Skip to main content
Administrator Guide
Last Updated: 2026-08-07
Set Up Integration System Users for Data Lake

Set Up Integration System Users for Data Lake

See the Data Lake Setup in Workday section of Get Started with Workday Data Lake. This topic is part of a larger procedure.
External data platforms connect to Workday Data Lake as integration system users (ISUs). Each ISU represents a non-person system account that a partner platform uses to authenticate to Data Lake.
We recommend creating one or more Workday ISU per external platform and access pattern.
  1. Create integration system security groups. If you already have appropriate security groups, skip this step.
    Security:
    Security Configuration
    domain in the System functional area.
    1. Access the
      Create Security Group
      task.
    2. From the
      Type of Tenanted Security Group
      prompt, select
      Integration System Security Group (Unconstrained)
      .
    3. (Optional) If you already have ISUs for Data Lake, select them from the
      Integration System Users
      prompt.
  2. Create user provisioning groups for Data Lake.
    Security:
    Data Cloud: Manage Data Lake Access Policies
    and
    Manage: Datalake User Provisioning
    domains in the Data Cloud functional area.
    1. Access the
      Manage User Provisioning for Workday Products
      worklet. If you don’t have access to this task, see Set Up Access to User Provisioning.
    2. Select
      Set Up Security Groups for User Provisioning
      .
    3. In the grid, add the security groups you created in step 1.
    4. Click
      OK
      .
    5. On the
      Manage User Provisioning for Workday Products
      page, select
      User Provisioning Workspace
      .
    6. On the
      Data Cloud: Data Lake
      tile, select
      Configure
      .
    7. On the
      Configuration
      tab that displays, select your security groups from the
      Workday Security Groups
      prompt and click
      Create Provisioning Group
      .
    8. Select
      Preview and Enable Sync
      . For more information on provisioning group previews, see Manage Reports for User Provisioning.
    9. Once you generate a preview report and review any errors, select both the check box and the
      Enable Sync
      button to synchronize the provisioning group across Workday and Data Lake. The Sync label will change from Off to On once synchronization is complete.
  3. Create ISUs for Data Lake.
    We recommend one or more ISU per platform and authorization policy defined in Admin Console.
    Security:
    Integration Security
    domain in the Integration functional area.
    1. Access the
      Create Integration System User
      task.
    2. Complete the task:
      Option
      Description
      User Name
      Enter a unique ISU user name.
      New Password
      New Password Verify
      Set a password.
      Require New Password at Next Sign In
      Don’t select the check box.
      Session Timeout Minutes
      Keep the value at zero to prevent the integration system user session from expiring.
      Do Not Allow UI Sessions
      Select the check box.
    3. Repeat these steps for each ISU required for your use case.
  4. Add Data Lake ISUs to security groups.
    Security:
    Security Configuration
    domain in the System functional area.
    1. Access the
      Edit Security Group
      task, and select a security group you created in step 1.
    2. Click
      OK
      .
    3. Select your ISUs from the
      Integration System Users
      prompt.
    4. Click
      OK
      .
The integration system users in your security groups are synchronized to Data Lake and can be used to authenticate from external clients.
Access to Data Lake tables is still controlled by access roles in the Admin Console. Configure those policies separately for each ISU or use case.
Register API Clients. Depending on the connector options in the data platform, either: