You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
1. On the **Basic SAML Configuration** page, enter the values for the following fields:
79
79
@@ -90,7 +90,7 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
90
90
> These values are not the real. Update these values with the actual Sign-on URL, Reply URL and Logout URL. Your reply URL must have a subdomain for example: www, wd2, wd3, wd3-impl, wd5, wd5-impl).
91
91
> Using something like `http://www.myworkday.com` works but `http://myworkday.com` does not. Contact [Workday Client support team](https://www.workday.com/en-us/partners-services/services/support.html) to get these values. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
92
92
93
-
1. Your Workday application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. The following screenshot shows the list of default attributes, where as**nameidentifier** is mapped with **user.userprincipalname**. Workday application expects **nameidentifier** to be mapped with **user.mail**, **UPN**, etc., so you need to edit the attribute mapping by clicking on **Edit** icon and change the attribute mapping.
93
+
1. Your Workday application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. The following screenshot shows the list of default attributes, whereas**nameidentifier** is mapped with **user.userprincipalname**. Workday application expects **nameidentifier** to be mapped with **user.mail**, **UPN**, etc., so you need to edit the attribute mapping by clicking on **Edit** icon and change the attribute mapping.
94
94
95
95

96
96
@@ -99,21 +99,21 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
99
99
100
100
1. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, find **Federation Metadata XML** and select **Download** to download the certificate and save it on your computer.
@@ -136,7 +136,7 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
136
136
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
137
137
1. Select **Add user**, then select **Users and groups** in the **Add Assignment** dialog.
138
138
1. In the **Users and groups** dialog, select **B.Simon** from the Users list, then click the **Select** button at the bottom of the screen.
139
-
1. If you are expecting a role to be assigned to the users, you can select it from the **Select a role** dropdown. If no role has been setup for this app, you see "Default Access" role selected.
139
+
1. If you are expecting a role to be assigned to the users, you can select it from the **Select a role** dropdown. If no role has been set up for this app, you see "Default Access" role selected.
140
140
1. In the **Add Assignment** dialog, click the **Assign** button.
141
141
142
142
## Configure Workday
@@ -145,28 +145,28 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
145
145
146
146
1. In the **Search box**, search with the name **Edit Tenant Setup – Security** on the top left side of the home page.
a. In the **Service Provider ID (Will be Deprecated)** textbox, type **http://www.workday.com**.
190
-
191
-
b. In the **IDP SSO Service URL (Will be Deprecated)** textbox, type **Login URL** value.
192
-
193
-
c. Select **Do Not Deflate SP-initiated Authentication Request (Will be Deprecated)**.
183
+
g. Select **Do Not Deflate SP-initiated Authentication Request**.
194
184
195
-
d. For**Authentication Request Signature Method**, select **SHA256**.
185
+
h. Click**Ok**.
196
186
197
-
e. Click **OK**.
187
+
i. If the task was completed successfully, click **Done**.
198
188
199
189
> [!NOTE]
200
190
> Please ensure you set up single sign-on correctly. In case you enable single sign-on with incorrect setup, you may not be able to enter the application with your credentials and get locked out. In this situation, Workday provides a backup log-in URL where users can sign-in using their normal username and password in the following format:[Your Workday URL]/login.flex?redirect=n
@@ -207,13 +197,13 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
207
197
208
198
1. In the **Directory** page, select **Find Workers** in view tab.
1. In the **Find Workers** page, select the user from the results.
213
203
214
204
1. In the following page,select **Job > Worker Security** and the **Workday account** has to match with the Azure active directory as the **Name ID** value.
> For more information on how to create a workday test user, please contact [Workday Client support team](https://www.workday.com/en-us/partners-services/services/support.html).
0 commit comments