Skip to main content
Administrator Guide
Last Updated: 2026-03-13
Reference: Edit Tenant Setup - Security

Reference: Edit Tenant Setup - Security

Security Email Settings

Option
Description
More Information
Enable Security Emails
Required for sending:
  • Password reset emails.
  • Trusted device emails.
  • X.509 and PGP certificate expiration notifications.
If checked:
  • Send to work email only
    : All Workday-generated emails go only to the work email address listed in each account.
  • Send to work email, else home email
    : If the worker has no work email address on file, Workday sends the email to the home email address.
  • Send to home email, else work email
    : If the worker has no home email address on file, Workday sends the email to the work email address.
If unchecked:
  • Users can only reset their password online.
  • Workday won't notify you about expired X.509 and PGP certificates for your tenant. Such expired certificates can prevent successful sign-ins to Workday.
Password reset emails initiate when:
  • Users reset their passwords. Workday emails a one-time reset link.
  • You initiate a password reset using a business process. Workday emails a temporary password.
  • You initiate a password reset using the
    Generate Random Password
    option on the
    Edit Workday Accounts
    task. Workday emails a temporary password, except when you set and verify a new password.
Bypass Login Redirect for New Accounts
Includes a URL in new Workday account emails that enables users to:
  • Sign in to Workday using their username and password.
  • Not be redirected to your SSO
    Login Redirect URL
    .
Example: Enable recruiting agency users with new Workday accounts to sign in to Workday for the first time using their username and password.
Workday sends the new Workday account emails with the login redirect URL to new hires and rehires.
Email Temporary Password to New Accounts
Generates temporary passwords automatically and emails the password to the new worker instead of requiring new workers to get their temporary password from their Workday administrator.
Enable Forgotten Password Reset
Enables users to reset their password through the
Forgot Password
link on the sign-in to Workday page. The
Disable All Emails
restriction on the
Edit Tenant Setup - Notifications
task overrides this option and suppresses the
Forgot Password
link.
If checked, Workday defaults to one-time passcodes
  • One Time Use Link
    requires users to enter their username and work or home email address. Workday emails a single-use link that they click to reset their password online.
Enable Email Notification On Account Lockout
Sends a notification to the primary email address of the user the next time they try to sign in after Workday locks their account:
  • If an administrator locks the account manually, the email instructs the user to contact an administrator. Workday sends a notification on subsequent sign-in attempts every 30 minutes if the account remains locked.
    Example: An administrator manually locks a user out at 9:00 AM. When the user tries to sign in at 9:01 AM, Workday sends an email. If the account for the user remains locked, and they try to sign in again at:
    • 9:15 AM, Workday doesn't send an email.
    • 9:20 AM, Workday doesn't send an email.
    • 9:31 AM, Workday sends another email.
  • If Workday locks the account due to excessive failed sign-in attempts, the email instructs the user to sign in later. You can specify when users can sign in again on the
    Maintain Password Rules
    task.
    Example: A user exceeds the maximum unsuccessful sign-in attempts and Workday locks their account at 9:00 AM. When they try to sign in again at 9:01 AM, Workday sends an email about a 10-minute lockout period. If the user has another unsuccessful sign-in attempt at 9:11 AM, Workday sends another email. If the user signs in successfully at 9:11 AM, Workday doesn't send another email.
Select the
Enable Security Emails
check box for users to receive these notifications.

WebAuthn (FIDO2)

Option
Description
More Information
Enable Web Authentication
Enables you to specify web authentication as an allowed authentication type on authentication policies. With web authentication enabled, your users can enroll in and use web authentication for passwordless sign in to Workday on supported web browsers.

Single Sign-On

Option
Description
More Information
Redirection URLs
Alternate URLs that Workday references when a specific action occurs. Redirect URLs must use HTTPS.
  • Redirect Type
    determines if Workday redirects all users to:
    • The single set of sign-in redirect URLs specified on this task for sign-in (
      Single URL
      ).
    • The sign-in redirect URLs on the selected Authentication Selector for sign-in, rather than URLs specified on this task (
      Authentication Selector
      ).
  • (Applies to desktop only)
    Login Redirect URL
    is an alternative URL to reference when workers make unauthenticated sign-in requests. Workday uses this URL instead of the Workday sign-in page or email links that reference Workday-authenticated URLs.
  • (Applies to desktop and mobile)
    Logout Redirect URL
    is an alternative URL to reference when workers exit Workday using the
    Sign Out
    link for the selected
    Environment
    .
  • (Applies to desktop and mobile)
    Timeout Redirect URL
    is an alternative URL to reference when the Workday session of a worker times out for the selected
    Environment
    .
  • (Applies to mobile only)
    Mobile App Login Redirect URL
    is an alternative URL to reference when a worker attempts to sign in to Workday on Android, iPad, or iPhone for the selected
    Environment
    .
  • (Applies to mobile only)
    Mobile Browser Login Redirect URL
    is an alternative URL to reference when a worker attempts to sign in to Workday on a mobile browser for the selected
    Environment
    .
  • Preview Only
    applies the redirect URLs to Preview tenants only. You can't select
    Preview Only
    if you select the Production environment.
You can select up to 2 redirect URLs for each environment. If you do, you must mark 1 as
Preview Only
; Workday will use the URL marked as
Preview Only
in Preview tenants, and the other in Production tenants.
To apply the redirection URLs to your Sandbox Preview or Implementation Preview tenants, select
Sandbox
or
Implementation
respectively at the
Environment
prompt. Those environments also apply to the respective preview tenants.

OAuth 2.0 Settings

Option
Description
More Information
OAuth 2.0 Clients Enabled
Enables OAuth 2.0 clients to access the Workday API for your tenant.

SAML Setup

To enable:
  • SAML for your tenant, select the
    Enable SAML Authentication
    check box.
  • Workday-delivered multifactor authentication for SAML on authentication policies, select the
    Enable Native Multi-Factor Authentication
    check box.
Configure options for
each
SAML IdP for your tenant.
Option
Description
More Information
Disabled
You can disable an IdP if it's currently assigned to an authentication policy. You can't disable an IdP if it's in use.
Identity Provider Name
Unique human-readable name for the SAML IdP.
Issuer
Unique identifier for the SAML IdP.
Workday validates a SAML authentication attempt only if:
  • The Issuer in the incoming SAML message is 1 of these configured Issuer values.
  • The environment type of the tenant is 1 of the valid environment types for the SAML IdP.
x509 Certificate
X.509 public certificate to verify the signature on SAML sign-in and sign-out requests.
Enable IdP Initiated Logout
Workday:
  1. Accepts SAML sign-out requests from an external IdP.
  2. Signs a worker out of a Workday session.
  3. Sends a SAML sign-out response to your IdP.
Logout Response URL
URL to which Workday sends a successful sign-out response when the IdP initiates the sign-out.
Enable Workday Initiated Logout
Workday:
  1. Generates signed SAML sign-out requests.
  2. Sends them to your IdP.
  3. Redirects the SAML sign-out response message.
Logout Request URL
URL to which Workday sends a sign-out request when it initiates the sign-out.
Use Unspecified Name ID Format for Logout Request
Workday generates a SAML logout request with an unspecified Name ID format, rather than X509SubjectName.
SP Initiated
Workday uses this IdP for SP-initiated SAML authentication in the selected environment.
Service Provider ID
The Service Provider (SP) ID configured for the Workday tenant in the SAML IdP setup. It identifies Workday as the service provider in SAML messages sent to this IdP.
Sign SP-initiated Request
Workday signs the SAML requests it sends to the SAML IdP using your SAML public key.
Do Not Deflate SP-initiated Request
Disables deflate compression of SAML requests that Workday sends to a SAML IdP endpoint. Workday automatically uses deflate compression and Base64 encoding when sending SAML requests. Certain SAML IdPs can't parse the SAML request if Workday compresses the SAML request with deflate.
Always Require IdP Authentication
(For SP-initiated SAML authentication) Requires the SAML IdP to force users to reauthenticate, even if they have an existing IdP session. Select
ForceAuthn and RequestedAuthnContext
if the IdP expects both of these values to force users to reauthenticate.
IdP SSO Service URL
(
SP Initiated
selected) - The URL to which Workday sends SAML authentication requests during SP-initiated SAML authentication. Complete this field for any IdP that Workday will use for SP-initiated SAML authentication.
(
SP Initiated
cleared) - The URL to which Workday sends SAML authentication requests.
Managed Device Attribute
The IdP returns an attribute as part of the SAML assertion when it's configured to use a mobile device management (MDM) provider to determine managed device status.  The value you enter in this field must exactly match that attribute name. Example: If the IdP returns isWDManagedDev as the managed device attribute in SAML assertions, you must enter
isWDManagedDev
in this field.
Used for Environments
If you don't select an environment, Workday uses the same IdP for all environments.
To configure the IdP for use in your Sandbox Preview or Implementation Preview tenants, select
Sandbox
or
Implementation
respectively at the
Used for Environments
prompt. Those environments also apply to the respective preview tenants.
Preview Only
Enables the SAML IdP for Preview tenants for the selected environments only. If the selected environment is Production, you can't select
Preview Only
.
  • If you don't select
    Preview Only
    for any IdP in an environment, Workday uses all IdPs for that environment.
  • If you select
    Preview Only
    for 1 or more IdPs in an environment, Workday uses them for Preview tenants in that environment. Workday uses the IdPs for which the
    Preview Only
    check box isn't selected for Production tenants in that environment.
Configure options for
all
SAML IdPs for your tenant.
Option
Description
More Information
x509 Private Key Pair
X.509 private key pair to use with SAML IdP-initiated sign-outs and Workday-initiated sign-outs.
With SAML IdP-initiated sign-outs, Workday uses the X.509 private key pair to sign the SAML sign-out response. With Workday-initiated sign-outs, Workday uses the X.509 private key pair to sign the SAML sign-out request.
