↳ Source GitHubConnecteur
Workday User Activity (via Codeless Connector Framework)
Description
The [Workday](https://www.workday.com/) User Activity data connector provides the capability to ingest User Activity Logs from [Workday API](https://community.workday.com/sites/default/files/file-hosting/restapi/index.html#privacy/v1/get-/activityLogging) into Microsoft Sentinel.
- Statut déclaré
- 1
- Auteur / éditeur déclaré
- Microsoft
Sources déclarées
Métadonnées du fichier source. Aucune dépendance déduite du KQL.
Types de données
Permissions déclarées
Read and Write permissions are required.
Workspace
Workspace
Workday User Activity API access
Access to the Workday user activity API through OAuth is required. The API Client needs to have the scope: System and it needs to be authorized by an account with System Auditing permissions.
Instructions du connecteur
Contenu publié dans le dépôt. Consultez le fichier original pour l’ensemble des paramètres.
Connect Workday to Microsoft Sentinel
1) In Workday, access the "Edit Tenant Setup - Security" task, verify "OAuth 2.0 Settings" section, make sure that the "OAuth 2.0 Clients Enabled" check box is ticked.
2) In Workday, access the "Edit Tenant Setup - System" task, verify "User Activity Logging" section, make sure that the "Enable User Activity Logging" check box is ticked.
3) In Workday, access the "Register API Client" task.
4) Define the Client Name, select the "Client Grant Type": "Authorization Code Grant" and then select "Access Token Type": "Bearer"
5) Enter the "Redirection URI" found in the form below
6) In section "Scope (Functional Areas)", select "System" and click OK at the bottom.
7) Copy the Client ID and Client Secret before navigating away from the page, and store it securely.
8) In Sentinel, in the connector page - provide required Token, Authorization and User Activity Endpoints, along with Client ID and Client Secret from previous step. Then click "Connect". You can find the exact endpoint values in the "View API Clients" report in your Workday tenant; the host differs per environment (for example, wd3-impl-services1.workday.com for implementation tenants and services1.myworkday.com for production tenants).
9) A Workday pop up will appear to complete the OAuth2 authentication and authorization of the API client. Here you need to provide credentials for Workday account with "System Auditing" permissions in Workday (can be either Workday account or Integration System User).
10) Once that's complete, the message will be displayed to authorize your API client
Connection Alias
Enter a unique alias to identify this Workday connection. **Important**: Use different aliases for each tenant/domain. To update an existing connection, use the same alias or delete and recreate it.
Query interval (in minutes)
5
10
15
20
30
60
Page size (records per request)
100
250
500
750
1000
Token Endpoint
Authorization Endpoint
User Activity Logs Endpoint (ends with /activityLogging)
Contenus associés
Liens établis à partir des identifiants déclarés et des manifests des solutions.
Traçabilité de la source
GitHubLes valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.
- Commit
629d1d3↗- Identifiant source
WorkdayCCPDefinition
GSTEP / SUIVI DU CATALOGUE
Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC