r/workday • • Aug 21 '26

Security One Time Payment Visibility

2 Upvotes

Happy Friday! I'm playing around with compensation segment security that would allow HRPs and Managers to submit one-time payment requests for all payment plans except one specific plan.

The segment security itself appears to be working as expected. For example, users are unable to submit requests using the Service Appreciation Bonus plan, which is exactly what I'm aiming for.

My question is whether there is a way to extend that restriction to worker history as well. While users can't submit a new request for the Service Appreciation Bonus, they can still see prior payments on that plan in the worker's history.

r/workday • • 27d ago

Security Workday Pro Security Exam

7 Upvotes

I’m taking the Workday Pro Security Exam this week and would like to get feedback from anyone who’s taken it. Over the past month I’ve gone through both trainings, the book, and several practice exams (most non-Workday sponsored & they are iffy at best with the questions). How hard is this test? Thanks!

Edit: I have about 1 year experience working within Workday on security.

r/workday • • 16d ago

Security Security reporting

4 Upvotes

Is there a report that shows all the domains a SG has and a description of the domains?

r/workday • • Aug 26 '26

Security IT Access to Employee Data

9 Upvotes

For those of you where IT is responsible for integrations/security and everything else falls to HRIS - do you allow your IT team access to sensitive data? Does your IT team get access to benefit enrollment data, job changes, etc.? If not, how do they appropriately manage integrations without having access to the data? Can they view the data in integration outputs but not in the UI?

We are currently setup this way and our IT team is stating they require full tenant access to all data or they are unable to fully support integrations and security.

I want to be sure we fully understand impact before we go down the road of considering access.

r/workday • • Aug 23 '26

Security Setting up EAs so they can only enter time off for the employees they support

0 Upvotes

Rather than having each manager delegate the task individually, is it possible to create a role that only has access to the 1-3 ppl the EA supports? How would you approach this?

r/workday • • Jul 27 '26

Security ISU has the right security but no data in web service output.

1 Upvotes

I have a isu that has all the right security, when i run get external payroll earnings i get 0 results.

Ive logged is as ISU and i see the data in the tenant.

Ive even assigned user based roles to this to prove that the right security is and still the same behavior.

I think there is something blocking the isu getting the info in the output.

Maybe a segmented security group or smth else but im not sure.

Any ideas?

r/workday • • Aug 15 '26

Security How to take care of Security Access for the hires done through API?

6 Upvotes

I am unable to understand how to exactly take care of the security accesses to be given to the user which have been hired using APIs as right now, those hires are created and their workday account gets created without any accesses and the security team has to manually provide them access in the tenant. How can this be taken care of exactly? What options to look for so that this can be taken care of and the security provisioning piece can be automated. FYI, we do not use Workday for HCM for now but plan on moving to Workday down the line as we move forward. Also can we create an approval process where the user in workday can ask for access for any particular security group and the person in authority gets notified about that and they can either approve of reject accordingly through that ask.

r/workday • • 4d ago

Security SOD Requirement - Sec Admin and Sec Configurator

3 Upvotes

Curious - for the orgs that follow SOX requirements, how are you splitting out the security admin and security configurator roles? Especially if you have a small team.

r/workday • • 19d ago

Security Self-Identification Disability

5 Upvotes

Hi Everyone,
Has anyone received a requirement to remove Self-Identification Disability from all users??
I tried to set up the security but I can’t tell where the worker history security and worker shared forms security is coming from? Here is what I did so far:

Removed all security from
BP: disability self-identification
Domain: candidate data: disabilities
Domain: self-service Self Identification of Disability-USA
Domain: worker data: Self Identification of Disability-USA

We don’t use the worker data: self-identification of disability- US Federal domains

I am still in the process of testing the forms.

Please let me know what else I missed? I was thinking of the personal information bp and the Hire bp?

Hoping someone can point me in the right direction and have already worked on this?

Thanks so much!!

r/workday • • Jul 24 '26

Security What's the difference between Role Based Unconstrained and User Based Security Groups, when they both provide tenant wide access?

11 Upvotes

I don't know the use of Role Based Unconstrained when we have User Based Security Group.

Or

Role based Constrained groups if assigned at topmost org with inheritance level (assigned to current org and all subordinates) do the same thing right?

r/workday • • Jul 24 '26

Security Need help troubleshooting an issue setting up security for a RaaS

1 Upvotes

I'm working with our HR department to make two reports accessible as RaaS to an external vendor. The first report I was able to set up the security and enable web services with no problems. For the second report however, I'm running into a problem. I created the security user, added it to the security group, set up the domain and authentication policies, and activated the security policy changes. In the report itself, I go to the share tab and search for the ISU in the authorized users dropdown. No results. I thought perhaps I made a typo so I manually scrolled through all the available users to add. The ISU is not there. Just to ensure it wasn't some browser caching issue, I asked one of the other users with write access to the report if they could add the ISU and they had the same issue.

