Workday identity, MFA & sign-in security checks
Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
On Workday, Black Cat runs 12 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Workday connector needs.
Checks (12)
severity: high Workday User Without MFA Required fix difficulty: easy #
Enable MFA for this Workday user account
- Navigate to Workday > Security > Authentication Policies
- Ensure the user's authentication policy requires MFA
- Verify the user has enrolled an MFA device
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Workday Dormant User Account fix difficulty: easy #
Review and disable inactive Workday accounts
- Verify the worker is still employed or on approved leave
- If no longer active, terminate the worker in Workday
- Disable the Workday account if not auto-disabled by termination
Satisfies: ISO 27001:2022 A.8.3 SOC 2 Type II CC6.2 CIS Controls v8 CIS-05.3 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: critical Terminated User With Active Account fix difficulty: easy #
Disable the Workday account for this terminated worker
- Navigate to the worker's profile in Workday
- Verify the termination date and reason
- Disable or lock the account under Security > Account
Satisfies: ISO 27001:2022 A.5.18 SOC 2 Type II CC6.2 CIS Controls v8 CIS-05.3 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: low User Without Manager Assigned fix difficulty: easy #
Assign a manager to this worker
- Navigate to the worker's supervisory organization
- Assign the correct manager relationship
Satisfies: ISO 27001:2022 A.5.18 SOC 2 Type II CC6.2 NIST CSF 2.0 PR.AA-05 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: high Weak Password Policy fix difficulty: easy #
Strengthen password requirements to minimum 12 characters with complexity
- Navigate to Workday > Security > Authentication Policies
- Edit the password policy
- Set minimum length to 12 or higher
- Enable password complexity requirements
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high SSO Not Enabled fix difficulty: hard #
Configure SSO for centralized authentication
- Set up SAML or OIDC SSO with your identity provider
- Enable SSO in the authentication policy
- Test SSO login before enforcing
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.AA-02 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: critical MFA Not Enforced fix difficulty: easy #
Enable MFA enforcement in the authentication policy
- Navigate to the authentication policy
- Enable 'Require Multi-Factor Authentication'
- Communicate the change to affected users
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Excessive Session Timeout fix difficulty: easy #
Reduce session timeout to 60 minutes or less
- Navigate to the sign-on policy
- Set session timeout to 60 minutes or less
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high No Account Lockout Policy fix difficulty: easy #
Configure account lockout to prevent brute-force attacks
- Navigate to the password policy
- Set lockout threshold to 5-10 failed attempts
- Set lockout duration to 15-30 minutes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high Delegated Auth Certificate Expiring Soon fix difficulty: medium #
Renew the delegated authentication x.509 certificate
- Generate a new certificate from your identity provider
- Upload the new certificate in Workday delegated auth config
- Test authentication before the old certificate expires
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Delegated Auth Allows Local Fallback fix difficulty: easy #
Disable local password fallback to enforce SSO
- Navigate to Workday delegated auth configuration
- Disable 'Allow Workday-Initiated Password Sign On'
- Ensure SSO is fully operational before disabling fallback
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Account Lockout Duration Too Short fix difficulty: easy #
Increase the account lockout duration to at least 15 minutes
- Navigate to Workday > Security > Authentication Policies
- Edit the password / lockout policy
- Set the lockout duration to 15 minutes or more (15-30 recommended)
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4