We upgraded our Infor OS environment to the latest patch last week, and now all our automated budget import jobs are failing with permission errors when trying to access the Data Lake. The jobs worked perfectly before the upgrade.
The error log shows:
ERROR: Access denied to object /budgets/imports/FY2025
Service account 'svc_budget_import' lacks READ permission
Data Lake security token validation failed
We haven’t changed any service account configurations or Data Lake security settings. The service account permissions look correct in the ION API Gateway, but something about the object-level security in Data Lake seems to have changed after the Infor OS upgrade. These imports are critical for our monthly budget consolidation process, and we’re now blocked from loading Q1 actuals.
Has anyone experienced similar Data Lake permission issues after upgrading Infor OS? What’s the proper way to restore service account access without compromising security?
The issue stems from how Infor OS changed the Data Lake security token validation mechanism. In earlier versions, service accounts inherited permissions through the ION API Gateway trust relationship, but the upgrade separated Data Lake access control into its own layer. You need to configure both layers properly now.
For the complete fix, here’s what worked for us after the same upgrade:
Add your service account to the ‘Data Lake Import Services’ security group in Infor OS Admin Console
Grant the security group explicit permissions on your Data Lake paths with inheritance enabled
Regenerate the service account credentials in ION API Gateway to refresh the security token
Update your import job configuration with the new credentials
The key is regenerating the credentials after adding the group membership - this ensures the security token includes the new Data Lake permissions. Here’s the permission grant we used:
# Data Lake Console > Security
Path: /budgets
Principal: Data Lake Import Services (group)
Permissions: READ, WRITE, LIST
Apply to children: YES
After applying these changes, restart your import jobs. The service account will now have proper object-level security through group membership rather than direct grants, which is cleaner for audit purposes and aligns with Infor’s new security model. This approach also automatically covers any other integration jobs using the same service account, as the group membership applies universally across Data Lake operations.
One additional note: if you’re running multiple tenants, you’ll need to configure this separately for each tenant’s Data Lake instance, as the security groups are tenant-scoped.
This draft is based on general Infor CloudSuite knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.
I’ve seen this exact issue. The Infor OS upgrade modified the Data Lake security model to enforce stricter object-level permissions. Your service account probably needs explicit grants on the bucket paths now, whereas before it inherited broader permissions. Check the Data Lake administration console under Security > Object Permissions and verify the service account has explicit READ/WRITE grants on your budget import paths.
Confirmed this resolves the Data Lake permission error — adding the service account to ‘Data Lake Import Services’ and enabling path inheritance fixed our budget import jobs immediately.
Thanks for the pointer. I checked the Data Lake console and you’re right - the service account only has tenant-level permissions but no explicit object grants. However, I’m not sure what the correct permission structure should be. Do I need to grant access to each individual folder, or can I grant recursive permissions at the /budgets level? Also, will this affect our other integration jobs that use the same service account?
You’ll want to grant recursive permissions at the parent folder level. In the Data Lake console, navigate to the /budgets path, select Security, and add your service account with READ and WRITE permissions, making sure to check the ‘Apply to child objects’ option. This approach is cleaner than individual folder grants and easier to maintain. The change should only affect Data Lake access - your ION API permissions remain separate and won’t be impacted.
Before you grant broad recursive permissions, I’d recommend reviewing what changed in the upgrade documentation. Infor OS upgrades sometimes introduce new security groups or modify the default permission inheritance model. You might need to add your service account to a specific Data Lake access group rather than granting direct object permissions. This is especially important if you’re in a regulated industry - direct object grants can create audit trail gaps. Check the release notes for your Infor OS version for any mentions of Data Lake security model changes.
Good point about the security groups. I found in the upgrade notes that they introduced a new ‘Data Lake Import Services’ group. However, I’m still unclear on the exact steps to properly configure this. Do I add the service account to this group, or do I need to reconfigure the ION API connection as well?