Workday | Integration System User (ISU) Authentication
In this article, we help you authenticate your Integration System User (ISU) so you can obtain your Workday web services endpoint URL and connect your Workday account to your Oyster account.
Prerequisites
You have Admin access to your company’s account.
You are logged in to Workday with your Admin credentials.
In the Search field, type: Create integration system user
Select the Create Integration System User task.
In the Create Integration System User window, do the following:
Type a [User Name]
Create and verify a password
Do not select the Require New Password at Next Sign In check box
Type 0 (zero) for Session Timeout Minutes to prevent session expiration
Make a note of this [User Name], you'll need it soon.
Click OK.
Add this user to the list of System Users to prevent the password from expiring.
Assign the ISU to a new security group
In the Search field, type: create security group
Select the Create Security Group task. The Create Security Group page appears.
Select Integration System Security Group (Unconstrained) from the Type of Tenanted Security Group drop-down.
Type a name in the Name field.
Make a note of this [Group name], you'll need it in the next section.
Click OK. The Edit Integration System Security Group (Unconstrained) page appears.
In the Name field, type the [Group name] you just created.
In the Integration System Users field, type the [User Name] you created previously.
Click OK.
Configure domain security policy permissions
In the Search field, type: Maintain permissions for securitygroup
Select the Maintain Permissions for Security Group task. The Maintain Permissions for Security Group page appears.
Select the Maintain Operation, as necessary.
Ensure the Source Security Group name is the same as the [Group name] you just assigned.
Click OK.
Add the corresponding Domain Security Policy Permissions with GET operation:
Please note the permissions listed below are the required permissions for the full HRIS API. Permissions can differ from implementation to implementation.
Pre-Hire Process Data: Name and Contact Information
Job Requisition Data
Person Data: Personal Data
Person Data: Home Contact Information
Person Data: Work Contact Information
Manage: Location
Worker Data: Public Worker Reports
Activate security policy changes
In the search bar, type: Activate Pending Security Policy Changes
Click the Activate Pending Security Policy Changes task to view a summary of the changes in the security policy that need to be approved.
Add any relevant comments in the window that appears.
Select the Confirm checkbox to accept the changes.
Validate the authentication policy
Check the Manage Authentication Policies section to ensure the ISU you created is added to a policy that can access the necessary domains. It should not be restricted to only the "SAML" Allowed Authentication Types – if this is the case, you can create a new Authentication Policy with a "User Name Password" Allowed Authentication Type.
Edit the Authentication Policies
Create an Authentication Rule and add the Security Group to the Rule.
Ensure the Allowed Authentication Types is set to either:
Specific> Any
Specific > User Name Password
Activate all pending authentication policy changes
In the search bar, type Activate All Pending Authentication Policy Changes.
Select the Activate All Pending Authentication Policy Changes task. The Activate All Pending Authentication Policy Changes page appears.
Proceed to the next screen and select the Confirm checkbox. This will activate the Authentication Policy that was just created.