Set Up Security for Data Lake Admin Console
See the Data Lake Setup in Workday section of Get Started with Workday Data Lake. This topic is part of a larger procedure.
Security:
Security Administration
and Security Configuration
domains in the System functional area.During the Implementation-only phase, access to the
Data Lake Admin Console
is not segmented by security domain. Users who have access to either domain can use all console capabilities. Domain separation will be enforced in a future release.Access to the
Data Lake Admin Console
report is controlled by two distinct Workday-delivered security domains in the Data Cloud functional area:
- Data Cloud: Manage Data Lake Application Configurations: Access the console only to configure which Workday objects and fields are made available in Data Lake.
- Data Cloud: Manage Data Lake Access Policies: Access the console only to manage Data Lake ISUs (Apache Polaris principals) and define configurable security on Data Lake objects.
Add users to security groups associated with these domains depending on their responsibilities.
- Create security groups for each domain and assign users to them (Example: SYS_Data_Lake_Admins). If you already have appropriate security groups, skip this step.
- Access theCreate Security Grouptask.
- From theType of Tenanted Security Groupprompt, selectUser-Based Security Group.
- Access theAssign Users to User-Based Security Grouptask to add users to your security groups.
- Update the domain security policies.
- Access theView Domaintask and select theData Cloud: Manage Data Lake Application Configurationsdomain from the prompt.
- From the related actions menu of the domain, selectDomain>Create Security Policy.
- Select theConfirmcheck box and clickOK.
- In theReport/Task Permissionsgrid, add rows and select your security groups from the prompt.
- Select theView and Modifycheck boxes for each security group, according to the level of access required.
- ClickOK, and thenDone.
- Repeat these steps for theData Cloud: Manage Data Lake Access Policiesdomain.
- Access theActivate Pending Security Policy Changestask.
- Add an appropriate comment and clickOK.
- Review the changes, check theConfirmcheck box, and clickOK.