Skip to main content
Administrator Guide
Last Updated: 2023-06-23
Steps: Enable OpenID Connect Authentication with SAML SSO in Customer Central

Steps: Enable OpenID Connect Authentication with SAML SSO in Customer Central

Customer Central Security Administrators can sign in to Customer Central and enable OpenID Connect Authentication (OIDC) for themselves and other users. You can set up SAML Single Sign-On (SSO) authentication the same way in Customer Central as you do in your target tenants.
  1. Sign in to Customer Central as a Customer Central Security Administrator.
  2. Google customers can skip the optional step to complete the
    Max OpenID Connect Session Age
    field. As an OIDC provider, Google doesn't support this feature.
  3. Access the
    Manage Authentication Policies
    report to add OIDC authentication in Customer Central.
    Complete these selections in the authentication policy that you add:
    • From the
      Restricted to Environment
      prompt, select
      Implementation
      or
      Sandbox
      .
    • Define the
      Default Rule for All Users
      .
    • On the
      Specific
      prompt, select
      SAML
      .
    • Select
      Activate All Authentication Policies
      .
  4. Access the
    Edit Customer Central Account for User
    task to add an OpenID identifier for the Customer Central Security Administrator and other Customer Central Administrators or Users.
    The OpenID identifier is typically the user's Gmail ID. Once you've enabled OpenID Authentication in Customer Central, you must configure the Security Administrator's OpenID identifier to sign in to Customer Central again.
    Workday recommends that you assign a password to any new Customer Central user because authentication methods might change.
After you enable your account with OIDC, you can sign in to Customer Central using your Google credentials.