Set Up Integration System Users for Data Lake
See the Data Lake Setup in Workday section of Get Started with Workday Data Lake. This topic is part of a larger procedure.
External data platforms connect to Workday Data Lake as integration system users (ISUs). Each ISU represents a non-person system account that a partner platform uses to authenticate to Data Lake.
We recommend creating one or more Workday ISU per external platform and access pattern.
- Create integration system security groups. If you already have appropriate security groups, skip this step.Security:Security Configurationdomain in the System functional area.
- Access theCreate Security Grouptask.
- From theType of Tenanted Security Groupprompt, selectIntegration System Security Group (Unconstrained).
- (Optional) If you already have ISUs for Data Lake, select them from theIntegration System Usersprompt.
- Create user provisioning groups for Data Lake.Security:Data Cloud: Manage Data Lake Access PoliciesandManage: Datalake User Provisioningdomains in the Data Cloud functional area.
- Access theManage User Provisioning for Workday Productsworklet. If you don’t have access to this task, see Set Up Access to User Provisioning.
- SelectSet Up Security Groups for User Provisioning.
- In the grid, add the security groups you created in step 1.
- ClickOK.
- On theManage User Provisioning for Workday Productspage, selectUser Provisioning Workspace.
- On theData Cloud: Data Laketile, selectConfigure.
- On theConfigurationtab that displays, select your security groups from theWorkday Security Groupsprompt and clickCreate Provisioning Group.
- SelectPreview and Enable Sync. For more information on provisioning group previews, see Manage Reports for User Provisioning.
- Once you generate a preview report and review any errors, select both the check box and theEnable Syncbutton to synchronize the provisioning group across Workday and Data Lake. The Sync label will change from Off to On once synchronization is complete.
- Create ISUs for Data Lake.We recommend one or more ISU per platform and authorization policy defined in Admin Console.Security:Integration Securitydomain in the Integration functional area.
- Access theCreate Integration System Usertask.
- Complete the task:OptionDescriptionUser NameEnter a unique ISU user name.New PasswordNew Password VerifySet a password.Require New Password at Next Sign InDon’t select the check box.Session Timeout MinutesKeep the value at zero to prevent the integration system user session from expiring.Do Not Allow UI SessionsSelect the check box.
- Repeat these steps for each ISU required for your use case.
- Add Data Lake ISUs to security groups.Security:Security Configurationdomain in the System functional area.
- Access theEdit Security Grouptask, and select a security group you created in step 1.
- ClickOK.
- Select your ISUs from theIntegration System Usersprompt.
- ClickOK.
The integration system users in your security groups are synchronized to Data Lake and can be used to authenticate from external clients.
Access to Data Lake tables is still controlled by access roles in the Admin Console. Configure those policies separately for each ISU or use case.
Register API Clients. Depending on the connector options in the data platform, either:
- Establish connection using a JWT Bearer Grant flow.
- Establish connection using a Refresh Token Grant flow.