5.3 Configuring and Using Batch Requests
Key Takeaways
Batch requests are created on Setup > Batch Requests from a comma-delimited file whose first column is the operation.
The operations are CreateIdentity, ModifyIdentity, CreateAccount, DeleteAccount, EnableAccount/DisableAccount, UnlockAccount, AddRole, RemoveRole, AddEntitlement, RemoveEntitlement, and ChangePassword.
Create Identity, Modify Identity, and Change Password requests must each be in a separate file; multiple roles or entitlements in one row are separated with a pipe (|).
Batch options control error tolerance, policy checking, scheduling, manual input (forms), work items, create-as-modify, and whether identity requests are generated.
The Lifecycle Manager Batch Request Approver option requires approval before a batch runs.
Configuring and Using Batch Requests
Objective 2.6 asks you to know how to configure and use batch requests. A batch request applies the same kind of change to many identities in one operation, driven by a comma-delimited (CSV) file. Common uses are loading a new department's accounts, removing a retired entitlement from hundreds of users, or unlocking accounts after an incident.
Access and Prerequisites
- Go to Setup > Batch Requests. The user needs IdentityIQ administrative capabilities.
- Batch requests are processed by a workflow of type Batch Provisioning and use the same provisioning engine as Lifecycle Manager.
- A batch size limit may have been set during configuration.
- On gear icon > Lifecycle Manager > Configure, the Batch Request Approver option requires an approval before batch requests are granted. This is useful when a single file can change thousands of identities.
The CSV Format
The first column is always operation. Target identities are usually given by identityName or by the account's nativeIdentity. Examples from the documentation:
| Operation | Header columns | Example row |
|---|---|---|
CreateIdentity | operation, name, location, email, department | CreateIdentity, Alex Smith, Austin, asmith@adept.com, Accounting |
ModifyIdentity | operation, identityName, location, email, department | ModifyIdentity, Bob Smith, Austin, bsmith@adept.com, Engineering |
CreateAccount | operation, application, nativeIdentity or identityName, email | CreateAccount, AdminsApp, jsmith, jsmith@example.com |
DeleteAccount | operation, application, nativeIdentity or identityName, email | DeleteAccount, AdminsApp, atoby, atoby@example.com |
EnableAccount / DisableAccount | operation, application, nativeIdentity or identityName | EnableAccount, AdminsApp, abell |
UnlockAccount | operation, application, nativeIdentity or identityName | UnlockAccount, AdminsApp, mjohnson |
AddRole / RemoveRole | operation, roles, identityName | AddRole, Benefits Manager, 222 |
AddEntitlement / RemoveEntitlement | operation, application, attributeName, attributeValue, nativeIdentity or identityName | AddEntitlement, Procurement_System, group, @Audit, id1 |
ChangePassword | operation, application, password, nativeIdentity or identityName | ChangePassword, Active_Directory, <password>, jsmith |
File Rules
- Separate files are required for Create Identity, Modify Identity, and Change Password. Other request types with similar columns can be mixed in one file.
- Multiple roles or entitlements in one row are separated with a pipe, for example
AddRole, Clerk|Approver, 222. - If order matters, such as creating identities before adding their roles, put each request type in its own file and run them one after another.
- Dates must use
MM/DD/YYYY,MM/DD/YYYY H:m:s, orMM/DD/YYYY H:m:s z(with a time zone).
Create Batch Request Options
| Option | Choices and purpose |
|---|---|
| Choose batch file | The prepared CSV |
| Error handling | Continue on errors, or stop after a set number of errors |
| Policy Option | Include policy checking, or fail on any policy violation |
| Schedule to run | Run immediately or at a later date and time |
| Manual input | Skip requests that need manual input, or create the provisioning forms they need |
| Work items | Skip requests that would generate work items, or create the work items |
| Handle create identity as modify if identity exists | Turns a CreateIdentity row into a modify when the identity already exists |
| Generate identity requests | Creates identity requests, visible under Manage > Access Requests, so each line can be tracked like an LCM request |
Monitoring on the Batch Request Details Page
The Batch Requests page lists batches assigned to you or your workgroups and batches you requested. You can create, stop, or delete them there. Double-click a batch to open its details:
- Header: File Name, Date Requested, Date Launched, Date Completed, Status, Total Records, Total Completed, Total Errors, Total Invalid.
- Per-row Status: Running (it may be waiting on an approval or manual work item), Finished, Terminated (manually cancelled), or Invalid (click for details).
- Per-row Result: Success, Failed (general validation error), Approval (waiting), ManualWorkItem (needed a manual work item, but the batch was set to skip them), PolicyViolation, ProvisioningForm (needed a form, but the batch was set to skip them), or Skipped.
- Identity Request ID, shown only if Generate identity requests was selected.
Batch Requests Compared With Other Bulk Tools
IdentityIQ has several ways to change many identities, and exam options often mix them up:
- Batch requests submit LCM-style requests from a CSV. Each row goes through approvals (if required), policy checks, forms, work items, and provisioning, just like a user's request.
- Lifecycle events and Rapid Setup react automatically to changes found during identity refresh. Nobody prepares a file.
- Role assignment rules grant roles automatically when identities match criteria during refresh (section 16.2).
- Certification revocations remove access as the result of an access review decision (section 6.1).
- Console or XML imports change objects directly and bypass the request process. They are not a substitute for governed provisioning.
Choose batch requests when a person has a known list of one-time changes that should still be governed and auditable.
Worked Scenario
A company retires the @Audit group in Procurement_System and must remove it from 1,200 users, with no forms and no approvals interrupting a weekend change window.
- Build a file of
RemoveEntitlement, Procurement_System, group, @Audit, <id>rows. - Set Error handling to stop after, for example, 25 errors, so a bad file does not run to completion.
- Set Manual input and Work items to skip, so rows that need people show up as ManualWorkItem or ProvisioningForm results instead of stalling.
- Select Generate identity requests for auditability, and schedule the batch for the start of the window.
- Review the details page afterward and re-run only the rows that failed.
A batch file must first create 50 identities and then add roles to them. What does the documentation recommend?
Put both operations in one file; IdentityIQ always processes CreateIdentity rows first.
Use the pipe delimiter to combine CreateIdentity and AddRole in each row.
Put each request type in its own file and run the files sequentially.
Enable Handle create identity as modify if identity exists.
A batch row's result shows ProvisioningForm. What does this mean?
The request needed a provisioning form, but the batch was configured not to create forms for manual input.
The row was waiting for a manager approval.
The provisioning form was completed successfully.
The row contained a date in an unsupported format.
Which set of batch request types must each be placed in a separate file?
AddRole, RemoveRole, and AddEntitlement
EnableAccount, DisableAccount, and UnlockAccount
Create Identity, Modify Identity, and Change Password
CreateAccount, DeleteAccount, and RemoveEntitlement
How do you add three entitlements to one identity in a single AddEntitlement row?
Repeat the attributeValue column three times.
Separate the values with the pipe (|) character.
Separate the values with semicolons inside double quotes.
It cannot be done; each entitlement needs its own file.
Sections you finish are checked off in the contents.