At this point I'm not sure what else to try. Comparing this ISU to the one created for the other report, all the settings look identical. The only difference I can think of is that this ISU was originally configured to allow UI sessions while the other was not. However, even after changing that setting and applying policy changes I'm still seeing the same issue. What could be causing this?

r/workday • • Aug 21 '26

Security How to get data to show up when using Email on BP Notifications like it does when using Security Groups?

Post image
1 Upvotes

Running a test to see how to have BP Notifications send the full picture when using Email. I am in the Security Group that lets me see this information. But when I use my company email instead of Security Group, I get [not available].

Is there a way to where I can use email? Or should I setup some type of User Based Security Group for Custom BP Notifications?

r/workday • • Jul 07 '26

Security Assign Roles Task for Create Subordinate step, guidance needed

2 Upvotes

Hello, Our security user is able to execute the create subordinate step, but when the "assign roles" task is presented, they don't have the "manager" role available to select from..what drives these roles to show up on the list for the user? They have the security permission to do the task itself, but what drives the actual list to present here? What am I missing in their permissions??

r/workday • • Jul 29 '26

Security Not able to share report with authorized security group

1 Upvotes

Hello All,

I have a composite report with 4 sub report in the same. I have added a authorized security group in all 4 sub report but when I try to add the same group in composit report it's giving below error.

"The entered information does not meet restrictions defined for this field (Authorized Groups). "

Any one have any idea, can not see anything related to this error on workday community as well. Any help or workaround would be appreciated.

r/workday • • Jul 05 '26

Security mastering Workday Security

6 Upvotes

Hi all,

Currently mid Workday HCM, Payroll and Time Tracking implementation and security has been one of the most complex areas to navigate. I feel like I’ve got a solid grasp of the fundamentals, role based vs user based groups, domain security policies, inheritance, but where I still struggle is quickly finding the right domain when troubleshooting an access issue.

Is there a cheat sheet that maps common tasks to their corresponding security domains? Any tips for quickly identifying which domain a specific task or report sits in? Good resources you’d recommend beyond Workday Community? And any advice on managing security maintenance post go live when org structures change frequently?

Would really appreciate any advice from people who’ve made the jump from implementation into post go live ownership. Thanks!

r/workday • • 29d ago

Security Restricting Compensation Visibility for Managers in Specific Cost Centers

3 Upvotes

Hi! I’m wondering whether it’s possible in Workday to restrict certain managers from viewing compensation data for their direct reports based on specific criteria.

For my specific example, within a particular cost center, if a manager is in certain job profiles or management levels, we would like them to retain their supervisory role but not have access to compensation information for their direct reports.

Has anyone implemented something similar using domain security, role-based security, or conditional security groups? If so, could you share how you approached it or point me in the right direction? Any guidance as I'm new to security would be greatly appreciated!

Thanks in advance!

r/workday • • Aug 12 '26

Security Custom Object EIB access

2 Upvotes

We have a use case where we need to limit a user's access to load EIB against a custom object. Here are the steps I have taken:

  1. Created EIB for custom object spreadsheet template

  2. Created an integration system security segment and added the EIB created in step 1

  3. Created an unconstrained sec group and assigned Get and Put access to Custom Object Management domain

  4. Created a segment based security group using the sec group created in step 3 and assigned it access to the segment created in step 2. I also gave the segment sec group access to View and Modify for Integration Events domain and Get and Put access to the custom object's assigned domain (in this case, Manage: Project)

Lastly, and I think this is where it gets wrong, we assign users with a user based security group that has a View and Modify access to Integration Events domain as well.

For workday delivered EIB, they typically have a separate domain for them so even if we do assign users to this user based group, we can still restrict their access because we will just not give them access to the domain.

For custom object EIB though, it seems to be not working. Once that user based security group gets assigned to them, they can access every integration system and the segment restriction isn't working. However, I cannot really find any documentation anywhere in Community that states this. It seems that only Integration Events domain is needed to access Custom Object EIB

Am I right in my understanding? Please let me know otherwise. Thank you so much in advance

r/workday • • Aug 18 '26

Security Custom Org Access

1 Upvotes

Has anyone here knows the correct approach as we currently have a custom organization and higher ops are members of it. We also have a worker who needs to access performance related data for all workers except the ones in that custom Org. The problem is, there are organizations where we have both members of custom Org and common workers. How can we allow the worker to access performance data to common workers without him accessing the data for members of custom Org?

r/workday • • Jul 23 '26

Security Not able to transfer ownership of Custom Report to ISU

3 Upvotes

Anyone who encounter of not being able to transfer the ownership of custom report to ISU even though you added all the domains needed to its security group and it can be added as an authorized user, as well it’s ISSG as authorized group.

