Workday new mobile device added to user account

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detect when a user registers an Android or iOS device within their Workday account for mobile access. Generates a higher-priority signal when registration occurs from a client IP address that threat intelligence classifies as malicious.

Technical Context

Workday mobile enrollment ties a physical device to an employee identity. Attackers who obtain credentials may add a device they control to receive push notifications, approve actions, or maintain persistent access after password rotation.

Triage and Response

  1. Ask the user through an established channel whether they enrolled a new phone or tablet for Workday around the event time.
  2. Review client IP, geolocation, and user agent; compare to the user’s typical mobile carrier and home or office locations.
  3. Check for correlated high-risk events (password reset, MFA change, contact or payroll updates, unusual report activity) in the same session or day.
  4. Declare an incident if the new device enrollment cannot be confirmed as legitimate.