Skip to main content
Administrator Guide
Last Updated: 2026-08-07
Set Up Security for Data Lake Admin Console

Set Up Security for Data Lake Admin Console

See the Data Lake Setup in Workday section of Get Started with Workday Data Lake. This topic is part of a larger procedure.
Security:
Security Administration
and
Security Configuration
domains in the System functional area.
During the Implementation-only phase, access to the
Data Lake Admin Console
is not segmented by security domain. Users who have access to either domain can use all console capabilities. Domain separation will be enforced in a future release.
Access to the
Data Lake Admin Console
report is controlled by two distinct Workday-delivered security domains in the Data Cloud functional area:
  • Data Cloud: Manage Data Lake Application Configurations
    : Access the console only to configure which Workday objects and fields are made available in Data Lake.
  • Data Cloud: Manage Data Lake Access Policies
    : Access the console only to manage Data Lake ISUs (Apache Polaris principals) and define configurable security on Data Lake objects.
Add users to security groups associated with these domains depending on their responsibilities.
  1. Create security groups for each domain and assign users to them (Example: SYS_Data_Lake_Admins). If you already have appropriate security groups, skip this step.
    1. Access the
      Create Security Group
      task.
    2. From the
      Type of Tenanted Security Group
      prompt, select
      User-Based Security Group
      .
    3. Access the
      Assign Users to User-Based Security Group
      task to add users to your security groups.
  2. Update the domain security policies.
    1. Access the
      View Domain
      task and select the
      Data Cloud: Manage Data Lake Application Configurations
      domain from the prompt.
    2. From the related actions menu of the domain, select
      Domain
      >
      Create Security Policy
      .
    3. Select the
      Confirm
      check box and click
      OK
      .
    4. In the
      Report/Task Permissions
      grid, add rows and select your security groups from the prompt.
    5. Select the
      View and Modify
      check boxes for each security group, according to the level of access required.
    6. Click
      OK
      , and then
      Done
      .
    7. Repeat these steps for the
      Data Cloud: Manage Data Lake Access Policies
      domain.
  3. Access the
    Activate Pending Security Policy Changes
    task.
    1. Add an appropriate comment and click
      OK
      .
    2. Review the changes, check the
      Confirm
      check box, and click
      OK
      .