Do you allow access to workday/HR application outside of InTune or another MDM tool? What is your policy for hourly employees accessing Workday ‘off hours’? How is this policy managed?

1.5k viewscircle icon1 Upvotecircle icon3 Comments
Sort by:
Information Security Director in Banking4 months ago

Hello Kara,

Recommend starting by defining what data is being accessed and what actions are being performed from these non-MDM governed devices. If the activity is low-risk—like entering hours, vacation, or sick time—that can often permit it with minimal friction. But if it involves viewing, uploading, or downloading sensitive HR data, treat that as a data loss risk and which require stronger controls before allowing access.

Policies could be managed through conditional access rules, risk-based authentication, and tight role-based access.

Strategically, I recommend:

- Classify HR tool/data transactions by risk, not just by app.
- Apply least privilege at the transaction level, where possible.
- Run periodic access reviews to catch drift in entitlements and behavior.

Lightbulb on1
IT Director in Manufacturing4 months ago

We use Dayforce, so I hope my feedback is relevant.

We allow access off-premises and at any time; however, access is restricted through the mobile app for Users to view and modify their HR documentation (such as statements, tax information, and benefits), and shift/hourly workers can use it for scheduling purposes only, Managers have a limited set of actions as well, including approving PTO, approving schedule changes, etc.

We also have SSO and MFA enabled for all users.

Lightbulb on2
CISO in Healthcare and Biotech4 months ago

We have been discussing this as well as some of our workers do not have laptops but will need access to the portal for their HR documentation. We are working out the best way for them to utilize MFA to still access it securely and will probably go that route if possible.

Lightbulb on1

Content you might like

Yes, BYOAI Copilot license use is allowed for all/most roles 25%

BYOAI Copilot license use is restricted to certain roles 46%

No, BYOAI Copilot license use is blocked 25%

N/A4%

View Results
Read More Comments

A unified global standard or regulations for IoT cybersecurity33%

Better end-user password hygiene54%

Consistent updates & patches applied by the end user46%

Closing the IoT security skills gap36%

Standardized data encryption on all devices29%

None of these2%

Other (please comment below)1%

View Results