Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Integrate with Workday using Basic Authentication

Integrate your Software Asset Management application with the Workday application using Basic authentication method to track your software subscriptions.

Configure permissions in Workday

To set up the Workday integration successfully, perform this procedure in Workday.

Before you begin

Role required: Users having roles such as Security Admin, Integration Admin, Integration Auditor, who can create Integration System Users and assign required security policies.

Procedure

  1. Register an Integration System User.

    Note: While filling out account information details, you must select the Do Not Allow UI Sessions check box.

  2. Create a security group and assign it to the Integration System User.

    1. In Action, navigate to Security Group > Maintain Domain Permissions for Security Group and provide the following permission:

      OperationDomain Security PolicyFunctional Areas
      Get OnlyWorker Data: Public Worker ReportsStaffing
      Get OnlyWorker Data: Current Staffing InformationStaffing
      Get OnlyWorker Data: WorkersStaffing

      Note: Confirm that the domain security policies are activated for the security group using the active pending security policy changes.

Result

The new credentials for this Integration System User would be used to configure the connection in the ServiceNow instance.

Create a Workday integration profile

Create a Workday integration profile to track software subscriptions and optimize licensing for your Workday applications.

Before you begin

Role required: admin, sam_admin, sam_integrator

Install the latest Workday HR spoke. For more information about the latest version, see the Spoke version section in Workday HR Spoke.

Important: You must select the Software Asset Management integration with Workday check box for this integration while installing optional features on the Application Manager page. For more information about choosing the required SaaS applications, see Request SaaS License Management.

About this task

If you’re using Software Asset Workspace, the option to create the Workday integration profile in Core UI is inactive.

Procedure

  1. Navigate to the integration profile.
InterfaceAction
Core UI
  1. Navigate to All > Software Asset > SaaS License > Direct Integration Profiles.
  2. Select New.
  3. Select Workday Integration Profile.
Software Asset Workspace
  1. Navigate to License operations > User Subscriptions > Direct integration profiles.
  2. Select New.
  3. Select Workday from the drop-down list.
  4. Select Continue.
  1. On the form, fill in the fields.
FieldDescription
Integration Profile
Display nameName of the integration profile. For example, `Workday integration`.
Authentication typeType of authentication to access Workday APIs.- Basic Auth - OAuth 2.0
StatusStatus of the integration profile. - If you haven’t published the integration profile, this field is automatically set to  Draft. - If you’ve already published the integration profile, this field is automatically set to  Published.
Profile typeType of integration profile. This field is automatically set to Workday Subscription.
  1. Review the required user roles or API permissions specified in the Vendor configuration field for each process to minimize security risks and optimize SaaS licenses.

    Note: For more information, see Minimal user permissions table.

    In the Download Subscription Subflow section, verify that the Subflow field is set to Workday Download Subscriptions. The Download subscriptions check box is selected by default and you can't clear it.

  2. Select Save.

    The Connection Setup section is displayed on the integration profile.

FieldDescription
Connection Details- If the connection details exist, this field is already populated. - If the connection details don't exist, you must create them.
SOAP UsernameUser name of the Integration system user created while configuring permissions in Workday.Important: Include the tenant suffix in the username. For example, username@<tenant>.
SOAP PasswordPassword of the Integration system user created while configuring permissions in Workday.
  1. If connection details don't exist, create the connection details.

    InterfaceAction
    Core UIIn the Connection Details field, select the search icon (
Image omitted: search-icon.png
Search icon.\).|
|**Software Asset Workspace**|Select the **Connection details** link.|

1.  Select **New**.

2.  On the form, fill in the fields.

    |Field|Description|
    |-----|-----------|
    |Base URL|Workday SOAP API URL with the tenant name in the following format: `https://<workday_host_url>/ccx/service/<workday_tenant_name>`.|
    |Version|The SOAP API version, for example, `v33.2`.|
    |Webservice Type|Should be set to **SOAP**.|

3.  Select **Submit**.

    A record is created and added in the **Connection Details** field.

4.  Review the connection details by selecting the new integration profile and selecting the lookup icon
Image omitted: search-icon.png
Lookup icon in the **Connection details** field.
  1. Create a SOAP user name and password when you don't have these credentials automatically populated.

    Note: Only an admin role can create or update the SOAP user name and password.

InterfaceAction
Core UI
  1. Navigate to All > System Web Services > SOAP Security Policies.
  2. Select All in the top menu bar.
  3. Select WorkdayHR.
Software Asset WorkspaceSelect the SOAP username profile link.
1.  On the Soap Security Policy form, select the lookup icon
Image omitted: search-icon.png
Lookup icon in the **WS-Security Username Profile** field.
2.  Select **New**.

3.  On the WS-Security Username Profiles \(Outbound\) form, fill in the name, user name, and password for the integration profile.

4.  Select **Submit**.
  1. Select Save.

  2. Under the FSE worker calculation tab, activate the worker categories covered by your contract by setting the value of Active to true and entering the FSE percentage.

  3. If worker categories are listed in your contract but not available in the FSE worker calculation tab, add a new worker category.

    1. In the FSE worker calculation tab, select New.

    2. On the form, fill in the fields.

      FieldDescription
      Worker CategoryThe worker category listed in your contract.
      FSE PercentageThe FSE percentage for the worker category that you added. Full Service Equivalent (FSE) is the method by which the subscriptions are calculated.
      Integration profileThe Workday integration profile that you created.
      ActiveOption to make the worker category active.
    3. Select Submit.

  4. Define the mapping of the newly created worker category.

    1. Select the Worker category tab and select New.

    2. On the form, fill in the fields:

      FieldDescription
      Worker TypeThe type of worker, either Employee or Contingent.
      Employee/Contingent worker typeThe type of Employee or Contingent worker.
      Time TypeIndicates whether the worker is full-time or part-time.
      Worker CategoryThe worker category that you created.
      Integration profileThe Workday integration profile that you created.
      ActiveOption to make the mapping active.
    3. Select Submit.

  5. Activate the list of modules that are defined in your contract.

    1. Select the Modules tab.

    2. Open the module record.

    3. Set the Active field to True.

    4. Select Save.

  6. Verify that there is at least one active record in all the tabs for your contract: FSE worker calculation, Worker category, and Modules, before publishing the connection.

  7. On the integration profile form, select Validate Connection to verify the connection and credential details of this integration.

  8. After the connection is verified, select Publish.

  9. In the Publish Confirmation dialog box, select OK.

What to do next

After the integration connects, your ServiceNow instance automatically creates software models, reclamation rules, and software subscriptions that are refreshed daily.

After creating an integration profile, view information about the profile in the Software Asset Workspace by navigating to License operations > User subscription > Direct integration profiles. You can select an integration profile to view the following related lists. If all of the following related lists aren't visible for an integration profile in the default view, you can select the custom integration view from the Details tab:

  • Software Models
  • Unrecognized Subscription Identifiers
  • Scheduled Jobs
  • Scheduled Job Results
  • Software Subscriptions
  • Subscription Identifier Exclusion Rule
  • Subscription User Exclusion Rule

After creating an integration profile, you can define subscription exclusion rules to keep certain subscriptions from license cost calculations. For more information, see Subscription exclusions for SaaS and SSO applications.

If you want to set up multiple integration profiles with unique connections, create child aliases to manage different configurations and settings for each integration profile. For more information, see Create a child alias to set up multiple integration profiles.

Review all automatically generated reclamation rules to reclaim user subscriptions. For more information, see Review a software reclamation rule.

Create software entitlements for the automatically generated software models to track used software against owned software.

Reconciliation also runs on your subscriptions as a scheduled job or on-demand. You can view your reconciliation results in the License Workbench (Software Asset Management classic application) or the License usage view (Software Asset Workspace). Use these results to determine your license compliance position and to remediate any non-compliance.