Workday - SAML My Page SSO Configuration - RSA Ready Implementation Guide
This article describes how to integrate Cloud Access Service (CAS) with Workday using My Page SSO.
Configure CAS
Perform these steps to configure RSA Cloud Access Service using My Page SSO.
Procedure
- Sign in to RSA Cloud Administration Console and navigate to Applications > Application Catalog.
- Click Create from Template, then click Select next to SAML Direct.
- On the Basic Information page, select Cloud.
- In the Name field, enter the application name and click Next Step.
- On the Connection Profile page, navigate to Initiate SAML Workflow section and choose IdP-initiated.
- In Data Input Method, Choose Enter Manually.
- Scroll down to the Service Provider section. enter the following fields in the following format:
- Assertion Consumer Service (ACS) URL: https://<WORKDAY-domain>/<tenant>/login-saml.htmld
- Service Provider Entity ID: Enter the same Service Provider Entity ID entered in the format http://<WORKDAY-domain>/<tenant>/
- In the Message protection section, select IdP Signs entire SAML response.
- Click Download Certificate.
- In the User Identity section, select the following values:
- Identifier Type > unspecified
- Property > sAMAccountName
- In the Statement Attributes section, select the following values:
-
Attribute Name: Username
-
Attribute Source: Identity Source
-
Property: SAMAccountName
-
- On the User Access page, choose the access policy you want to use to determine which users can access the application, then click Next Step.
- On the Portal Display page, configure the portal display and other settings. Then click Next Step.
- On the Fulfillment page, configure your preferred settings or leave the Fulfillment toggle disabled as it is, then click Save and Finish.
- Click Publish Changes and wait for the operation to be completed.
- After publishing, your application is now enabled for SSO.
- View the newly created application on the Applications page. Choose Export Metadata from the dropdown list. This Metadata will be used later in the WORKDAY configuration.
Configure WORKDAY
Perform these steps to configure WORKDAY SIP
Procedure
- Log in to WORKDAY tenant with an Administrator account.
- Navigate to Account Administration > Edit Tenant Setup – Security.
- Click the + icon under Redirection URLs to add a row.
- In the Redirect URLs section, enter the Login Redirect URL for your tenant. This should match the ACS URL in the RSA configuration.
- Use the scroll bar to continue filling the SAML Identity Provider fields.
- In the SAML Setup section, select the checkbox Enable SAML Authentication and then click the + icon under SAML Identity Providers.
- Click Import Identity Provider, select the meta data file downloaded from RSA.
- Configure the fields in the SAML Identity Provider table, select the following values:
- Enter a unique value for the Service Provider ID.
- Enable the Enable SP Initiated SAML Authentication.
- Enable the Do Not Deflate SP-initiated Authentication Request.
- Enable the Always Require IDP Authentication.
- Select ForceAuthn Only.
- Click OK
The configuration is complete.
Related Articles
Salesforce - SAML IDR SSO Configuration RSA Ready Implementation Guide 56Number of Views Salesforce - SAML My Page SSO Configuration - RSA Ready Implementation Guide 66Number of Views Workday - SAML Relying Party Configuration - RSA Ready Implementation Guide 4Number of Views How to fix duplicate rpm issue during SA upgrade process 41Number of Views Skyhigh End User Remediation Flow - SAML My Page SSO Configuration - RSA Ready Implementation Guide 21Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) How to install the jTDS JDBC driver on WildFly for use with Data Collections in RSA Identity Governance & Lifecycle RSA Authentication Manager 8.8 Setup and Configuration Guide Artifacts to gather in RSA Identity Governance & Lifecycle
Don't see what you're looking for?