Skip to Content.
Sympa Menu

workday - Re: [InC-Workday] Update on Workday MFA

Subject: Discussion of use cases and implementation experience integrating with Workday

List archive

Re: [InC-Workday] Update on Workday MFA


Chronological Thread 
  • From: Renee Shuey <>
  • To:
  • Subject: Re: [InC-Workday] Update on Workday MFA
  • Date: Thu, 25 Feb 2016 12:48:10 -0500 (EST)

Thank you CW.

Is there an update from the February 11 meeting?  Penn State is in the early stages of implementing Workday.  There is an executive level meeting next Thursday with Penn State and Workday.  Is there anything we can do to help?

Also, does anyone have a one page executive paper on why InCommon and or enterprise 2FA?  I've committed to writing something for next week but would love to steal your work if it already exists. ;-)  Ok, I could say want to represent a consistent message from the community. 

Thanks in advance!
Renee


From: "Belcher, C W" <>
To:
Sent: Tuesday, January 26, 2016 6:33:47 PM
Subject: [InC-Workday] Update on Workday MFA

Hi folks, 

I hope everyone’s year is getting off to a good start. It’s been a while since we have communicated about Workday and MFA! I wanted to give you some updates on UT Austin’s discussions with Workday: 
  • Workday has designed an enhancement to authentication policies to require step-up authentication for specific functions / security groups. This enhancement may make the cut for WD27 (still trying to get confirmation on that). 
  • However, the proposed step-up authentication would use internal Workday two-factor (SMS or email OTP), which is unacceptable to UT Austin (and to many of your institutions, based on our prior email thread). We have communicated to Workday our requirement for the step-up authentication to be deferred to our SAML IdP. 
  • With the help of the write-up from NYU (thanks Gary Chapman and Scott Koranda!) Workday now understands what we want in terms of SAML-based MFA. 
  • Chris Co’s team at Workday is analyzing what would be required to implement SAML-based step-up authentication. They have asked us (UT Austin) to help with a proof-of-concept, which we will be working on over the next two weeks. 
  • The next Workday authentication design partner call is February 11th and Workday is supposed to indicate then whether the SAML-based stepped-up authentication feature will make it into WD27. 
  • As a reminder, the Workday brainstorm for step-up authentication is https://community.workday.com/idea/90665 
I’ll be providing an update on the IAM Online call tomorrow 1/27 at 1PM CT so please let me know if you have Workday MFA news to share from your campuses or feel free to join the discussion live :) 

Thanks, CW

——


C.W. BELCHER, Associate Director 

Identity & Access Management  |  Information Technology Services 

The University of Texas at Austin  |  512-232-6519  |  FAC 326R





Archive powered by MHonArc 2.6.16.

Top of Page