Skip to main content
Administrator Guide
Last Updated: 2026-06-26
Steps: Set Up Security Settings

Steps: Set Up Security Settings

Have the
settings.admin
permission. This gives you access to the
Company Settings
page.
Security settings in VNDLY allow administrators to configure and manage security roles, including new roles, permission management, policy management, and log in and session management. By configuring these settings, organizations can maintain security and ensure that users have the necessary access to perform their tasks.
  1. From the header, select
    More
    Company Settings
    .
  2. From the
    Security
    section, click
    Security Settings
    .
  3. On the
    Roles
    tab, Create Security Roles.
  4. On the
    Policies
    tab, Set Up Security Policies.
  5. On the
    Configuration
    tab, review each section:
    Section
    Consideration
    Reporting Hierarchy Access
    Allows users to manage and view reports based on their organizational structure and ownership of records.
    When you select the check boxes for each module, any user with an owned-read permission passes that permission up their reporting line according to the
    Report to User
    field in their user profile.
    Session Management
    Configure the global session expiration and session inactivity timeout. See Set Up Session Management.
    Sign-up Token Expiration
    Enables you to define the validity period, in hours, for the initial sign-in link provided to new VNDLY users. See Set Up Sign-Up Token Expiration Period.
    Password Management
    Enables you to define the minimum length of characters required to enforce a company's security policies.
    If this field is empty, the password follows the Workday VNDLY password standards. See Reference: Password Standards.
    Multi-factor Authentication
    Enables you to configure multi-factor authentication (MFA). See Set Up Multi-Factor Authentication in Workday VNDLY.
    Vendor Auth
    Enables you to configure vendor user permissions. When you select the
    Allow Vendor Auth Management
    check box, you enable client-side users to edit and manage vendor users and contacts.
    By default, this option is cleared.
    Consider these client-side permissions:
    • Add a vendor contact:
      vendor_user.create
    • Reset vendor user password:
      vendor_user.reset_password
    • Update authentication type:
      vendor_user.auth.update
    • Update username:
      vendor_user.username.update