Body
Summary
This article provides detailed information for Help Desk staff on how to support local Workday account holders, including former employees, retirees, and other non-employee users. It covers the process of account access, password reset, and troubleshooting issues related to local Workday accounts.
When an employee leaves USNH, their Workday account is converted from a USNH account to a personal account local to Workday. This means that the user will no longer use USNH's Microsoft password processes (Single Sign-On). Instead, they will use the built-in local Workday password reset process. This process uses the Home Contact Email in Workday, so it's important that employees review/maintain their email information before their employment ends.
Other non-employees may be granted local Workday account access so they can sign in to complete forms or pay invoices, etc.
Local Workday Account Access
Account Conversion for Former Employees
When an employee leaves USNH, their Workday account is converted from a USNH account to a personal account local to Workday. This means that the user will no longer use USNH's Microsoft password processes (SSO / Single Sign-On). Instead, they will use the built-in local Workday password reset process.
This process uses the Home Contact Email in Workday, so it's important that employees review/maintain their email information before their employment ends.
Account Claiming Emails
New local Workday account holders will be sent two emails to their Home Contact Email (personal email address) in Workday. For retiring or departing employees these emails are sent on the last day of employment.
The emails will include the following information:
Email #1
- Username Confirmation:
- This email confirms their local Workday username.
- The username@usnh.edu (e.g. jbd2519@usnh.edu) will continue to be used to log into Workday.
- Login URL:
Email #2
- Temporary Password:
- This email contains a temporary password and instructions to be used when logging into the local Workday login page for the first-time.
- After using the temporary password, the user must reset their local Workday password.
Multi-Factor Authentication (MFA)
Local Workday accounts require Multi-Factor Authentication (MFA), but they MFA through a different process using authenticator apps, email codes, or SMS codes, separate from USNH's Azure Entra SSO MFA process.
Self-Service Password Reset for Local Workday Accounts
The local Workday login page has a "Forgot Password?" link below the Sign In box.
Click for full-size image
Former employees or other local Workday account holders can reset their local Workday password using this “Forgot Password?” link on the local Workday login page.
This triggers an email with a password reset link sent to the personal email address on file in Workday.
Troubleshooting
Local Workday account holder can’t access their "personal" email
If the user no longer has access to the personal email on file (e.g. the "personal" email is actually a USNH email account), then the HR Operations team can update the person’s Workday contact information. But the Help Desk must fully verify the person’s identity before that request goes to HR for updates.
Step 1 – Verify the requestor’s identity following standard procedures. See related articles:
Step 2 – Open a ticket with these details as well as any other relevant information:
- Document the ID verification steps and outcome.
- Document the old (not working) email address as seen in IIQ in the Workday data source.
- Provide the new, desired email address.
- Include a good call back number.
Step 3 – Assign the ticket to TDx Group: HR – HRIS. Collegis should escalate to USNH after ID verification.
Step 4 – Either HRIS or Help Desk will notify the customer when the new personal email address is in place.
Step 5 – Once the new personal email account is in place, then the former employee or local Workday account holder can use the "Forgot Password?" option to reset their local Workday account password.
Additional Information
Workday Authentication Policy
Workday uses a set of rules to determine who is required to login in what ways, from what networks, and with what restrictions. It is processed in a top-down order, stopping at the first matching rule. This does mean that in some cases a user with multiple rules is required to login in ways because of one of their roles that matches first. For example, a former employee who is taking classes is in both the All External Students group and the All Terminees group. Since All External Students is first, the user must use SSO authentication and not the local username and password option that would otherwise be used for former workers.
Here's a simplified version of the authentication policy as of January 2026 for reference:
| Authentication Rule Name |
Security Group |
Allowed Authentication Types |
Notes |
| Implementers Rule |
Implementers |
All |
Only for consultants working on implementation of Workday |
| Security Admin Rule |
Security Administrator |
All |
"Backdoor" access for ET&S security admin team in case SSO fails |
| Retiree |
All Retirees |
Mobile PIN/Biometric
SAML
User Name Password |
Allows both SSO and local username/password access to support Emeriti |
| General Access Rule |
All Contingent Workers
All Employees
All External Students
All Pre-Contingent Workers
All Pre-Employees |
Mobile PIN/Biometric
SAML |
Normal SSO online authentication for active students, employees, and contractors |
| Terminations Rule |
All Terminees |
User Name Password |
Former employees with no other roles use local username/password only |
Types of Local Accounts
Local Workday accounts are used for various populations who need specific, limited access to execute certain business functions within Workday. These include:
|
Population
|
Business functions or roles in Workday
|
|
Job Applicants
|
Submit application materials for job openings.
Interact with recruiters during the recruiting, interviewing, and hiring process.
|
|
Customers (Non-students)
|
Receive invoices for goods and services purchased from USNH not related to academic instruction.
See status of invoices.
Connect to payment services.
|
|
External Committee Members
|
Participate in committee activities.
Review applicants in a search process.
Submit expense reports.
|
|
Extended Enterprise Learners
|
Access required training materials as a volunteer or other non-student/non-employee role required for involvement in a USNH program.
|
|
Terminated Employees / Retirees
|
Access to pay history and tax documents (W-2, etc) for a period following termination.
|
Password Rules
USNH Workday has local account password rules configured to align with USNH's password policy:
|
Item
|
Setting
|
|
Minimum Password Length
|
15 characters
|
|
Password Must Contain…
|
No specific character requirements
|
|
Days Before Password Can Be Reused
|
1825 days (5 years)
|
|
Maximum Password Age in Days
|
365 days (annual change)
|
|
Number of Passwords Before Reuse
|
5 passwords
|
|
Failed Sign-On Attempts Before Lockout
|
5 sign-on attempts
|
|
Failed Password Reset Attempts
|
3 password reset attempts
|
|
Lockout Minutes
|
15 minutes
|
Further Readings
local Workday login page - URL: https://wd5.myworkday.com/usnh/login.flex?redirect=n
Access to Workday Post Termination
Accounts: Account Verification Process
IIQ: Verifying Identity with ID Proofing (ETS Internal)
Need additional help?
If you have questions or need additional help with these topics, please reach out to your Help Desk Team Lead or supervisor for assistance.