SAML SSO session expires during asset depreciation calculation

We’re running scheduled asset depreciation calculations in Workday Studio (R1 2023) that process around 12,000 assets monthly. The batch job takes approximately 90 minutes to complete, but we’re seeing authentication failures about 65 minutes in. Our SAML tokens appear to be expiring mid-process, causing the job to fail with authentication errors.

The error shows:


SAML assertion expired at 2025-03-14T10:05:00Z
Authentication failed for batch process
Remaining assets: 4,200 unprocessed

We’ve checked our SAML token lifecycle settings and service account configuration, but the token refresh mechanism doesn’t seem to trigger for long-running batch processes. The issue specifically impacts our month-end close timeline since we need complete depreciation data. Has anyone dealt with SAML token expiration in batch authentication scenarios? We need to understand how to properly isolate batch process authentication from interactive SSO sessions.

Here’s the complete solution for your SAML token expiration issue in batch depreciation calculations:

1. SAML Token Lifecycle Management Your current problem stems from using SAML authentication for batch processes. SAML tokens are session-based with fixed lifetimes (typically 60 minutes) designed for interactive user sessions, not long-running batch jobs. SAML doesn’t support programmatic token refresh in background processes, which is why your 90-minute job fails at the 65-minute mark.

2. Service Account OAuth2 Configuration Migrate your Studio assembly to use OAuth2 with Integration System User credentials:


// Studio Integration Properties
auth.type=OAuth2
auth.grant_type=client_credentials
auth.client_id=STUDIO_DEPRECIATION_ISU
auth.token_endpoint=https://wd2-impl.workday.com/ccx/oauth2/token
auth.scope=Workday.Asset_Management

In Workday tenant, navigate to Edit Tenant Setup - Security > Register API Client for Integrations. Register your Studio integration with OAuth2 enabled and assign the ISU. Configure token lifetime to 8 hours (28800 seconds) for batch processes.

3. Batch Process Authentication Isolation Implement batch chunking with independent authentication contexts. Instead of one 12K asset batch, create 6 batches of 2K assets each. Each batch chunk authenticates independently with its own OAuth2 token lifecycle:


// Pseudocode - Batch chunking strategy:
1. Split asset list into chunks of 2000 records
2. For each chunk, obtain fresh OAuth2 token
3. Process chunk with isolated authentication context
4. Token expires only after chunk completion
5. Next chunk starts with new token request
// Prevents cascading failures across entire job

4. Token Refresh Mechanisms Workday Studio’s connector includes automatic token refresh for OAuth2 when configured correctly. Ensure you’re using Workday Connector version 34.0 or later (compatible with R1 2023). The connector monitors token expiration and automatically refreshes 5 minutes before expiry. However, implement explicit error handling:


try {
  processDepreciation(assetBatch);
} catch (AuthenticationException e) {
  if (e.isTokenExpired()) {
    refreshToken();
    retryProcess(assetBatch);
  }
}

5. ISU Permission Configuration Verify your ISU has these permissions:

  • Domain: Asset Management (View, Modify)
  • Business Process: Calculate Asset Depreciation
  • Report/Task: Asset Depreciation Reports
  • Integration Permissions: Get, Put for Asset objects

In Edit Integration System User, explicitly add OAuth2 scope mappings. The SAML permission model doesn’t automatically translate to OAuth2 scopes.

Implementation Steps:

  1. Register Studio integration as OAuth2 API client in Workday
  2. Update Studio assembly connection properties to use OAuth2 authentication
  3. Modify batch job to process assets in 2K chunks with independent auth contexts
  4. Update ISU permissions to include OAuth2-specific scopes
  5. Test with single chunk before deploying full batch
  6. Monitor token refresh in Studio logs to confirm automatic renewal

Expected Outcome: Each 2K asset chunk completes in ~15 minutes, well within token lifetime. OAuth2 tokens refresh automatically, eliminating mid-process authentication failures. Total job time remains ~90 minutes but with 6 independent authentication contexts providing fault isolation. Your month-end depreciation calculations will complete reliably without SAML session expiration issues.

The key architectural change is moving from interactive SAML sessions to programmatic OAuth2 service accounts, which are purpose-built for unattended batch authentication scenarios.


This draft is based on general Workday knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.

I’ve seen similar issues with SAML in batch contexts. The problem is that SAML tokens are designed for interactive sessions, not long-running background processes. Your batch job is inheriting the SAML session context, which has a fixed lifetime regardless of ongoing activity. Have you considered switching to OAuth2 service account tokens for your batch processes? Service accounts can be configured with longer token lifetimes and automatic refresh capabilities that are better suited for scheduled jobs.

Mike’s right about OAuth2 being the better approach. In Workday Studio, you should configure your batch integration to use Integration System User (ISU) credentials with OAuth2 instead of relying on SAML SSO. ISUs are specifically designed for system-to-system authentication and support token refresh. Check your integration security setup in Workday - you’ll need to register the Studio integration as an API client and configure OAuth2 grant type. The token lifetime can be extended up to 8 hours for batch processes.

Thanks for the direction. We do have an ISU configured, but I think our Studio assembly is still using SAML context from the initial deployment. When you say configure OAuth2 grant type, are you referring to client credentials flow? Also, should the token refresh happen automatically within the Studio runtime, or do we need to implement refresh logic in our custom code?

Yes, client credentials flow is what you want for unattended batch processes. The key is to separate your authentication layer from your business logic. In your Studio assembly properties, configure the ISU with OAuth2 credentials. The Workday connector handles token refresh automatically if configured correctly - you don’t need custom refresh logic. However, you should implement proper error handling to catch token expiration exceptions and retry with fresh tokens. I’d also recommend breaking your 12K asset batch into smaller chunks (maybe 2K per batch) with independent authentication contexts to minimize risk.

Tested this on Workday Studio 2023.28 with OAuth2 client credentials replacing our SAML tokens, and 4-hour depreciation batch jobs now complete without session interruption.

Adding to Chen’s point about chunking - this is actually a best practice for batch authentication isolation. Each chunk can have its own OAuth2 token lifecycle, so even if one batch encounters issues, others complete successfully. You also get better visibility into which asset ranges are failing. For your Studio assembly, make sure you’re using the latest Workday connector version compatible with R1 2023, as earlier versions had some token refresh quirks in long-running processes.

I went through this exact scenario last year. One thing to watch for: when you switch from SAML to OAuth2 for your batch process, make sure your ISU has the correct functional area permissions. We initially got 403 errors because our ISU was configured for SAML-based permissions which didn’t translate properly to OAuth2 scopes. You’ll need to explicitly grant the ISU access to Asset Management domain and the specific business processes for depreciation calculations.

Your batch job is inheriting the SAML session context, which has a fixed lifetime regardless of ongoing activity.