Configure Workday as SAML Service Provider

Use the following SAML configuration for Workday.

  1. Go to Dashboard > Applications > Applications and either create a new application or click the name of an application to update.

  2. Go to the Addons tab and enable the SAML2 Web App toggle.

  3. On the Settings tab, set the Application Callback URL to: https://impl.workday.com/<tenant>/login-saml.htmld.

    Dashboard Applications Applications Addons Tab SAML2 Web App Settings Tab
  4. Paste the following code into the Settings text box and click Debug.

    {
          "audience": "http://www.workday.com",
          "recipient": "https://www.myworkday.com/<tenant>/login-saml.htmld",
          "mappings": {
          },
          "createUpnClaim":       false,
          "passthroughClaimsWithNoMapping": false,
          "mapUnknownClaimsAsIs": false,
          "mapIdentities":        false,
          "signResponse":         true,
          "nameIdentifierFormat": "urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName",
          "nameIdentifierProbes": [
        "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress",
          ],
          "authnContextClassRef": "urn:oasis:names:tc:SAML:2.0:ac:classes:X509",
        }

    Was this helpful?

    /
    Change the subdomain impl depending on the Workday data center you are using.

  5. Scroll to the bottom of the page and click Enable.

  6. On the Usage tab, locate Identity Provider Metadata, and click Download to download the metadata file. You'll need this when you configure Auth0 as the identity provider.

    Dashboard Applications Applications Addons Tab SAML2 Web App Usage Tab