Workday employee contact information changed

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detect when a user changes employee contact information in Workday. Generates a higher-priority signal when the change originates from a client IP address that threat intelligence classifies as suspicious.

Technical Context

Workday stores phone numbers, email addresses, and other contact details used for authentication notices, password recovery, and HR communications. Unauthorized updates to contact fields can be related to account takeover.

This detection groups activity by the acting user and evaluates Change Contact Information audit events.

Triage and Response

  1. Review the client IP, geolocation, and user agent; correlate them with other Workday or IdP sessions for the same user in the same window.
  2. Verify with the user that they initiated the contact information change.
  3. Inspect related Workday activity (bank account updates, report exports, or other actions) for the impacted employee.
  4. Coordinate with your HR team if you need technical assistance.
  5. If suspicious activity is confirmed, consider freezing the affected accounts and declaring an incident.