This site requires JavaScript to be enabled
Customer Service > General > Configuring SAML for Workday
Configuring SAML for Workday
Article: KB0010951 Published: 01/05/2022 Last modified: 11/09/2023

This topic describes how to configure OneLogin to provide SSO for Workday using SAML.

Note. If you want to set up SSO for Workday with form-based authentication, see Adding a Form-Based Application.

Note. If you want to sync users between Workday and the OneLogin Cloud Directory or a third-party user store like Active Directory, see Workday as a Directory.

To configure SSO for Workday using SAML:

  1. Log into OneLogin as an admin and go to Apps > Add Apps.

  2. Search for and select the Workday connector that supports SAML2.0.

    The initial Configuration tab appears.

  3. Click Save to add the app to your Company Apps and display additional configuration tabs.

    The Info tab appears.

  4. Go to the Configuration tab.

  5. In the Tenant URL field enter your tenant name.

    https://impl.workday.com/your_company

  6. Click Save.

  7. Go to the Parameters tab and map Workday attributes to OneLogin attributes.

    In most cases, you should keep the Configured by admin default. For more information, see Setting Credential Configuration Options.

    The Workday field Email should be set to the OneLogin attribute Email. If, however, your Workday implementation doesn't use Email as the Username, click the parameter row to open the Edit Field dialog and select the correct attribute from the drop-down list.

  8. Go to the SSO tab to configure your Workday account with OneLogin's SAML settings.


    1. In a new browser tab, log into your organization's Workday account as admin.

    2. On your Workday admin dashboard, click Account Administration > Edit Tenant Setup - Security.

      The Edit Tenant Setup - Security page appears.

    3. Scroll down to the Single Sign-on section and ensure that the Login Redirect URL Environment setting is set to Implementation.

    4. Scroll down to the SAML Setup section and select Enable SAML Authentication.

    5. With both the OneLogin SSO tab and the Workday Edit Tenant Setup - Security page open, copy the SAML values from OneLogin to the analogous Workday fields in the SAML Setup section of the Edit Tenant Setup - Security page.

      Copy this OneLogin SSO field value: To this Workday SAML Setup field:

      Issuer URL

      Issuer in the SAML Identity Providers table

      SAML 2.0 Endpoint (HTTP)

      Login Redirect URL in the Redirection URLs table

      OneLogin

      Identity Provider Name in the SAML Identity Providers table

      When you are done, the Single Sign-on and SAML Setup sections of your Workday Edit Tenant Setup - Security page should look like this:

    6. In Workday, click the menu icon on the right side of the X509 Certificate field in the SAML Identity Providers table, and select Create X509 Public Key from the drop-down list.

      The Create X509 Public Key page appears.

    7. In the Name field, enter a name for the key.

    8. Click the Valid From and Valid To fields to define a period of time for which the key is valid.

      You must begin with a date that precedes the current date and terminate on a date later than the current date.

    9. In the OneLogin SSO tab under the X.509 Certificate field, click the View Details link. This creates a pop-up window. Copy the entire X.509 Certificate, including "----BEGIN CERTIFICATE----" and "----END CERTIFICATE----"

    10. Paste the entire X.509 Certificate from the OneLogin SSO tab into the Certificate field on the Workday Create X509 Public Key page.

    11. On the Workday Create X509 Public Key page, click OK.

  9. On the OneLogin Access tab, assign the OneLogin roles that should have access to Workday and provide any app security policy that you want to apply to Workday.

    You can also go to Users > All Users to add the app to individual user accounts.

  10. Click Save.
  11. Test the SAML connection.


    1. Ensure that you have user accounts in both OneLogin and Workday that use the same email as the username.

      You can create a test user, or you can use your own account if you choose.

    2. Make sure you are logged out of Workday.

    3. Log in to OneLogin as an admin and give the test user access to the Workday app in OneLogin. (See step 10 above)

    4. Log in to OneLogin as the test user.

    5. Click the Workday icon on your OneLogin dashboard.

      If you are able to access Workday, then SAML works.


Expand/Collapse Comments
:     
Was this helpful?
YesYesNoNo