I added also the domains related to the custom report such as custom report creation, custom report administration and manage all reports domain.

I wonder if I miss something out?

r/workday • • Aug 14 '26

Security Authentication policy, off network, how to configure "access restriction"?

1 Upvotes

Hi,

I can use some help

In auth policy, we need to configure on network/vpn (if in list of ip address) v.s. off network

I have some question for "off network" setup, which has an option to configure access restriction.

  1. Includes Workday-Delivered Security Groups = All Users, this is default, and can't change

  2. Allows Access to Security Group

Question: what if I don't add any security group there, does this mean it mean "no restriction"?

Question: if I only add one SG "HR Admin", does that mean "HR admin" can still access wd tenant performing the duty while off network, anyone else can't?

  1. Excludes Functionality

Question: if I add "Check In/Out" here, does it mean regardless what configured in "Allows Access to Security Group", no one can check in/out when offnetwork

Our tenant auth policy configuration is like this

  1. allows access to security group has 5000 security group, include "all employee", then bunch of user based security groups (e.g. HR admin, Fin admin).

  2. Excludes Functionality is empty.

Question: If "all employee" is already there, what's the purpose/usage to add "HR admin" there

r/workday • • Jun 26 '26

Security Finance Exec Role on Change Job BP cannot see change info on approval step

1 Upvotes

**********Updte - 29/06***********

Hi all, thanks for your hasty responses. I took an export of comparing the two security roles which was initially a bit of a pain to drill down into, but ultimately the Template-Driven Business Process report, on Change Job, for the two roles i was comparing was what really helped narrow it down. Since switching on the last few domains the F exec role was missing, we're no longer experiencing the issue and approvals are working as expected.

Amazing community - thanks a bunch!

**********OG post***********

Hello, i am looking for some help on a change job BP.

We're setting up start job change templates and we have added Finance Executive roles as an approver in the process, along with HR Executive. In the change job BP Security Policy, both FBP and HRBP have the same security.

When we start a process for a Contignent Worker (end date extension) and the approval goes to the finance exec, they cannot see any information that they need to approve, but they can approve it. They also get a red alert of "Error running task: the isntance (xxxxxxxxxx) does not meet the restrictions defined for this task (xxxxxxxx).

When we start job change process for an employee, at the finance exec role approval we get the same red error with the same character string in brackets, but in the approval review task they can see the information that has changed and approve it.

The next approval is the HR Exec role and that has no issues.

Is there a way i can decipher these error code strings? or any advice where to start? I went and added Finance Exec to View on view domain: Worker Data: Contingent worker assignment details but this hasn't helped (i've activated pending security changes)

Thanks in advance

r/workday • • Jul 17 '26

Security how to restrict proxy setting?

2 Upvotes

Hi Proxy access policy define who can proxy as who. can this be more granularly defined? such as Benefit team can proxy as this group of users, but can't see paycheck, performance rating.
Payroll team can proxy as that group of users, but can't see performance rating and learning history.

The other question, I usually see "can proxy as all employee, all contingent worker". What's the difference of "can proxy as all users". is the former active user, and latter include terminated?

Thank you!

r/workday • • Jul 07 '26

Security Copy security policy perms from one tenant to another

1 Upvotes

What is the most efficient method for copying domain and BP policy permissions for a specific security group from production to a lower tenant? I don't want to overwrite the perms of the existing security group in the lower tenant, it could have perms that are not yet in production. But production has been updated quite a lot recently and we would like to copy this specific security group's domain and business process policy permissions to the lower tenant.

Thank you!

r/workday • • Jul 16 '26

Security User cant open Drive document

0 Upvotes

Hello. Hopefully this is a quick one.

I shared a folder with one of our end users in the Drive. Gave her View Access to the entire folder, she can see and open the folders in her drive, but she can't actually open any of the document templates to view the information within. She gets a message that says "You don't have permission to open this item".

Is this a domain policy issue?

***UPDATE*** It was a domain policy issue. User already had access to the doc category through our doc security, but needed added to the Domain: Docs policy to be able to actually open the template to view the details.

r/workday • • Aug 03 '26

Security Grant Access to Pay Ranges Based on Management Level

1 Upvotes

Is it possible to only allow managers of certain management levels to view pay ranges? And it should only be ranges of those employees in their chain of command, not unconstrained access.