate from AgilePlace to Roadmaps using a single identity and authentication provided by Planview Admin.
Planview Admin provides a user an entry point to the Planview applications they have access to. (Coming soon, also to see notifications from various applications in one place)
Settings
Planview Admin is used to configure some application settings such as for OKRs.
Q: How is Planview Admin Different than Planview ID
A: Planview ID is an antiquated term. In the beginning, the original component was a shared SSO across applications and it was known as Planview ID. This component tied authentication together between these applications and made the configuration self-serviceable. As Planview moved toward platform services, there was a need to expand the capabilities to manage uses, configurations, and common settings in one place. Planview ID was rebranded from this need as Planview Admin as it took on more administrative capabilities.
Q: What is SSO, SP, IDP and SAML
A:
SSO – Single Sign On. Single sign on provides a convenience for a user to have a single username and password to sign into various applications used across your enterprise. Your IT department or SSO management team can manage security settings such as password complexity and two-factor authentication in one place for the entire organization.
SP – Service Provider: (Planview Side) Is the software that provides some access control and communicates with the Identity Provider for identity information to make authorization decisions granting or denying access to content based on the attributes about the user, received from the Identity Provider.
IDP – Identity Provider: (Customer Side - such as Microsoft Azure AD, ADFS, Okta, Ping Federated, etc.) This is the system that contains your organization’s users and credentials. The IDP handles user authentication and can securely share that authentication with applications such as Planview Admin.
SAML - Security Assertion Markup Language. This is a message format used between an Identity Provider (IDP) and Planview Admin to securely request for authentication and respond with a user’s identity.
Q: If SSO has been previously setup in other products what happens if SSO is configured in Planview Admin?
A: SSO in Planview Admin will override authentication settings configured in other products after the product has been added and SSO enabled for the product.
Q: What products are available in Planview Admin?
A: The following: Portfolios, AgilePlace, ProjectPlace, Roadmaps, PPM Pro*
*PPM Pro will be excluded from future development for the time being.
Q: Are any additional products coming soon to Planview Admin?
A: The following: Viz, IdeaPlace, Hub, EA
Q: What products are excluded from Planview Admin?
A: The following: AdaptiveWork, Changepoint, Daptiv
User Management
Q: Do we need everyone to create a Planview Admin account before we activate Planview Admin? What happens to a user that doesn’t follow instructions to create it?
A: Yes, everyone should have created their Planview Admin account before you activate Planview Admin SSO. If a user hasn’t created their account before Planview Admin is activated, they will have to go through the Forgot Password process to finish creating their account before they will be able to sign in.
Q: Say on Monday we send the email to users inviting them to create a Planvew ID account, but we don’t activate Planview ID until Friday. Do users use their “old” credentials until Friday?
A: All users will continue using their “old” credentials until Planview ID is activated.
Q: I understand that the product URLs for signing in stay the same. Can I create a new Planview ID account with the same user ID and password as I have in PPM Pro so I wouldn’t care what happens in between getting the email and the activation? Otherwise, I would need to know when the activation happens so that I start using my new password.
A: Great question! All Planview ID accounts will be created with the user’s email as their user ID/login. So, if your user ID in PPM Pro is already richard.hart@paintbynumbers.com, then you could use the same user ID/password combination for your Planview ID account.
Q: Our process today is to create an account in PPM Pro, and then as projects are synchronized with ProjectPlace, the IDs are created in ProjectPlace. During the set up where I connect PPM Pro to Planview Admin, will it take all users in PPM Pro only? What about users that have been sent invitations to join ProjectPlace outside of our process?
A: The recommended process would be to import your PPM Pro users and your ProjectPlace users separately. So, if you have users who only exist in ProjectPlace, they will get imported into Planview Admin without needing a special invitation, but you will have visibility into those accounts in Planview Admin.
Q: I created a User in Planview Admin and then created a user in my Planview product; when I performed a sync, the user in the application was not mapped to the user. What happened?
A: If Planview ID doesn't find a user with a matching email address (say you entered a typo in the user's email address in the Planview product), but the email address is valid, Planview Admin will create a new Planview ID user with that email address, and your original Planview ID user will remain unmapped. You can map the errant user to the one you created. For more information, see Mapping a User.
Q: Why do I get a "user not found" message when logging in with SSO?
A: First, confirm the user has been created in Planview admin. If the user exists, The error is likely a result of an email mismatch between the customer IdP and Planview. This happens when an email used in Planview related to the user is not the Primary email related to that user in their Active Directory. When the user is validated at the IdP, the primary email address is returned, and authentication fails with a "User not found" error message. To resolve this, you will need to work with your IT team to verify what the primary email address is for that user, and adjust that email in Planview to match.
Q: What web browsers are supported by Planview Admin?
A: Planview Admin supports the latest mobile and computer version of Microsoft Edge, Google Chrome, Apple Safari, and Mozilla Firefox.
*NOTE: Application-specific support is considered separate from Planview Admin support.
Security
Q: Does Planview Admin have a disaster recover model?
A: Yes. We are deployed in multiple regulatory regions worldwide, and within each regulatory region, we are deployed to multiple data centers.
Q: Where are the data centers in each region located?
A: US is in Oregon, United States (AWS us-west-2 region) and failover in Ohio (AWS us-east-2 region)
Europe is in Frankfurt, Germany (AWS eu-central-1 region) and failover in Ireland (AWS eu-west-1 region)
APAC is in Sydney, Australia (AWS ap-southeast-2 region) and failover in Mumbai, India (ap-south-1)
Q: Does Planview Admin support FIDO?
A: No, Planview Admin does not support FIDO. However, if it is used as part of 2FA setup on the customer's SAML/SSO provider connected to PV Admin, that should work.