Enable Mobile Browser SSO for Native Apps
Redirects users to a mobile browser to complete Single Sign-On (SSO) when they sign in to Workday on Android, iPad, and iPhone. After successful sign-in, Workday redirect users to the Workday app on their device.
You can't enable this feature if you've enabled certificate-based SSO. If you enable this feature:
  • You can't enable dynamic or standard certificate pinning.
  • When users sign out of their mobile application, Workday doesn't terminate the SSO session.
To enable hardware authentication such as YubiKey on mobile devices, you must select this option.
Enable Microsoft Edge for Login to Native Mobile Apps
Redirects users to the Microsoft Edge web browser to complete Single Sign-On (SSO) when they sign in to Workday on Android, iPad, and iPhone. After successful sign-in, Workday redirect users to the Workday app on their device.
Enable DOM Storage
Enables DOM (Document Object Model) storage for Single Sign-On (SSO) configurations that were configured to use DOM storage to work correctly. Depending on the configuration, DOM storage can optimize load times through client-side storage.
Enable Certificate Based SSO
Enables certificate-based SSO for Workday on Android, iPad, and iPhone.
Enable Dynamic Certificate Pinning
(For Workday on Android, iPad, and iPhone) Ensures authentication requests from mobile clients to your SSO providers are made only through hosts associated with the
Trusted Domain Certificates
.
Dynamic certificate pinning is only available for Workday on Android if you also enable certificate-based SSO.
Trusted Domain Certificates
The trusted domain certificates that you store in Workday for dynamic certificate pinning.
When Workday attempts to connect to an SSO provider from the mobile client, it checks the trusted domain certificate that you've stored for the SSO provider domain against the certificate presented by the SSO provider host. Workday enables the connection only if the certificates match.
The Workday mobile client permits domain names for which Workday doesn't have a trusted domain certificate.
Service Provider ID (Will be deprecated)
Workday plans to retire this field. Use the
Service Provider ID
field in the
SAML Identity Providers
grid instead.
Enable SP Initiated SAML Authentication (Will be Deprecated)
Workday plans to retire this field. Use the
SP Initiated
field in the
SAML Identity Providers
grid to configure IdPs for SP-initiated SAML authentication.
IdP SSO Service URL (Will be deprecated)
Workday plans to retire this field. Use the
IdP SSO Service URL
field in the
SAML Identity Providers
grid instead.
Sign SP-initiated Authentication Request (Will be deprecated)
Workday plans to retire this field. Use the
Sign SP-initiated Request
field in the
SAML Identity Providers
grid instead.
Do Not Deflate SP-initiated Authentication Request (Will be deprecated)
Workday plans to retire this field. Use the
Do Not Deflate SP-initiated Request
field in the
SAML Identity Providers
grid instead.
Always Require IdP Authentication (Will be deprecated)
Workday plans to retire this field. Use the
Always Require IdP Authentication
field in the
SAML Identity Providers
grid instead.
Authentication Request Signature Method
(For SP-initiated SAML authentication) Workday requires that you use SHA256.
Enable Signature KeyInfo Validation
Workday compares the optional SAML
keyInfo
element in incoming SAML messages with the SAML public key that your tenant stores. If the element contains an X.509 public key and:
  • If the public key in
    keyInfo
    matches the SAML public key Workday stores in your tenant, Workday processes the authentication request.
  • If the values don't match, Workday:
    • Rejects the authentication request.
    • Displays an error message on the
      Signons and Attempted Signons
      report.
Additional Negative Skew (in minutes)
Additional Positive Skew (in minutes)
The number of minutes to add to the
NotBefore
/
NotOnOrAfter
time (the current time minus/plus the skew time) when processing the validity of a SAML assertion. Workday enforces a combined 3-minute maximum in either direction from the
issueInstant
of the message and the current Workday server time. Skew is the difference between the Workday server time and your IdP server time.

OpenID Connect Settings

To enable:
  • OpenID Connect for your tenant, select the
    Enable OpenID Connect Authentication
    check box.
  • Workday-delivered multifactor authentication for OpenID Connect on authentication policies, select the
    Enable Native Multi-Factor Authentication
    check box.
Option
Description
More Information
OpenID Connect Provider
Enables you to configure connection information for the OpenID Connect provider. Google is the only OpenID Connect provider Workday supports.

