Reference: Edit Tenant Setup - Security
Manage tenant-wide security and authentication settings in these areas:
Security Email Settings
Option | Description | More Information |
|---|---|---|
Enable Security Emails
| Required for sending:
If checked:
If unchecked:
Password reset emails initiate when:
| |
Bypass Login Redirect for New Accounts
| Includes a URL in new Workday account emails that enables users to:
Example: Enable recruiting agency users with new Workday accounts to sign in to Workday for the first time using their username and password. Workday sends the new Workday account emails with the login redirect URL to new hires and rehires. | |
Email Temporary Password to New Accounts
| Generates temporary passwords automatically and emails the password to the new worker instead of requiring new workers to get their temporary password from their Workday administrator. | |
Enable Forgotten Password Reset
| Enables users to reset their password through the Forgot Password link on the sign-in to Workday page. The Disable All Emails restriction on the Edit Tenant Setup - Notifications task overrides this option and suppresses the Forgot Password link.
If checked, Workday defaults to one-time passcodes
| |
Enable Email Notification On Account Lockout
| Sends a notification to the primary email address of the user the next time they try to sign in after Workday locks their account:
Enable Security Emails check box for users to receive these notifications. |
WebAuthn (FIDO2)
Option | Description | More Information |
|---|---|---|
Enable Web Authentication
| Enables you to specify web authentication as an allowed authentication type on authentication policies. With web authentication enabled, your users can enroll in and use web authentication for passwordless sign in to Workday on supported web browsers. |
Single Sign-On
Option | Description | More Information |
|---|---|---|
Redirection URLs
| Alternate URLs that Workday references when a specific action occurs. Redirect URLs must use HTTPS.
Preview Only ; Workday will use the URL marked as Preview Only in Preview tenants, and the other in Production tenants.
To apply the redirection URLs to your Sandbox Preview or Implementation Preview tenants, select Sandbox or Implementation respectively at the Environment prompt. Those environments also apply to the respective preview tenants. |
OAuth 2.0 Settings
Option | Description | More Information |
|---|---|---|
OAuth 2.0 Clients Enabled
| Enables OAuth 2.0 clients to access the Workday API for your tenant. |
SAML Setup
To enable:
- SAML for your tenant, select theEnable SAML Authenticationcheck box.
- Workday-delivered multifactor authentication for SAML on authentication policies, select theEnable Native Multi-Factor Authenticationcheck box.
Configure options for
each
SAML IdP for your tenant.Option | Description | More Information |
|---|---|---|
Disabled
| You can disable an IdP if it's currently assigned to an authentication policy. You can't disable an IdP if it's in use. | |
Identity Provider Name
| Unique human-readable name for the SAML IdP. | |
Issuer
| Unique identifier for the SAML IdP.
Workday validates a SAML authentication attempt only if:
| |
x509 Certificate
| X.509 public certificate to verify the signature on SAML sign-in and sign-out requests. | |
Enable IdP Initiated Logout
| Workday:
| |
Logout Response URL
| URL to which Workday sends a successful sign-out response when the IdP initiates the sign-out. | |
Enable Workday Initiated Logout
| Workday:
| |
Logout Request URL
| URL to which Workday sends a sign-out request when it initiates the sign-out. | |
Use Unspecified Name ID Format for Logout Request
| Workday generates a SAML logout request with an unspecified Name ID format, rather than X509SubjectName. | |
SP Initiated
| Workday uses this IdP for SP-initiated SAML authentication in the selected environment. | |
Service Provider ID
| The Service Provider (SP) ID configured for the Workday tenant in the SAML IdP setup. It identifies Workday as the service provider in SAML messages sent to this IdP. | |
Sign SP-initiated Request
| Workday signs the SAML requests it sends to the SAML IdP using your SAML public key. | |
Do Not Deflate SP-initiated Request
| Disables deflate compression of SAML requests that Workday sends to a SAML IdP endpoint. Workday automatically uses deflate compression and Base64 encoding when sending SAML requests. Certain SAML IdPs can't parse the SAML request if Workday compresses the SAML request with deflate. | |
Always Require IdP Authentication
| (For SP-initiated SAML authentication) Requires the SAML IdP to force users to reauthenticate, even if they have an existing IdP session. Select ForceAuthn and RequestedAuthnContext if the IdP expects both of these values to force users to reauthenticate. | |
IdP SSO Service URL
| ( SP Initiated selected) - The URL to which Workday sends SAML authentication requests during SP-initiated SAML authentication. Complete this field for any IdP that Workday will use for SP-initiated SAML authentication.
