<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Grant Workspace Admin Permissions to an ID Using Parent Groups in Community Articles</title>
    <link>https://community.databricks.com/t5/community-articles/how-to-grant-workspace-admin-permissions-to-an-id-using-parent/m-p/103485#M345</link>
    <description>&lt;P&gt;Thanks for sharing this is great!&lt;/P&gt;</description>
    <pubDate>Sun, 29 Dec 2024 23:06:11 GMT</pubDate>
    <dc:creator>Alberto_Umana</dc:creator>
    <dc:date>2024-12-29T23:06:11Z</dc:date>
    <item>
      <title>How to Grant Workspace Admin Permissions to an ID Using Parent Groups</title>
      <link>https://community.databricks.com/t5/community-articles/how-to-grant-workspace-admin-permissions-to-an-id-using-parent/m-p/103408#M344</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;There are several ways to grant Workspace Admin permissions in Databricks. While this may seem straightforward, I found it a bit confusing when I started using Databricks, so I’d like to share my experience. This guide is aimed at beginners.&lt;/P&gt;&lt;HR /&gt;&lt;H2&gt;How Account Admins Can Grant Workspace Admin Permissions&lt;/H2&gt;&lt;P&gt;This is a simple process. From the account console, you can directly attach an ID (user, group, or service principal) to a workspace. By selecting "Admin" during the attachment, you can grant Workspace Admin permissions.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TakuyaOmi_4-1735401774100.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/13738iC133F69A5798141D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TakuyaOmi_4-1735401774100.png" alt="TakuyaOmi_4-1735401774100.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;HR /&gt;&lt;H2&gt;How Workspace Admins Can Grant Workspace Admin Permissions&lt;/H2&gt;&lt;P&gt;Compared to granting permissions via the account console, this method is slightly more complex as it varies depending on the ID type.&lt;/P&gt;&lt;H3&gt;Granting Permissions to a User&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;Log in to the Databricks workspace as a Workspace Admin.&lt;/LI&gt;&lt;LI&gt;Click on &lt;STRONG&gt;Settings&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Identity and Access&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Click &lt;STRONG&gt;Manage&lt;/STRONG&gt; next to &lt;STRONG&gt;Users&lt;/STRONG&gt;, and select the target user.&lt;/LI&gt;&lt;LI&gt;Go to the &lt;STRONG&gt;Entitlements&lt;/STRONG&gt; tab and toggle &lt;STRONG&gt;Admin access&lt;/STRONG&gt; to enable it.&lt;/LI&gt;&lt;/OL&gt;&lt;H3&gt;Granting Permissions to a Service Principal&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;Log in to the Databricks workspace as a Workspace Admin.&lt;/LI&gt;&lt;LI&gt;Click on &lt;STRONG&gt;Settings&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Identity and Access&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Click &lt;STRONG&gt;Manage&lt;/STRONG&gt; next to &lt;STRONG&gt;Groups&lt;/STRONG&gt;, and select the &lt;STRONG&gt;admins&lt;/STRONG&gt; system group.&lt;/LI&gt;&lt;LI&gt;Click &lt;STRONG&gt;Add members&lt;/STRONG&gt;, select the service principal, and click &lt;STRONG&gt;Confirm&lt;/STRONG&gt;.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;EM&gt;Note: This method can also be used for users.&lt;/EM&gt;&lt;/P&gt;&lt;H3&gt;Granting Permissions to a Group&lt;/H3&gt;&lt;P&gt;&lt;STRONG&gt;Currently, it is not possible to directly grant Workspace Admin permissions to a group from within the workspace.&lt;/STRONG&gt;&lt;BR /&gt;Even though adding a group to the &lt;STRONG&gt;admins&lt;/STRONG&gt; system group might seem like an option, this is not allowed. So, how can this be achieved? This is the main topic of this guide.&lt;/P&gt;&lt;HR /&gt;&lt;H2&gt;Understanding Parent Groups&lt;/H2&gt;&lt;P&gt;To grant admin permissions to a group, you can either:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Have an Account Admin assign permissions via the account console, or&lt;/LI&gt;&lt;LI&gt;Add the group to an existing group that already has Workspace Admin permissions.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The latter creates a parent-child relationship where the admin permissions of the parent group propagate to the child group. Let’s explore this mechanism.&lt;/P&gt;&lt;H3&gt;Parent Group Setup Example&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;admin_group&lt;/STRONG&gt;: A group directly attached to the workspace by an Account Admin, possessing Workspace Admin permissions.