Mobile Authentication

Option
Description
More Information
Enable Biometric Authentication
Enables fingerprint authentication for:
  • These Android devices that support biometrics:
    • Google
    • HTC
    • Huawei Nexus 6P
    • LG
    • Motorola
    • Samsung
    • Sony
  • iPad or iPhone devices supporting Touch ID.
Also enables users with supported iPhone devices to authenticate using Face ID. Workday automatically enables biometric authentication in the tenant.
Enable Mobile PIN Authentication
Enables mobile PIN authentication for your tenant so that users can sign in to Workday for Android, iPad, and iPhone using a PIN.
PIN Min Length
The minimum PIN length is 4. Workday automatically populates the field with 6.
PIN Max Length
The maximum PIN length is 8. Workday automatically populates the field with 8.
PIN Max Failed Signin Attempts
The number of failed mobile PIN sign-in attempts, from 2 to 5, before Workday deletes the PIN. The user must then sign in to Workday using another authentication type. Workday automatically populates the field with 3.
This setting affects only mobile PIN authentication. For biometric authentication, the number of failed sign-in attempts is 3, after which the user must sign in to Workday using another authentication type.
Max Mobile Authentication Age (in days)
The number of days, from 30 to 365, before Workday expires mobile PIN and biometric authentication. Upon expiration, the user must reset the PIN and reenable biometric authentication if they're using those features.

Sensitive Data Enumeration

Option
Description
More Information
Disable Sensitive Data Enumeration Feature
Opts out of the sensitive data enumeration feature for the tenant.
The sensitive data enumeration feature signs out all sessions and locks user accounts that repeatedly access these sensitive data groups over a short period of time:
  • Bank Account Number.
  • Person Birth Place.
  • Person Date of Birth.
  • Person Global Identifier.
  • Tax ID.
Example: Workday signs out user sessions and locks user accounts used by a malicious script that repeatedly accesses sensitive data groups.

Trusted Devices

Option
Description
More Information
Disable Trusted Devices
Opts out of the trusted devices feature for the tenant. Workday automatically enables trusted devices in the tenant.
Workday resets the trust relationship for all trusted devices in the tenant if you disable the trusted devices feature.

Multifactor Authentication Settings

Option
Description
More Information
Maximum Grace Signin Count
Sets the maximum number of times users can sign in before Workday requires them to enroll 1 of the multifactor authentication types you've enabled for them. Set to zero to enforce multifactor authentication enrollment for all users.
Add Multi-Factor Authentication Provider
Click to add these multifactor authentication providers:
  • Authenticator App
  • Backup Codes
  • Duo
  • One Time Passcode - Email
  • One Time Passcode - SMS
Add authenticator app before you add backup codes. Workday removes this button from the task once you've added all providers.
Edit
(for Authenticator App multifactor authentication provider).
Click to change the state of the
Enabled
check box.
Edit
(for Backup Codes multifactor authentication provider).
Click to change the state of the
Enabled
check box and access this setting:
  • Max Backup Code Count
    : The number of authenticator app backup codes that Workday supplies to the user.
Edit
(for Duo multifactor authentication provider).
Click to change the state of the
Enabled
check box and access these settings:
  • Auth Integration Key
  • Auth Secret Key
  • Admin Integration Key
  • Admin Secret Key
The public and secret keys provided by Duo Security to protect the Workday and Admin API applications for your Duo trusted access account. See the Duo documentation for information on obtaining these keys and the
API Hostname
.
  • Username Format
    : Duo compares the information from Workday accounts that you specify here to identify Workday users in the Duo service.
Edit
(for One Time Passcode - Email multifactor authentication provider).
Click to change the state of the
Enabled
check box and access these settings:
  • Passcode Timeout (in minutes)
    : Ensure that the default tenant and individual user session timeouts are more than 10 minutes if you set this parameter to 10 minutes.
  • Email Address for Passcode
    : Ensure that you also set up email addresses for users in the security groups you enable for
    One Time Passcode - Email
    multifactor authentication. Example: You:
    • Select
      Send to home email only
      here.
    • Configure a security policy to require
      One Time Passcode - Email
      multifactor authentication for the Benefits Administrator and Compensation Administrator security groups.
    Ensure that the users in those security groups have home email addresses included in their worker profiles.
The
Email Address for Passcode
setting is independent of the
Enable Security Emails
setting. You don't have to enable security emails for your users to receive one-time passcode emails.
Edit
(for One Time Passcode - SMS multifactor authentication provider).
Click to change the state of the
Enabled
check box and access these settings:
  • Passcode Timeout (in minutes)
    : Ensure that the default tenant and individual user session timeouts are more than 10 minutes if you set this parameter to 10 minutes.
  • Allow Home Mobile for One Time Passcode
    : Enables users to select a mobile phone number for work or home from their contact information. They'll then receive a one-time passcode for accessing Workday at the selected mobile phone number.