( SP Initiated cleared) - The URL to which Workday sends SAML authentication requests. | |
Managed Device Attribute
| The IdP returns an attribute as part of the SAML assertion when it's configured to use a mobile device management (MDM) provider to determine managed device status. The value you enter in this field must exactly match that attribute name. Example: If the IdP returns isWDManagedDev as the managed device attribute in SAML assertions, you must enter isWDManagedDev in this field. | |
Used for Environments
| If you don't select an environment, Workday uses the same IdP for all environments.
To configure the IdP for use in your Sandbox Preview or Implementation Preview tenants, select Sandbox or Implementation respectively at the Used for Environments prompt. Those environments also apply to the respective preview tenants. | |
Preview Only
| Enables the SAML IdP for Preview tenants for the selected environments only. If the selected environment is Production, you can't select Preview Only .
|
Configure options for
all
SAML IdPs for your tenant.Option | Description | More Information |
|---|---|---|
x509 Private Key Pair
| X.509 private key pair to use with SAML IdP-initiated sign-outs and Workday-initiated sign-outs.
With SAML IdP-initiated sign-outs, Workday uses the X.509 private key pair to sign the SAML sign-out response. With Workday-initiated sign-outs, Workday uses the X.509 private key pair to sign the SAML sign-out request. | |
Enable Mobile Browser SSO for Native Apps
| Redirects users to a mobile browser to complete Single Sign-On (SSO) when they sign in to Workday on Android, iPad, and iPhone. After successful sign-in, Workday redirect users to the Workday app on their device.
You can't enable this feature if you've enabled certificate-based SSO. If you enable this feature:
To enable hardware authentication such as YubiKey on mobile devices, you must select this option. | |
Enable Microsoft Edge for Login to Native Mobile Apps
| Redirects users to the Microsoft Edge web browser to complete Single Sign-On (SSO) when they sign in to Workday on Android, iPad, and iPhone. After successful sign-in, Workday redirect users to the Workday app on their device. | |
Enable DOM Storage
| Enables DOM (Document Object Model) storage for Single Sign-On (SSO) configurations that were configured to use DOM storage to work correctly. Depending on the configuration, DOM storage can optimize load times through client-side storage. | |
Enable Certificate Based SSO
| Enables certificate-based SSO for Workday on Android, iPad, and iPhone. | |
Enable Dynamic Certificate Pinning
| (For Workday on Android, iPad, and iPhone) Ensures authentication requests from mobile clients to your SSO providers are made only through hosts associated with the Trusted Domain Certificates .
Dynamic certificate pinning is only available for Workday on Android if you also enable certificate-based SSO. | |
Trusted Domain Certificates
| The trusted domain certificates that you store in Workday for dynamic certificate pinning.
When Workday attempts to connect to an SSO provider from the mobile client, it checks the trusted domain certificate that you've stored for the SSO provider domain against the certificate presented by the SSO provider host. Workday enables the connection only if the certificates match. The Workday mobile client permits domain names for which Workday doesn't have a trusted domain certificate. | |
Service Provider ID (Will be deprecated)
| Workday plans to retire this field. Use the Service Provider ID field in the SAML Identity Providers grid instead. | |
Enable SP Initiated SAML Authentication (Will be Deprecated)
| Workday plans to retire this field. Use the SP Initiated field in the SAML Identity Providers grid to configure IdPs for SP-initiated SAML authentication. | |
IdP SSO Service URL (Will be deprecated)
| Workday plans to retire this field. Use the IdP SSO Service URL field in the SAML Identity Providers grid instead. | |
Sign SP-initiated Authentication Request (Will be deprecated)
| Workday plans to retire this field. Use the Sign SP-initiated Request field in the SAML Identity Providers grid instead. | |
Do Not Deflate SP-initiated Authentication Request (Will be deprecated)
| Workday plans to retire this field. Use the Do Not Deflate SP-initiated Request field in the SAML Identity Providers grid instead. | |
Always Require IdP Authentication (Will be deprecated)
| Workday plans to retire this field. Use the Always Require IdP Authentication field in the SAML Identity Providers grid instead. | |
Authentication Request Signature Method
| (For SP-initiated SAML authentication) Workday requires that you use SHA256. | |
Enable Signature KeyInfo Validation
| Workday compares the optional SAML keyInfo element in incoming SAML messages with the SAML public key that your tenant stores. If the element contains an X.509 public key and:
| |
Additional Negative Skew (in minutes) Additional Positive Skew (in minutes) | The number of minutes to add to the NotBefore /NotOnOrAfter time (the current time minus/plus the skew time) when processing the validity of a SAML assertion. Workday enforces a combined 3-minute maximum in either direction from the issueInstant of the message and the current Workday server time. Skew is the difference between the Workday server time and your IdP server time. |
OpenID Connect Settings
To enable:
- OpenID Connect for your tenant, select theEnable OpenID Connect Authenticationcheck box.
