TECHNOLOGIES: WORKDAY

Workday Security Review

A Workday security group decides what a user or an integration can see and do. We test your security groups, business process configurations and integration access together. CREST-certified testers, fixed price from £4,180 for a 3-day single-tenant scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Workday Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Groups

A Workday security group, not a job title, decides what a user or an integration can actually see and do, and every person or system holds several groups at once that combine together.

Why a Workday finding is a security group or business process setting, not a Workday flaw

Workday’s own security documentation describes a role-based access model built from roles, security groups and business process configurations, layered on top of what Workday calls context-sensitive and context-free role-based security. That layering is exactly where a review earns its keep: a security group assembled for one job function, a business process step approved for one organisation, or a context rule written for one exception can each widen access in ways nobody revisits once the tenant is live. We test your security groups, business process configurations and the context rules sitting on top of them against what your organisation actually intended.

System-to-system access works differently again. Workday’s own data security whitepaper states that system-to-system access is facilitated via public web service or Reports-as-a-Service, with tight control over data results held through the Integration System Security Group. Workday also publishes a directory of its SOAP-based web services with their WSDL and XML schemas, and supports x509 certificate authentication and WS-Security for web services integrations. We test what an Integration System Security Group can actually reach, whether the certificate or credential behind it is scoped tightly, and what a RaaS report or public web service call returns beyond what the integration needs.

Authentication sits underneath both layers. Workday supports SAML and OpenID Connect for single sign-on, step-up authentication that demands a second factor for items marked critical, and multi-factor authentication through a TOTP authenticator, an email-to-SMS passcode or challenge questions, alongside trusted-device enrolment and IP allow and deny lists. A tenant that never fully migrated to SSO, a step-up rule that was never applied to the items it was meant to protect, or an MFA method left optional for an administrator account is a configuration gap, not a platform one, the same question we test on Dynamics 365 and Salesforce tenants.

SCOPE

What we pen test on a Workday tenant

WD-01

Security Group Assignment and Inheritance

A user’s Workday access comes from every security group assigned to their user-based or role-based membership, and those assignments combine rather than override each other. We test whether the combined effect of a user’s security groups still matches what your organisation intended, not just whether each group looks correct on its own.

WD-02

Business Process Configuration Security

Each business process in Workday, from a compensation change to a headcount request, carries its own configuration for who can initiate, approve or view a step. We test whether a business process configuration still matches your approval chain, including a step quietly reassigned to cover an absence and never returned.

WD-03

Contextual and Context-Free Security Rules

Workday’s own security documentation describes context-sensitive and context-free role-based security, where a rule can grant access based on a user’s organisational association rather than a flat role assignment. We test whether a context rule built for one organisation, cost centre or supervisory relationship actually stops at the boundary it was written for.

WD-04

Integration System Security Group and RaaS Access

System-to-system access in Workday runs through a public web service or a Reports-as-a-Service call, with the Integration System Security Group holding the actual scope of what that call can return. We test what an Integration System Security Group can reach, and whether a RaaS report built for one purpose now returns more than the integration consuming it needs.

WD-05

SOAP Web Service and Public API Surface

Workday documents its SOAP-based web services publicly, with a versioned directory of WSDL and XML schema definitions covering everything from absence management to benefits administration. We test which of those services a given integration credential can actually call, against what the integration was built to do.

WD-06

Certificate and WS-Security Credential Handling

Workday supports x509 certificate authentication and WS-Security for web services integrations, alongside PGP or a public and private key pair for file-based integrations. We test where those certificates and keys are stored, how they are rotated, and what a leaked one would actually let someone call.

WD-07

Single Sign-On Coverage (SAML and OpenID Connect)

Workday supports SAML and OpenID Connect for single sign-on, including a direct Azure Active Directory connector, as an alternative to its native login. We test whether every account in scope, including service and admin accounts, is actually covered by SSO rather than left on native login by exception.

