↳ GitHub sourceConnector

Workday User Activity (via Codeless Connector Framework)

Description

The [Workday](https://www.workday.com/) User Activity data connector provides the capability to ingest User Activity Logs from [Workday API](https://community.workday.com/sites/default/files/file-hosting/restapi/index.html#privacy/v1/get-/activityLogging) into Microsoft Sentinel.
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Workday User Activity API access
Access to the Workday user activity API through OAuth is required. The API Client needs to have the scope: System and it needs to be authorized by an account with System Auditing permissions.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Connect Workday to Microsoft Sentinel
1) In Workday, access the "Edit Tenant Setup - Security" task, verify "OAuth 2.0 Settings" section, make sure that the "OAuth 2.0 Clients Enabled" check box is ticked. 2) In Workday, access the "Edit Tenant Setup - System" task, verify "User Activity Logging" section, make sure that the "Enable User Activity Logging" check box is ticked. 3) In Workday, access the "Register API Client" task. 4) Define the Client Name, select the "Client Grant Type": "Authorization Code Grant" and then select "Access Token Type": "Bearer" 5) Enter the "Redirection URI" found in the form below 6) In section "Scope (Functional Areas)", select "System" and click OK at the bottom. 7) Copy the Client ID and Client Secret before navigating away from the page, and store it securely. 8) In Sentinel, in the connector page - provide required Token, Authorization and User Activity Endpoints, along with Client ID and Client Secret from previous step. Then click "Connect". You can find the exact endpoint values in the "View API Clients" report in your Workday tenant; the host differs per environment (for example, wd3-impl-services1.workday.com for implementation tenants and services1.myworkday.com for production tenants). 9) A Workday pop up will appear to complete the OAuth2 authentication and authorization of the API client. Here you need to provide credentials for Workday account with "System Auditing" permissions in Workday (can be either Workday account or Integration System User). 10) Once that's complete, the message will be displayed to authorize your API client
Connection Alias
Enter a unique alias to identify this Workday connection. **Important**: Use different aliases for each tenant/domain. To update an existing connection, use the same alias or delete and recreate it.
Query interval (in minutes)
5
10
15
20
30
60
Page size (records per request)
100
250
500
750
1000
Token Endpoint
Authorization Endpoint
User Activity Logs Endpoint (ends with /activityLogging)

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
WorkdayCCPDefinition
Additional source files 2Solutions/Workday/Data Connectors/Workday_ccp/Workday_DataConnectorDefinition.jsonsource ↗Solutions/Workday/Data/Solution_Workday.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.