Author: Eric Vasbinder
From time to time, when transforming to the cloud, even though our process is designed to be as much of a "forklift" / "lift and shift" as possible, certain items may be missed and require addressing after the cloud go-live automated processes are complete.
As you move into the cloud, SSO becomes your primary mechanism for users to authenticate to Trimble products. Something critical to note is that, across ALL Trimble products, as well as our platform identity service, the user's email addresses must match. In addition, we should also note that if Federation to an external identity provider, like Okta or Microsoft Entra, is used, both the email address and UPN for that user must match the email addresses listed in our Trimble ID platform, as well as in the Trimble products in question.
NOTE: If you are using other Trimble products that use TID prior to moving into our cloud, such as AccuBid, SketchUp, etc., you should also ensure that the email address assiociated with that user in our Trimble licensing system matches that which is in TID and your IdP. It's a 3-4 way match of emails, depending up on if an external, Federated, IdP is used or not.
In summary, the user's email address must meet the following criteria:
Unique
No spaces
No non-printable characters
Must match from product level (e.g. Vista or Vista Web), to platform level (Trimble ID)
If SSO will be Federated:
Must match their primary email address in their IdP login
Must match the primary UPN for that user in their IdP login
Reocmmendation: Prior to go live, please review the email addresses and usernames that you have for existing Trimble product users, as well as their accounts in Trimble ID (submit a request with management approval to obtain the list of pre-existing user emails from the TID platform). Please ensure these emails all match.
During the process of a cloud transformation, these are the things that our transformation scripts may currently miss:
Workcenters Missing from Main Page: Some workcenters may no longer be show in the user's pages
They still exist - they will just need to be re-added / re-loaded to the user's main workcenter screen
Certain Grid customizations: Such as grid layouts, columns showing, column order, etc. may be lost
You will need to re-create these
User "Favorite" Program and Report Groups: Favorite programs or groups may be missing,
You will need to re-create these.
User Custom Shortcuts: These custom items may be missing after moving from on-premise to the cloud, or from one database server to another.
You will ned to re-create these.
Both the legacy process for SSO, known as Viewpoint ID Legacy SSO, and the new proces, known as Trimble ID Direct SSO, can some times result in group memberships being lost. This happens infrequently, but occurs as a result of the process that either renames or copies and deactivates user accounts from on-premise to prepare those accounts for cloud SSO usage.
Payroll Group Membership: user membership in various payroll groups may rarely be missing after final go-live start
Users will need to be manually added back into the appropriate payroll groups
HQ Reviewers Membership: user membership in HQ Reviewers may also be empty or missing members after final go-live start
Users will need to be manually added by into the HQ Reviewers group, or exports from the on-premise database and manually imported in, taking care to match their old usernames with the new usernames they have after being renamed and activated for SSO. E.g. username COMPANYadDOMAIN\username becomes UserEmail@domain.com_EnterpriseID. That latter username needs to be added to HQ Reviewers.
In addition, please note that due to the design of the Vista application, Vista needs to be fully reinstalled during the go-live process. As such, the trust relationship between Vista and other tools will be broken during the standard go-live process. Given this, our team avoids setting up multiple tools during pre-go-live testing, which means they are only available for review and testing about 1-2 weeks after go-live of Vista and Vista Web (HFF/Keystyle). Again, you will NOT be able to test the following items prior to the go-live of Vista itself. The only exception is for customers that make use of elements of our Enterprise Solutions Bundle (ESB), which is available for an additional cost and provides test environments equivalent to production as well as additional Team Enterprises for pre-go-live testing.
These items include:
Team Project Management
Automated Invoicing
Viewpoint Analytics
Paginated Reports (SSRS in Viewpoint Analytics)
Web-based Crystal Reports (Crystal in Viewpoint Analytics)
The following information is highly dependent on individual user behavior and should be discussed with the Viewpoint team.
With VRL as the access method, some processes can experience slower performance, especially around heavy keyboard data entry (i.e., 10-key experts). This is simply due to the physical distance between the user (client side) and database (cloud data center) and the latency of data communication.
For payroll (PR) time entry directly into Vista, we have observed “10-key experts'' can encounter sub-second delays which are still noticeable. Instead, we recommend one of the following changes:
Strongly recommend our customers use Viewpoint Field Management (formerly Keystyle). This relies on web-browser or native mobile application interfaces for individual employees or supervisors to enter time.
Use an alternative data entry approach, such as Excel or CSV file import.
Use RDP access method for Vista cloud for payroll data entry. Typically the data entry is more responsive, but should be validated.
For accounts payable (AP) transaction entry, we have observed “10-key experts'' can encounter sub-second delays which are still noticeable. Instead, we recommend one of the following changes:
Strongly recommend our customers use Viewpoint Financial Controls (formerly Keystyle). This relies on web-browser or native mobile application interfaces for AP personnel to enter invoices. The caveat here is that Financial Controls only currently handles individual files whereas Vista can employ page splitting technology to separate out documents from a larger document.
Use an alternative data entry approach, such as Excel or CSV file import.
Use RDP access method for Vista cloud for AP data entry. Typically the data entry is more responsive, but should be validated. Note that TSScan will be needed to scan invoices.
Another key category of item to note is that the go live process itself is designed around a factory model, which allow for various different groups to take process handoffs from group to group, ensuring nearly constant activity.
Critically, our overnight team requires that database backups be made available to them by 6pm Pacific time on a weeknight prior to the go-live process start. This means that if your go-live hand off is estimated for a Friday, your backups should be completed and uploads finished prior to 6pm Pacific time.
If the process for the backup uploads extends past that time, it can increase the risk that the hand off to you as the customer occurs either late on Friday, or potentially Saturday, or even the following Monday.
Due to the timing issues mentioned above, most any cloud transformation go-live will require at least 24 hours of production downtime to complete backups, upload, restore, testing, platform pipeline setup, and more, prior to hand off back to the customer.
Finally, due to resource coordination needs, the go-live process does not occur over weekends. As such, this production downtime will take place overnight and during the following weekday after go-live start.
changelog
Thursday, 02 July 2026 at 02:08PM:
Added go-live timing considerations
Thursday, 02 July 2026 at 01:27PM:
Added section on SSO username and email address alignment.
Monday, 30 March 2026 at 11:18AM:
Added additional content