WD-08

Step-Up Authentication and MFA Coverage

Step-up authentication is meant to demand a second factor for items Workday marks critical, and multi-factor authentication can run through a TOTP authenticator, an email-to-SMS passcode or challenge questions. We test whether step-up rules actually cover the items they were configured for, and whether MFA is enforced rather than optional for every administrator and integration account.

WD-09

Trusted Devices and IP Access Controls

Workday lets you enrol trusted devices, flag unrecognised device attempts, and restrict access with IP allow and deny lists enforced through authentication policies. We test whether a device or network location outside those lists is actually blocked, and whether the trusted-device list itself gets reviewed rather than left to grow.

WD-10

Audit Trail Export and Native Login Hygiene

Workday’s audit trail and user activity logs export through REST APIs into a customer SIEM, and native login passwords are stored only as a hash with a configurable session timeout and password rules. We test whether the SIEM export credential is scoped to read-only audit data, and whether native login accounts still meet your password and timeout policy where SSO has not replaced them.

OUR PROCESS

Workday Tenant and Integration Security Review: From Scope to Attestation

01

Scope and Tenant Access

We agree a sandbox or preview tenant, test accounts covering a couple of your security groups, and visibility of any Integration System Security Groups and certificates in scope.

02

Security Group and Business Process Mapping

We map security group assignment, business process configurations and the context rules layered on top of them across your tenant before manual testing starts.

03

Manual Testing

A CREST-certified tester manually tests security group boundaries, business process approvals, context rules, integration credentials and SSO or MFA coverage, chaining findings where they compound.

04

Attestation and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Workday pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Workday Tenant and Integration Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£4,180–£5,860
3 to 5 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£8,470–£11,320
7 to 9 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Workday Tenant and Integration Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Workday tenant?

We need test accounts covering a couple of your security groups and roles, ideally in a sandbox or preview tenant rather than production. If integrations are in scope we need visibility of the Integration System Security Groups involved, and for a specific business process we may ask for the configuration behind it rather than working it out from the outside.

Will testing touch our live data?

We test whichever tenant you nominate. Workday’s own tenant model separates sandbox, preview and production tenants, so testing against a non-production tenant avoids any risk to live worker or finance data, and if we test production we agree exclusions such as live payroll runs before testing starts.

How long does a Workday security review take?

A single Workday tenant sits in our 3-day single-tenant scope, with a report typically landing around 6 to 8 working days after kickoff. A tenant with many custom business processes, a large integration footprint or several connected systems can move into a wider scope.

Workday is a hosted SaaS platform we cannot install ourselves. Does that change what you test?

It changes where the risk sits rather than reducing it. There is no server or codebase of Workday’s own to review; your security groups, business process configurations, context rules and integration credentials are what your team configured, and that configuration is what we test in full.

What is out of scope for a single-tenant Workday review?

Workday’s own multitenant infrastructure, data centres and platform code are never in scope. A separate connected system, such as an identity provider or a downstream finance tool that only happens to integrate through the API, is scoped and quoted separately.

Do you need our source code?

We do not need Workday’s platform code, since that belongs to Workday. If you have custom integration code calling Workday’s APIs, a grey-box option where we review that code alongside testing is available for deeper coverage of specific findings.

Does Workday have a customer penetration-testing policy we need to follow?

Workday’s own trust documentation describes an internal programme where a third-party security firm tests Workday’s web and mobile application before every major release, and Workday shares its own penetration testing results and security advisories with customers through Workday Community. That covers Workday’s platform rather than a customer’s own tenant configuration, so we confirm Workday’s current requirements for testing your tenant during scoping, before testing starts.

Do you test our integrations and connected systems?

Yes. We test the Integration System Security Group scopes, certificate and WS-Security handling, and what a RaaS report or public web service call actually returns. A separate platform on the other end of an integration, such as Dynamics 365 or an identity provider, is tested and quoted as its own engagement.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Workday tenant

A Workday security group decides what a user or an integration can see and do. We test your security groups, business process configurations and integration access together. CREST-certified testers, fixed price from £4,180 for a 3-day single-tenant scope, quoted within 24 hours.