Skip to main content
Administrator Guide
Last Updated: 2024-09-06
Concept: Mobile Authentication

Concept: Mobile Authentication

To enable users to access Workday quickly from a mobile device, Workday provides these separately configurable types of mobile authentication:
  • Mobile personal identification number (PIN)
  • Biometric
You can set up mobile authentication on the
Edit Tenant Setup - Security
task. Your users can then use or skip the mobile authentication you set up when they sign in to Workday. After they sign in, they can make further mobile authentication changes in their settings.
Users might need to use their primary authentication type (example: User Name Password or Single Sign-On (SSO)) in these situations:
  • Before they create a mobile PIN.
  • When they can't use mobile authentication. Example: When Workday requires them to set up a new PIN after too many failed PIN sign-in attempts.
  • When they sign in to Workday using any other client.
You can run the
Signons and Attempted Signons
report to monitor and troubleshoot tenants that have mobile authentication enabled.
Workday doesn't support passwordless sign-in (also known as web authentication) as a primary authentication type on the Workday mobile apps.

Mobile PIN Authentication

To use mobile PIN authentication to access their Workday account, users must create a PIN for:
  • Each device
  • Each client on a single device
They can specify the same PIN for each device or client.

Biometric Authentication

Workday automatically enables biometric authentication in your tenant. Biometric authentication enables users to access Workday using these authentication options on supported devices:
  • Fingerprint authentication (Touch ID)
  • Face ID
To access their account, users can enable fingerprint authentication or Face ID for each device and for each client on a single device.
Workday supports fingerprint biometric authentication only on Android devices from these manufacturers:
  • Android devices 11.0 or later:
    • Google
    • HTC
    • Huawei Nexus 6P
    • LG
    • Motorola
    • Samsung
    • Sony
  • iPad and iPhone devices iOS 17.0 or later
Users with supported iPhone devices can also authenticate using Face ID.
Workday doesn't support any facial biometric authentication on any of the Android devices. These devices use Android's biometric API to verify the user's identity.

Authentication for the Desktop Experience

Mobile authentication is interdependent on the primary authentication policies used for the Workday desktop experience. Your authentication configuration for desktop will affect your mobile authentication. See Concept: Authentication Policies.
We recommend that you review your existing authentication rules, IP ranges, and access restrictions to understand how your authentication for the desktop experience will affect your mobile authentication.