- Workday-delivered multifactor authentication for OpenID Connect on authentication policies, select theEnable Native Multi-Factor Authenticationcheck box.
Option | Description | More Information |
|---|---|---|
OpenID Connect Provider
| Enables you to configure connection information for the OpenID Connect provider. Google is the only OpenID Connect provider Workday supports. |
Mobile Authentication
Option | Description | More Information |
|---|---|---|
Enable Biometric Authentication
| Enables fingerprint authentication for:
| |
Enable Mobile PIN Authentication
| Enables mobile PIN authentication for your tenant so that users can sign in to Workday for Android, iPad, and iPhone using a PIN. | |
PIN Min Length
| The minimum PIN length is 4. Workday automatically populates the field with 6. | |
PIN Max Length
| The maximum PIN length is 8. Workday automatically populates the field with 8. | |
PIN Max Failed Signin Attempts
| The number of failed mobile PIN sign-in attempts, from 2 to 5, before Workday deletes the PIN. The user must then sign in to Workday using another authentication type. Workday automatically populates the field with 3.
This setting affects only mobile PIN authentication. For biometric authentication, the number of failed sign-in attempts is 3, after which the user must sign in to Workday using another authentication type. | |
Max Mobile Authentication Age (in days)
| The number of days, from 30 to 365, before Workday expires mobile PIN and biometric authentication. Upon expiration, the user must reset the PIN and reenable biometric authentication if they're using those features. |
Sensitive Data Enumeration
Option | Description | More Information |
|---|---|---|
Disable Sensitive Data Enumeration Feature
| Opts out of the sensitive data enumeration feature for the tenant.
The sensitive data enumeration feature signs out all sessions and locks user accounts that repeatedly access these sensitive data groups over a short period of time:
Example: Workday signs out user sessions and locks user accounts used by a malicious script that repeatedly accesses sensitive data groups. |
Trusted Devices
Option | Description | More Information |
|---|---|---|
Disable Trusted Devices
| Opts out of the trusted devices feature for the tenant. Workday automatically enables trusted devices in the tenant.
Workday resets the trust relationship for all trusted devices in the tenant if you disable the trusted devices feature. |
Multifactor Authentication Settings
Option | Description | More Information |
|---|---|---|
Maximum Grace Signin Count
| Sets the maximum number of times users can sign in before Workday requires them to enroll 1 of the multifactor authentication types you've enabled for them. Set to zero to enforce multifactor authentication enrollment for all users. | |
Add Multi-Factor Authentication Provider
| Click to add these multifactor authentication providers:
| |
Edit (for Authenticator App multifactor authentication provider). | Click to change the state of the Enabled check box. | |
Edit (for Backup Codes multifactor authentication provider). | Click to change the state of the Enabled check box and access this setting:
| |
Edit (for Duo multifactor authentication provider). | Click to change the state of the Enabled check box and access these settings:
API Hostname .
| |
Edit (for One Time Passcode - Email multifactor authentication provider). | Click to change the state of the Enabled check box and access these settings:
The Email Address for Passcode setting is independent of the Enable Security Emails setting. You don't have to enable security emails for your users to receive one-time passcode emails. | |
Edit (for One Time Passcode - SMS multifactor authentication provider). | Click to change the state of the Enabled check box and access these settings:
|