Integrate with Workday using Basic Authentication
Integrate your Software Asset Management application with the Workday application using Basic authentication method to track your software subscriptions.
Configure permissions in Workday
To set up the Workday integration successfully, perform this procedure in Workday.
Before you begin
Role required: Users having roles such as Security Admin, Integration Admin, Integration Auditor, who can create Integration System Users and assign required security policies.
Procedure
Register an Integration System User.
Note: While filling out account information details, you must select the Do Not Allow UI Sessions check box.
Create a security group and assign it to the Integration System User.
In Action, navigate to Security Group > Maintain Domain Permissions for Security Group and provide the following permission:
Operation Domain Security Policy Functional Areas Get Only Worker Data: Public Worker Reports Staffing Get Only Worker Data: Current Staffing Information Staffing Get Only Worker Data: Workers Staffing Note: Confirm that the domain security policies are activated for the security group using the active pending security policy changes.
Result
The new credentials for this Integration System User would be used to configure the connection in the ServiceNow instance.
Create a Workday integration profile
Create a Workday integration profile to track software subscriptions and optimize licensing for your Workday applications.
Before you begin
Role required: admin, sam_admin, sam_integrator
Install the latest Workday HR spoke. For more information about the latest version, see the Spoke version section in Workday HR Spoke.
Important: You must select the Software Asset Management integration with Workday check box for this integration while installing optional features on the Application Manager page. For more information about choosing the required SaaS applications, see Request SaaS License Management.
About this task
If you’re using Software Asset Workspace, the option to create the Workday integration profile in Core UI is inactive.
Procedure
- Navigate to the integration profile.
| Interface | Action |
|---|---|
| Core UI |
|
| Software Asset Workspace |
|
- On the form, fill in the fields.
| Field | Description |
|---|---|
| Integration Profile | |
| Display name | Name of the integration profile. For example, `Workday integration`. |
| Authentication type | Type of authentication to access Workday APIs.- Basic Auth - OAuth 2.0 |
| Status | Status of the integration profile. - If you haven’t published the integration profile, this field is automatically set to Draft. - If you’ve already published the integration profile, this field is automatically set to Published. |
| Profile type | Type of integration profile. This field is automatically set to Workday Subscription. |
Review the required user roles or API permissions specified in the Vendor configuration field for each process to minimize security risks and optimize SaaS licenses.
Note: For more information, see Minimal user permissions table.
In the Download Subscription Subflow section, verify that the Subflow field is set to Workday Download Subscriptions. The Download subscriptions check box is selected by default and you can't clear it.
Select Save.
The Connection Setup section is displayed on the integration profile.
| Field | Description |
|---|---|
| Connection Details | - If the connection details exist, this field is already populated. - If the connection details don't exist, you must create them. |
| SOAP Username | User name of the Integration system user created while configuring permissions in Workday.Important: Include the tenant suffix in the username. For example, username@<tenant>. |
| SOAP Password | Password of the Integration system user created while configuring permissions in Workday. |
If connection details don't exist, create the connection details.
Interface Action Core UI In the Connection Details field, select the search icon (
Search icon.\).|
|**Software Asset Workspace**|Select the **Connection details** link.|
1. Select **New**.
2. On the form, fill in the fields.
|Field|Description|
|-----|-----------|
|Base URL|Workday SOAP API URL with the tenant name in the following format: `https://<workday_host_url>/ccx/service/<workday_tenant_name>`.|
|Version|The SOAP API version, for example, `v33.2`.|
|Webservice Type|Should be set to **SOAP**.|
3. Select **Submit**.
A record is created and added in the **Connection Details** field.
4. Review the connection details by selecting the new integration profile and selecting the lookup icon
Lookup icon in the **Connection details** field.
Create a SOAP user name and password when you don't have these credentials automatically populated.
Note: Only an admin role can create or update the SOAP user name and password.
| Interface | Action |
|---|---|
| Core UI |
|
| Software Asset Workspace | Select the SOAP username profile link. |
1. On the Soap Security Policy form, select the lookup icon
Lookup icon in the **WS-Security Username Profile** field.
2. Select **New**.
3. On the WS-Security Username Profiles \(Outbound\) form, fill in the name, user name, and password for the integration profile.
4. Select **Submit**.
Select Save.
Under the FSE worker calculation tab, activate the worker categories covered by your contract by setting the value of Active to true and entering the FSE percentage.
If worker categories are listed in your contract but not available in the FSE worker calculation tab, add a new worker category.
In the FSE worker calculation tab, select New.
On the form, fill in the fields.
Field Description Worker Category The worker category listed in your contract. FSE Percentage The FSE percentage for the worker category that you added. Full Service Equivalent (FSE) is the method by which the subscriptions are calculated. Integration profile The Workday integration profile that you created. Active Option to make the worker category active. Select Submit.
Define the mapping of the newly created worker category.
Select the Worker category tab and select New.
On the form, fill in the fields:
Field Description Worker Type The type of worker, either Employee or Contingent. Employee/Contingent worker type The type of Employee or Contingent worker. Time Type Indicates whether the worker is full-time or part-time. Worker Category The worker category that you created. Integration profile The Workday integration profile that you created. Active Option to make the mapping active. Select Submit.
Activate the list of modules that are defined in your contract.
Select the Modules tab.
Open the module record.
Set the Active field to True.
Select Save.
Verify that there is at least one active record in all the tabs for your contract: FSE worker calculation, Worker category, and Modules, before publishing the connection.
On the integration profile form, select Validate Connection to verify the connection and credential details of this integration.
After the connection is verified, select Publish.
In the Publish Confirmation dialog box, select OK.
What to do next
After the integration connects, your ServiceNow instance automatically creates software models, reclamation rules, and software subscriptions that are refreshed daily.
After creating an integration profile, view information about the profile in the Software Asset Workspace by navigating to License operations > User subscription > Direct integration profiles. You can select an integration profile to view the following related lists. If all of the following related lists aren't visible for an integration profile in the default view, you can select the custom integration view from the Details tab:
- Software Models
- Unrecognized Subscription Identifiers
- Scheduled Jobs
- Scheduled Job Results
- Software Subscriptions
- Subscription Identifier Exclusion Rule
- Subscription User Exclusion Rule
After creating an integration profile, you can define subscription exclusion rules to keep certain subscriptions from license cost calculations. For more information, see Subscription exclusions for SaaS and SSO applications.
If you want to set up multiple integration profiles with unique connections, create child aliases to manage different configurations and settings for each integration profile. For more information, see Create a child alias to set up multiple integration profiles.
Review all automatically generated reclamation rules to reclaim user subscriptions. For more information, see Review a software reclamation rule.
Create software entitlements for the automatically generated software models to track used software against owned software.
- For more information on creating software entitlements in the Software Asset Management Core UI, see Create entitlements in Software Asset Management Core UI.
- For more information on creating software entitlements in the Software Asset Workspace, see Create entitlements in workspace.
- For more information on creating software entitlements using the Software Asset Management Playbook, see Create entitlements using the guided walk-through.
Reconciliation also runs on your subscriptions as a scheduled job or on-demand. You can view your reconciliation results in the License Workbench (Software Asset Management classic application) or the License usage view (Software Asset Workspace). Use these results to determine your license compliance position and to remediate any non-compliance.
- For more information on running reconciliation in the Software Asset Management classic application, see Run software reconciliation in Software Asset Management classic.
- For more information on running reconciliation in the Software Asset Workspace, see Run software reconciliation in the workspace.