Connect Workday to Microsoft Cloud App Security (Preview)

Applies to: Microsoft Cloud App Security

This article provides instructions for connecting Microsoft Cloud App Security to your existing Workday account using the app connector API. This connection gives you visibility into and control over Workday use.

Prerequisites

The Workday account used for connecting to Cloud App Security must be a member of a security group (new or existing). The security group must have the following permissions selected for the following domains:

Functional area Domain Subdomain Report/Task Permissions Integration Permissions
System Set Up: Tenant Setup – General Set Up: Tenant Setup – Security View, Modify Get, Put
System Security Administration View, Modify Get, Put
System System auditing View Get
Staffing Worker Data: Staffing Worker Data: Public Worker Reports View Get

For more information about setting up Workday integration users, security groups, and permissions, see steps 1 to 4 of the Grant Integration or External Endpoint Access to Workday guide (accessible with Workday documentation/community credentials).

We recommended using a Workday Integration System User.

How to connect Workday to Cloud App Security using OAuth

  1. Sign in to Workday with an account that is a member of the security group mentioned in the prerequisites.

  2. Search for "Edit tenant setup – system", and under User Activity Logging, select Enable User Activity Logging.

    Screenshot of allowing user activity logging

  3. Search for "Edit tenant setup – security", and under OAuth 2.0 Settings, select OAuth 2.0 Clients Enabled.

  4. Search for "Register API Client" and select Register API Client – Task.

  5. On the Register API Client page, fill out the following information, and then click OK.

    Field name Value
    Client Name Microsoft Cloud App Security
    Client Grant Type Authorization Code Grant
    Access Token Type Bearer
    Redirection URI https://portal.cloudappsecurity.com/api/oauth/connect
    OAuth2 Scopes Staffing and System
    Scope (Functional Areas) Staffing and System

    Screenshot of registering API client

  6. Once registered, make a note for the following parameters, and then click Done.

    • Client ID
    • Client Secret
    • Workday REST API Endpoint
    • Token Endpoint
    • Authorization Endpoint

    Screenshot of confirming registration of API client

  7. In the Cloud App Security portal, click Investigate and then click Connected Apps.

  8. In the App connectors page, click the plus button and then Workday.

    Screenshot of adding app connector

  9. In the popup, add your instance name and then click Connect Workday.

    Screenshot of adding instance name

  10. On the next page, fill out the details with the information you noted earlier, and then click Connect in Workday.

    Screenshot of filling out app details

  11. In Workday, a popup will ask you if you want to allow Cloud App Security access to your Workday account. To proceed, click Allow.

    Screenshot of authorizing access to app

  12. Back in the Cloud App Security portal, you should see a message that Workday was successfully connected. Make sure the connection succeeded by clicking Test API.

    Testing may take a couple of minutes. After receiving a success notice, click Close.

Note

After connecting Workday, you'll receive events for seven days prior to connection.

Next steps

Control cloud apps with policies

Premier customers can also create a new support request directly in the Premier Portal.