Example: Mobile PIN Authentication
This example illustrates 1 way to configure an authentication policy that enables the use
of a Personal Identification Number (PIN) on mobile devices.
Your organization uses a SAML Single Sign-On (SSO) solution. You want to enable workers to
access Workday self-service tasks using a PIN to sign in on their mobile devices,
however. You want to set the Mobile PIN with strict requirements:
- PIN length from 6 to 8 digits.
- Only 2 failed attempts before Workday resets the PIN.
- PIN expires after 30 days.
You must have security administrator privileges.
- Access theEdit Tenant Setup - Securitytask.
- In theMobile Authenticationsection, select theEnable Mobile PIN Authenticationcheck box and enter these settings:
Option Description PIN Min Length6PIN Max Length8PIN Max Failed Signin Attempts2Max Mobile Authentication Age (in days)30 - Access theManage Authentication Policiesreport.
- Create a new authentication policy or edit an existing one.
- In theAuthentication Rulesetgrid, add this rule:
Option Description Authentication Rule NameWorker Self-Service on Mobile RuleSecurity GroupAll EmployeesAll Contingent WorkersAuthentication ConditionAnyAllowed Authentication TypesMobile PINSAMLAccess Restriction for Authentication ConditionSelf-Service(See the next step to create.) - If you haven't yet defined access restrictions, you can click the prompt for the appropriate rule underAccess Restriction for Authentication Conditionand selectCreate Access Restriction.ForWorker Self-Service on Mobile Rule:
Option Description NameSelf-ServiceAllows Access to Security GroupsEmployee As SelfContingent Worker As Self - In theDefault Rule for All Users, check theDisabledcheck box.
- ClickOKandDone.
- Access theActivate All Pending Authentication Policy Changestask to activate and confirm the changes.
- Notify your workers that they must sign in using their SAML SSO credentials before they set up their PIN.A worker needs to set up a new PIN to sign in with their SAML SSO credentials if Workday resets the PIN due to:
- Too many failed sign-in attempts.
- An expired PIN.
All workers can perform self-service tasks from their mobile devices, using their PIN
to sign in.