Skip to content

Workday identity, MFA & sign-in security checks

Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.

On Workday, Black Cat runs 12 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Workday connector needs.

Checks (12)

severity: high Workday User Without MFA Required fix difficulty: easy #

Enable MFA for this Workday user account

  1. Navigate to Workday > Security > Authentication Policies
  2. Ensure the user's authentication policy requires MFA
  3. Verify the user has enrolled an MFA device

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Workday Dormant User Account fix difficulty: easy #

Review and disable inactive Workday accounts

  1. Verify the worker is still employed or on approved leave
  2. If no longer active, terminate the worker in Workday
  3. Disable the Workday account if not auto-disabled by termination

Satisfies: ISO 27001:2022 A.8.3 SOC 2 Type II CC6.2 CIS Controls v8 CIS-05.3 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

severity: critical Terminated User With Active Account fix difficulty: easy #

Disable the Workday account for this terminated worker

  1. Navigate to the worker's profile in Workday
  2. Verify the termination date and reason
  3. Disable or lock the account under Security > Account

Satisfies: ISO 27001:2022 A.5.18 SOC 2 Type II CC6.2 CIS Controls v8 CIS-05.3 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

severity: low User Without Manager Assigned fix difficulty: easy #

Assign a manager to this worker

  1. Navigate to the worker's supervisory organization
  2. Assign the correct manager relationship

Satisfies: ISO 27001:2022 A.5.18 SOC 2 Type II CC6.2 NIST CSF 2.0 PR.AA-05 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

severity: high Weak Password Policy fix difficulty: easy #

Strengthen password requirements to minimum 12 characters with complexity

  1. Navigate to Workday > Security > Authentication Policies
  2. Edit the password policy
  3. Set minimum length to 12 or higher
  4. Enable password complexity requirements

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high SSO Not Enabled fix difficulty: hard #

Configure SSO for centralized authentication

  1. Set up SAML or OIDC SSO with your identity provider
  2. Enable SSO in the authentication policy
  3. Test SSO login before enforcing

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.AA-02 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: critical MFA Not Enforced fix difficulty: easy #

Enable MFA enforcement in the authentication policy

  1. Navigate to the authentication policy
  2. Enable 'Require Multi-Factor Authentication'
  3. Communicate the change to affected users

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Excessive Session Timeout fix difficulty: easy #

Reduce session timeout to 60 minutes or less

  1. Navigate to the sign-on policy
  2. Set session timeout to 60 minutes or less

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high No Account Lockout Policy fix difficulty: easy #

Configure account lockout to prevent brute-force attacks

  1. Navigate to the password policy
  2. Set lockout threshold to 5-10 failed attempts
  3. Set lockout duration to 15-30 minutes

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high Delegated Auth Certificate Expiring Soon fix difficulty: medium #

Renew the delegated authentication x.509 certificate

  1. Generate a new certificate from your identity provider
  2. Upload the new certificate in Workday delegated auth config
  3. Test authentication before the old certificate expires

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Delegated Auth Allows Local Fallback fix difficulty: easy #

Disable local password fallback to enforce SSO

  1. Navigate to Workday delegated auth configuration
  2. Disable 'Allow Workday-Initiated Password Sign On'
  3. Ensure SSO is fully operational before disabling fallback

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Account Lockout Duration Too Short fix difficulty: easy #

Increase the account lockout duration to at least 15 minutes

  1. Navigate to Workday > Security > Authentication Policies
  2. Edit the password / lockout policy
  3. Set the lockout duration to 15 minutes or more (15-30 recommended)

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

More Workday checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial