<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Consideration for OAUTH Secrets to use Service Principal to authenticate with  Databric in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/security-consideration-for-oauth-secrets-to-use-service/m-p/78796#M1376</link>
    <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/9"&gt;@Retired_mod&lt;/a&gt;&amp;nbsp;for the response. I do have follow up questions.&lt;/P&gt;&lt;P&gt;- What kind of encryption is used to store OAUTH secret?&lt;/P&gt;&lt;P&gt;-&amp;nbsp; Is there any way OAUTH can be generated by someone else who is not a manager of that SPN? We need this as a part of segregation of duty&lt;/P&gt;&lt;P&gt;- Can we use OAUTH secret for non M2M authentication?&amp;nbsp;&lt;/P&gt;&lt;P&gt;- What is the purpose of .databrickscfg file? Can we avoid using it as someone can store Secret in plain text?&lt;/P&gt;&lt;P&gt;- Can we create multiple OAUTH Secret for single SPN?&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jul 2024 12:43:50 GMT</pubDate>
    <dc:creator>VJ3</dc:creator>
    <dc:date>2024-07-15T12:43:50Z</dc:date>
    <item>
      <title>Security Consideration for OAUTH Secrets to use Service Principal to authenticate with  Databricks</title>
      <link>https://community.databricks.com/t5/administration-architecture/security-consideration-for-oauth-secrets-to-use-service/m-p/78227#M1362</link>
      <description>&lt;P&gt;What are the security consideration we need to keep in mind when we want to us OAUTH Secrets to use a Service Principal to access Azure Databricks when Identity federation is disabled and workspace is not yet on boarded on to Unity Catalog?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we consider OAUTH secret similar to Personal Access Token?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is time limit when OAUTH secrets expires?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do we get new OAUTH secrets?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we use Azure Key Vault to store the OAUTH secrets?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the workflow we use in OAUTH for authentication? Do we use Implicit grant workflow in OAUTH?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do we store secret in .databrickscfg?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Who has access to .databrickscfg?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do we ensure that OAUTH secret is stored safely and encrypted using AES256 and higher encryption?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://urldefense.com/v3/__https:/learn.microsoft.com/en-us/azure/databricks/dev-tools/auth/oauth-m2m__;!!PxNGlQK5RbneE5k!QbwPuvYiNA4wiu4Wxis4SjRh-o3EvQvrHriTKj6ytThjEpeJzfAoxq6gnRETsNMxLF88UPD7Y9JPaJ4pCea6kQ$" target="_blank"&gt;https://learn.microsoft.com/en-us/azure/databricks/dev-tools/auth/oauth-m2m&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;VJ&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 00:06:39 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/security-consideration-for-oauth-secrets-to-use-service/m-p/78227#M1362</guid>
      <dc:creator>VJ3</dc:creator>
      <dc:date>2024-07-11T00:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: Security Consideration for OAUTH Secrets to use Service Principal to authenticate with  Databric</title>
      <link>https://community.databricks.com/t5/administration-architecture/security-consideration-for-oauth-secrets-to-use-service/m-p/78796#M1376</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/9"&gt;@Retired_mod&lt;/a&gt;&amp;nbsp;for the response. I do have follow up questions.&lt;/P&gt;&lt;P&gt;- What kind of encryption is used to store OAUTH secret?&lt;/P&gt;&lt;P&gt;-&amp;nbsp; Is there any way OAUTH can be generated by someone else who is not a manager of that SPN? We need this as a part of segregation of duty&lt;/P&gt;&lt;P&gt;- Can we use OAUTH secret for non M2M authentication?&amp;nbsp;&lt;/P&gt;&lt;P&gt;- What is the purpose of .databrickscfg file? Can we avoid using it as someone can store Secret in plain text?&lt;/P&gt;&lt;P&gt;- Can we create multiple OAUTH Secret for single SPN?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 12:43:50 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/security-consideration-for-oauth-secrets-to-use-service/m-p/78796#M1376</guid>
      <dc:creator>VJ3</dc:creator>
      <dc:date>2024-07-15T12:43:50Z</dc:date>
    </item>
    <item>
      <title>Re: Security Consideration for OAUTH Secrets to use Service Principal to authenticate with  Databric</title>
      <link>https://community.databricks.com/t5/administration-architecture/security-consideration-for-oauth-secrets-to-use-service/m-p/102382#M2523</link>
      <description>&lt;P&gt;Any updates on this?&lt;/P&gt;&lt;P&gt;Also struggling with the OAuth security considerations. Specifically with updating the OAuth Secrets.&lt;/P&gt;&lt;P&gt;Currently using a SP to access Databricks workspace for DevOps purposes through the Databricks CLI.&lt;/P&gt;&lt;P&gt;I have the SP set up to renew it's ClientSecret every 2 months and update in Azure KV. I want to do something similar with Databricks OAuth Client Secret. Now I have it manually created and copy pasted to KeyVault. But I want to periodically update the OAuath Secret due to strict security requirements.&lt;/P&gt;&lt;P&gt;I see some methods on how to renew your own Databricks OAuth Token. But I see no information on renewing the Oauth Secret (programatically). Or on how to prevent storing the Secret as plain text in the&amp;nbsp;&lt;SPAN&gt;.databrickscfg&amp;nbsp;file.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 13:28:32 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/security-consideration-for-oauth-secrets-to-use-service/m-p/102382#M2523</guid>
      <dc:creator>Rob_Lemmens</dc:creator>
      <dc:date>2024-12-17T13:28:32Z</dc:date>
    </item>
  </channel>
</rss>

