Example: Alternate Sign-In Option for OfficeConnect
This example illustrates 1 way to configure an authentication selector that enables users to
select a different sign-in flow when their usual sign-in isn't desirable.
The desired authentication flow at your company, Global Modern Services (GMS), redirects users
to:
- Your SAML Identity Provider (IdP) for Single Sign-On when they access your company URL from a browser that Workday recognizes as a standard computer.
- The GMS sign-in page when they access your company URL from a browser that Workday recognizes as from a mobile device.
- You must have security administrator privileges.
- You must set up your tenant for SP-initiated SAML.
- Security:Set Up: Tenant Setup - Securitydomain in the System functional area.
- Access theEdit Tenant Setup - Securitytask.
- In theRedirection URLsgrid in theSingle Sign-onsection, selectAuthentication Selectorfor theRedirect Type.
- In theAuthentication Selectorfield, selectCreate Authentication Selector, and name the authentication selectorMultiple Auth Paths.
- Add a row in theRedirection URLsgrid for OfficeConnect users:
Option Description NameOfficeConnect Sign-InLogin Redirect URLhttps://myworkday.com/gms/login-saml2.htmldMobile Browser Login Redirect URLhttps://myworkday.com/gms/login-saml2.htmld - Add another row for all other users:
Option Description NameGMS Sign-InLogin Redirect URLhttps://myworkday.com/gms/login-saml2.htmldMobile Browser Login Redirect URLhttps://www.gms.com - ClickOK.
- ClickOKandDone.
When users enter the GMS company URL into a browser, a sign-in page with 2 options displays:
- GMS Sign-In
- OfficeConnect Sign-In
GMS Sign-In
and OfficeConnect
Sign-In
options redirect them to the IdP for sign-in. If the user
accesses the sign-in page from a computer with mobile characteristics:- TheGMS Sign-Inoption redirects them to the GMS home page.
- TheOfficeConnect Sign-Inoption redirects them to the IdP for sign-in.