


| Field | Value |
|---|---|
| Client ID (=SP Entity ID) | <TENANT_NAME>.workday.com |
| Name | Workday |
| Description | Workday SSO integration |
| Assertion Consumer Service URL | <TENANT_NAME>.workday.com/saml2/acs |
| NameID Policy Format |
| Field | Value |
|---|---|
| Client ID | <TENANT_NAME>.workday.com |
| Name | Workday |
| Description | Workday SSO integration |
| Always display in UI | ON |
| Field | Value |
|---|---|
| Home URL (IdP-initiated) | https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/clients/<APP_NAME> |
| Valid Redirect URIs (ACS) | Paste Workday’s ACS URL |
| IDP-Initiated SSO URL Name | <APP_NAME> |
| Valid post logout redirect URIs | Paste Workday’s Single Logout URL if used (Optional) |
| Setting | Value |
|---|---|
| Name ID Format | |
| Force Name ID Format | ON |
| Force POST Binding | ON |
| Include AuthnStatement | ON |
| Setting | Value |
|---|---|
| Sign Documents | OFF |
| Sign Assertions | ON |
https://<TENANT_NAME>.workday.com/saml2/acs
Multi-Pass as the Identity Provider Name.