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;test_group&lt;/STRONG&gt;: A group that needs admin permissions, added to the workspace by a Workspace Admin.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;test_user&lt;/STRONG&gt;: A user in &lt;STRONG&gt;test_group&lt;/STRONG&gt; who does not initially have admin permissions.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TakuyaOmi_2-1735401216903.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/13736i54BAE2B8787B4223/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TakuyaOmi_2-1735401216903.png" alt="TakuyaOmi_2-1735401216903.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;By adding &lt;STRONG&gt;test_group&lt;/STRONG&gt; to &lt;STRONG&gt;admin_group&lt;/STRONG&gt;, a parent-child relationship is established. You can verify this under the &lt;STRONG&gt;Parent groups&lt;/STRONG&gt; tab in the group settings. Once set, the parent group’s permissions propagate to the child group.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TakuyaOmi_5-1735401862717.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/13739iACF0C4CA4E959051/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TakuyaOmi_5-1735401862717.png" alt="TakuyaOmi_5-1735401862717.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;H3&gt;Verifying Permissions&lt;/H3&gt;&lt;P&gt;After setting up the parent-child relationship:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The &lt;STRONG&gt;test_user&lt;/STRONG&gt;, who originally did not have admin permissions, will now have &lt;STRONG&gt;Admin access&lt;/STRONG&gt; enabled in the &lt;STRONG&gt;Entitlements&lt;/STRONG&gt; section.&lt;/LI&gt;&lt;LI&gt;Under the groups the user belongs to, you’ll see &lt;STRONG&gt;admin_group&lt;/STRONG&gt;, &lt;STRONG&gt;test_group&lt;/STRONG&gt;, and &lt;STRONG&gt;admins&lt;/STRONG&gt;, indicating Workspace Admin permissions.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TakuyaOmi_6-1735402496967.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/13740i50345D6A6DFE2BA1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TakuyaOmi_6-1735402496967.png" alt="TakuyaOmi_6-1735402496967.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;HR /&gt;&lt;H2&gt;Granting Workspace Admin Permissions to Users Added Through Groups&lt;/H2&gt;&lt;P&gt;Lastly, let’s address this scenario:&lt;/P&gt;&lt;P&gt;If a user is added to the workspace via a group, you cannot directly enable their admin permissions from the &lt;STRONG&gt;Entitlements&lt;/STRONG&gt; tab.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TakuyaOmi_0-1735401068418.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/13734i78E26211FF164614/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TakuyaOmi_0-1735401068418.png" alt="TakuyaOmi_0-1735401068418.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;"This user is added through a group. Manage its admin status from the parent group instead."&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Instead, you must add the user to a group that already has Workspace Admin permissions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;I hope this guide has been helpful in explaining how to grant Workspace Admin permissions to an ID using the parent group mechanism. Feel free to share your feedback or thoughts in the comments!&lt;/P&gt;</description>
      <pubDate>Sat, 28 Dec 2024 16:38:40 GMT</pubDate>
      <guid>https://community.databricks.com/t5/community-articles/how-to-grant-workspace-admin-permissions-to-an-id-using-parent/m-p/103408#M344</guid>
      <dc:creator>Takuya-Omi</dc:creator>
      <dc:date>2024-12-28T16:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to Grant Workspace Admin Permissions to an ID Using Parent Groups</title>
      <link>https://community.databricks.com/t5/community-articles/how-to-grant-workspace-admin-permissions-to-an-id-using-parent/m-p/103485#M345</link>
      <description>&lt;P&gt;Thanks for sharing this is great!&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2024 23:06:11 GMT</pubDate>
      <guid>https://community.databricks.com/t5/community-articles/how-to-grant-workspace-admin-permissions-to-an-id-using-parent/m-p/103485#M345</guid>
      <dc:creator>Alberto_Umana</dc:creator>
      <dc:date>2024-12-29T23:06:11Z</dc:date>
    </item>
  </channel>
</rss>

