5.3 Configuring and Using Batch Requests

Key Takeaways

  • Batch requests are created on Setup > Batch Requests from a comma-delimited file whose first column is the operation.

  • The operations are CreateIdentity, ModifyIdentity, CreateAccount, DeleteAccount, EnableAccount/DisableAccount, UnlockAccount, AddRole, RemoveRole, AddEntitlement, RemoveEntitlement, and ChangePassword.

  • Create Identity, Modify Identity, and Change Password requests must each be in a separate file; multiple roles or entitlements in one row are separated with a pipe (|).

  • Batch options control error tolerance, policy checking, scheduling, manual input (forms), work items, create-as-modify, and whether identity requests are generated.

  • The Lifecycle Manager Batch Request Approver option requires approval before a batch runs.

Last updated: September 2026

Configuring and Using Batch Requests

Objective 2.6 asks you to know how to configure and use batch requests. A batch request applies the same kind of change to many identities in one operation, driven by a comma-delimited (CSV) file. Common uses are loading a new department's accounts, removing a retired entitlement from hundreds of users, or unlocking accounts after an incident.

Access and Prerequisites

  • Go to Setup > Batch Requests. The user needs IdentityIQ administrative capabilities.
  • Batch requests are processed by a workflow of type Batch Provisioning and use the same provisioning engine as Lifecycle Manager.
  • A batch size limit may have been set during configuration.
  • On gear icon > Lifecycle Manager > Configure, the Batch Request Approver option requires an approval before batch requests are granted. This is useful when a single file can change thousands of identities.

The CSV Format

The first column is always operation. Target identities are usually given by identityName or by the account's nativeIdentity. Examples from the documentation:

OperationHeader columnsExample row
CreateIdentityoperation, name, location, email, departmentCreateIdentity, Alex Smith, Austin, asmith@adept.com, Accounting
ModifyIdentityoperation, identityName, location, email, departmentModifyIdentity, Bob Smith, Austin, bsmith@adept.com, Engineering
CreateAccountoperation, application, nativeIdentity or identityName, emailCreateAccount, AdminsApp, jsmith, jsmith@example.com
DeleteAccountoperation, application, nativeIdentity or identityName, emailDeleteAccount, AdminsApp, atoby, atoby@example.com
EnableAccount / DisableAccountoperation, application, nativeIdentity or identityNameEnableAccount, AdminsApp, abell
UnlockAccountoperation, application, nativeIdentity or identityNameUnlockAccount, AdminsApp, mjohnson
AddRole / RemoveRoleoperation, roles, identityNameAddRole, Benefits Manager, 222
AddEntitlement / RemoveEntitlementoperation, application, attributeName, attributeValue, nativeIdentity or identityNameAddEntitlement, Procurement_System, group, @Audit, id1
ChangePasswordoperation, application, password, nativeIdentity or identityNameChangePassword, Active_Directory, <password>, jsmith

File Rules

  • Separate files are required for Create Identity, Modify Identity, and Change Password. Other request types with similar columns can be mixed in one file.
  • Multiple roles or entitlements in one row are separated with a pipe, for example AddRole, Clerk|Approver, 222.
  • If order matters, such as creating identities before adding their roles, put each request type in its own file and run them one after another.
  • Dates must use MM/DD/YYYY, MM/DD/YYYY H:m:s, or MM/DD/YYYY H:m:s z (with a time zone).

Create Batch Request Options

OptionChoices and purpose
Choose batch fileThe prepared CSV
Error handlingContinue on errors, or stop after a set number of errors
Policy OptionInclude policy checking, or fail on any policy violation
Schedule to runRun immediately or at a later date and time
Manual inputSkip requests that need manual input, or create the provisioning forms they need
Work itemsSkip requests that would generate work items, or create the work items
Handle create identity as modify if identity existsTurns a CreateIdentity row into a modify when the identity already exists
Generate identity requestsCreates identity requests, visible under Manage > Access Requests, so each line can be tracked like an LCM request

Monitoring on the Batch Request Details Page

The Batch Requests page lists batches assigned to you or your workgroups and batches you requested. You can create, stop, or delete them there. Double-click a batch to open its details:

  • Header: File Name, Date Requested, Date Launched, Date Completed, Status, Total Records, Total Completed, Total Errors, Total Invalid.
  • Per-row Status: Running (it may be waiting on an approval or manual work item), Finished, Terminated (manually cancelled), or Invalid (click for details).
  • Per-row Result: Success, Failed (general validation error), Approval (waiting), ManualWorkItem (needed a manual work item, but the batch was set to skip them), PolicyViolation, ProvisioningForm (needed a form, but the batch was set to skip them), or Skipped.
  • Identity Request ID, shown only if Generate identity requests was selected.

Batch Requests Compared With Other Bulk Tools

IdentityIQ has several ways to change many identities, and exam options often mix them up:

  • Batch requests submit LCM-style requests from a CSV. Each row goes through approvals (if required), policy checks, forms, work items, and provisioning, just like a user's request.
  • Lifecycle events and Rapid Setup react automatically to changes found during identity refresh. Nobody prepares a file.
  • Role assignment rules grant roles automatically when identities match criteria during refresh (section 16.2).
  • Certification revocations remove access as the result of an access review decision (section 6.1).
  • Console or XML imports change objects directly and bypass the request process. They are not a substitute for governed provisioning.

Choose batch requests when a person has a known list of one-time changes that should still be governed and auditable.

Worked Scenario

A company retires the @Audit group in Procurement_System and must remove it from 1,200 users, with no forms and no approvals interrupting a weekend change window.

  1. Build a file of RemoveEntitlement, Procurement_System, group, @Audit, <id> rows.
  2. Set Error handling to stop after, for example, 25 errors, so a bad file does not run to completion.
  3. Set Manual input and Work items to skip, so rows that need people show up as ManualWorkItem or ProvisioningForm results instead of stalling.
  4. Select Generate identity requests for auditability, and schedule the batch for the start of the window.
  5. Review the details page afterward and re-run only the rows that failed.
Test Your Knowledge

A batch file must first create 50 identities and then add roles to them. What does the documentation recommend?

A

Put both operations in one file; IdentityIQ always processes CreateIdentity rows first.

B

Use the pipe delimiter to combine CreateIdentity and AddRole in each row.

C

Put each request type in its own file and run the files sequentially.

D

Enable Handle create identity as modify if identity exists.

Test Your Knowledge

A batch row's result shows ProvisioningForm. What does this mean?

A

The request needed a provisioning form, but the batch was configured not to create forms for manual input.

B

The row was waiting for a manager approval.

C

The provisioning form was completed successfully.

D

The row contained a date in an unsupported format.

Test Your Knowledge

Which set of batch request types must each be placed in a separate file?

A

AddRole, RemoveRole, and AddEntitlement

B

EnableAccount, DisableAccount, and UnlockAccount

C

Create Identity, Modify Identity, and Change Password

D

CreateAccount, DeleteAccount, and RemoveEntitlement

Test Your Knowledge

How do you add three entitlements to one identity in a single AddEntitlement row?

A

Repeat the attributeValue column three times.

B

Separate the values with the pipe (|) character.

C

Separate the values with semicolons inside double quotes.

D

It cannot be done; each entitlement needs its own file.

Sections you finish are checked off in the contents.