Skip to main content

Configure authentication to Workday

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Workday Activity Logging from the Previews page. See Manage Databricks previews.

Configure Workday to enable authentication and user activity log access for the Workday Activity Logging connector. Use the values from these steps to create a Unity Catalog connection in Databricks.

Prerequisites​

You must have permission in Workday to edit tenant settings, create integration system users and security groups, update domain security policies, register API clients, and generate refresh tokens.

Enable activity logging and OAuth​

  1. In Workday, search for and select Edit Tenant Setup - System.
  2. Ensure that Enable User Activity Logging is selected.
  3. Search for and select Edit Tenant Setup - Security.
  4. Ensure that OAuth 2.0 Clients Enabled is selected.

Create an integration system user​

  1. In Workday, search for and select Create Integration System User.
  2. Enter a user name. For example, ISU_Databricks.
  3. Enter a new password.
  4. Set Session Timeout Minutes to 0.
  5. Select Don't Allow UI Sessions.
  6. Click OK.
  7. Record the user name. You use it when you generate the refresh token.

Configure security permissions​

  1. In Workday, search for and select Create Security Group.
  2. For Type of Tenanted Security Group, select Integration System Security Group (Unconstrained), and enter a name for the group. For example, ISSG_Databricks_Monitoring.
  3. Click OK.
  4. In the next form, add the integration system user to Integration System Users.
  5. Click OK, then click Done.
  6. Search for and select View Domain.
  7. For Domain, select System Auditing.
  8. Click the three-dot menu next to the System Auditing domain name, then select Domain > Edit Security Policy Permissions.
  9. Add the security group to the Report/Task Permissions table and grant it View access.
  10. Add the security group to the Integration Permissions table and grant it Get access.
  11. Click OK, then click Done.
  12. Search for and select Activate Pending Security Policy Changes.
  13. Enter a description for the change.
  14. Click OK.

Register an API client​

  1. In Workday, search for and select Register API Clients for Integrations.
  2. Enter a Client Name. For example, Databricks User Activity Monitor.
  3. Select Non-Expiring Refresh Tokens to avoid interruptions caused by refresh token expiration.
  4. For Scope (Functional Areas), select System.
  5. Click OK.
  6. Record the Client ID and Client Secret. You use these values when you create the Unity Catalog connection.

Retrieve the Workday values for Databricks authentication​

  1. In Workday, search for and select View API Clients.
  2. Select the API Clients for Integrations tab.
  3. For the API client that you created, confirm that the following settings are enabled:
    • Client Grant Type: Authorization Code Grant
    • Access Token Type: Bearer
  4. Locate the Workday REST API Endpoint. Record the following values from the URL:
    • The instance domain, ending in .com and excluding the scheme and path. For example, wd2-impl-services1.workday.com.
    • The tenant name, which appears after /v1/ in the URL.
  5. Click the API client link. On the View API Client page, click the three-dot menu next to the client name.
  6. Select API Client > Manage Refresh Token for Integrations.
  7. For Workday Account, select the integration system user, then click OK.
  8. Select Generate New Refresh Token, then click OK.
  9. Record the refresh token. You use it when you create the Unity Catalog connection.

Next steps​

Create a Workday Activity Logging connection in Databricks. See Create a Workday Activity Logging connection.