Concept: Single Sign-On
Background
You can use Security Assertion Markup Language (SAML) for single sign-on (SSO) in Workday Peakon Employee Voice. Example: Users with manager and personal dashboard access can sign in using their existing company identity without requiring separate credentials for Peakon.
Peakon integrates with external systems capable of acting as a SAML 2.0 identity provider (IdP).
SAML standardizes the exchange of authentication and authorization data between security domains. It enables administrators to manage user credentials centrally through a third-party IdP. Example: Okta. Once configured, users can access Peakon directly from your organization's central application portal.
Users can initiate sign-in from service provider websites or IdP app portals. Popular hosted services with SAML support include:
- G Suite (Google Apps)
- Microsoft ADFS
- Microsoft Entra
- Okta
- OneLogin
Considerations
- Users who access their dashboards for the first time using an email confirmation link gain initial access without authenticating through SSO. All subsequent sign-ins require SSO authentication.
- Contact Customer Care if your organization uses multiple email domains to ensure all domains are added to your account.
- Employee email addresses in Peakon must match the email address in your identity provider exactly. Consider this requirement if your organization uses email aliases.
Recommendations
- Set theRequire single sign-onsetting toEveryoneif you want to ensure that all users authenticate through SSO only.
Limitations
- Only Peakon administrators can access SSO configuration on Peakon.
- You cannot add common public email domains to your Peakon account for SSO. Example: @gmail.com.
- Peakon supports encryption certificates in XML metadata, but does not support signing certificates.
- Peakon requires aSessionIndexattribute on theAuthnStatementelement of the SAML assertion provided by an IdP.