Workday - SAML My Page SSO Configuration - RSA Ready Implementation Guide
This article describes how to integrate Cloud Access Service (CAS) with Workday using My Page SSO.
Configure CAS
Perform these steps to configure RSA Cloud Access Service using My Page SSO.
Procedure
- Sign in to RSA Cloud Administration Console and navigate to Applications > Application Catalog.
- Click Create from Template, then click Select next to SAML Direct.
- On the Basic Information page, select Cloud.
- In the Name field, enter the application name and click Next Step.
- On the Connection Profile page, navigate to Initiate SAML Workflow section and choose IdP-initiated.
- In Data Input Method, Choose Enter Manually.
- Scroll down to the Service Provider section. enter the following fields in the following format:
- Assertion Consumer Service (ACS) URL: https://<WORKDAY-domain>/<tenant>/login-saml.htmld
- Service Provider Entity ID: Enter the same Service Provider Entity ID entered in the format http://<WORKDAY-domain>/<tenant>/
- In the Message protection section, select IdP Signs entire SAML response.
- Click Download Certificate.
- In the User Identity section, select the following values:
- Identifier Type > unspecified
- Property > sAMAccountName
- In the Statement Attributes section, select the following values:
-
Attribute Name: Username
-
Attribute Source: Identity Source
-
Property: SAMAccountName
-
- On the User Access page, choose the access policy you want to use to determine which users can access the application, then click Next Step.
- On the Portal Display page, configure the portal display and other settings. Then click Next Step.
- On the Fulfillment page, configure your preferred settings or leave the Fulfillment toggle disabled as it is, then click Save and Finish.
- Click Publish Changes and wait for the operation to be completed.
- After publishing, your application is now enabled for SSO.
- View the newly created application on the Applications page. Choose Export Metadata from the dropdown list. This Metadata will be used later in the WORKDAY configuration.
Configure WORKDAY
Perform these steps to configure WORKDAY SIP
Procedure
- Log in to WORKDAY tenant with an Administrator account.
- Navigate to Account Administration > Edit Tenant Setup – Security.
- Click the + icon under Redirection URLs to add a row.
- In the Redirect URLs section, enter the Login Redirect URL for your tenant. This should match the ACS URL in the RSA configuration.
- Use the scroll bar to continue filling the SAML Identity Provider fields.
- In the SAML Setup section, select the checkbox Enable SAML Authentication and then click the + icon under SAML Identity Providers.
- Click Import Identity Provider, select the meta data file downloaded from RSA.
- Configure the fields in the SAML Identity Provider table, select the following values:
- Enter a unique value for the Service Provider ID.
- Enable the Enable SP Initiated SAML Authentication.
- Enable the Do Not Deflate SP-initiated Authentication Request.
- Enable the Always Require IDP Authentication.
- Select ForceAuthn Only.
- Click OK
The configuration is complete.
Related Articles
Error "PIN change failed dictionary check" and authentication fails for a user in new PIN mode in RSA Authentication Manag… 88Number of Views SA server is not connecting SA Live cloud due to Local network Proxy 8Number of Views How to close ports used by the RSA Authentication Agent to block SSLv3 communication to RSA Authentication Manager 8.x 386Number of Views Release Notes Archive - Cloud Authentication Service and Authenticators (November 2025 - May 2025) 61Number of Views After Microsoft Windows update and/or GPO changes, administrative users cannot login to RSA Authentication Manager 8.1 Sec… 415Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA Release Notes for RSA Authentication Manager 8.8 RSA SecurID Software Token 5.0.2 for Windows Desktop displays message after reboot due to roaming profile: No token stor… Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?