
828av (828av) asked a question.
Hi experts,
we would like to configure sso for workday and we have following requirements where we may need to enable sso
- For the future hires who haven't started their job in the company
- For the terminated users who may need to access only workday to update their address
We know that we can redirect the users to workday login url to authenticate the above users bypassing okta sso. But would like to know if there is any way to authenticate the users using okta sso in above scenarios

Hello,
In order for SAML to work the user will need to be active in Workday. Having them as future hire or terminated will make the SAML not function, due to the SAML assertion sending that they do not have access to it. Therefore for situations like this the best approach will be the option you are already doing.
Thank You,
Marius-Alexandru Voinescu
Technical Support Engineer
Okta Global Customer Care