<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Obtain access of Azure metastore storage account to configure Lifecycle management in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/obtain-access-of-azure-metastore-storage-account-to-configure/m-p/82281#M1530</link>
    <description>&lt;P&gt;Thanks for your response,&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/9"&gt;@Retired_mod&lt;/a&gt;. I already have Unity Catalog configured using an access connector and managed identity, these were automatically created by the Databricks workspace initialisation. The issue I'm facing is that [Azure Blob Lifecycle Management Policies](&lt;A href="https://learn.microsoft.com/en-us/azure/storage/blobs/lifecycle-management-policy-configure?tabs=azure-portal#create-or-manage-a-policy" target="_blank"&gt;https://learn.microsoft.com/en-us/azure/storage/blobs/lifecycle-management-policy-configure?tabs=azure-portal#create-or-manage-a-policy&lt;/A&gt;) require access to the storage container, but I am prevented from doing this by the Deny assignment.&lt;/P&gt;&lt;P&gt;I have tried&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;logging in as the managed identity that has access to the storage container, but the managed identity is also blocked by a Deny assignment.&lt;/LI&gt;&lt;LI&gt;creating another managed identity with access to the storage container, but the resource group is blocked by a Deny assignment&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I want to know if there is a way around these Deny assignments as an administrator.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Aug 2024 21:38:04 GMT</pubDate>
    <dc:creator>heathwinning</dc:creator>
    <dc:date>2024-08-07T21:38:04Z</dc:date>
    <item>
      <title>Obtain access of Azure metastore storage account to configure Lifecycle management</title>
      <link>https://community.databricks.com/t5/administration-architecture/obtain-access-of-azure-metastore-storage-account-to-configure/m-p/81561#M1454</link>
      <description>&lt;P&gt;I recently set up an Azure Databricks workspace with an automatically created metastore and metastore-level root storage within the &lt;STRONG&gt;metastore blob storage account&lt;/STRONG&gt;. All the catalogs, schemas, and tables/volumes have been created without a specified or external location, so the data all reside in the &lt;STRONG&gt;metastore blob storage account&lt;/STRONG&gt;&amp;nbsp;under the container named "unity-catalog-storage".&lt;/P&gt;&lt;P&gt;Because of the "&lt;SPAN&gt;System deny assignment created by Azure Databricks" I have no direct access to the&amp;nbsp;&lt;STRONG&gt;metastore blob storage account&lt;/STRONG&gt;, and therefore cannot set the access tier of some large raw files to Cool, nor can I create lifecycle management policies to do this automatically.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I regret not setting up a separate storage account for catalogs, but if possible I'd love to avoid risking migration of lots of data in lots of tables. Is there a way to achieve the access required to configure Lifecycle management?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2024 00:13:15 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/obtain-access-of-azure-metastore-storage-account-to-configure/m-p/81561#M1454</guid>
      <dc:creator>heathwinning</dc:creator>
      <dc:date>2024-08-02T00:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Obtain access of Azure metastore storage account to configure Lifecycle management</title>
      <link>https://community.databricks.com/t5/administration-architecture/obtain-access-of-azure-metastore-storage-account-to-configure/m-p/82281#M1530</link>
      <description>&lt;P&gt;Thanks for your response,&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/9"&gt;@Retired_mod&lt;/a&gt;. I already have Unity Catalog configured using an access connector and managed identity, these were automatically created by the Databricks workspace initialisation. The issue I'm facing is that [Azure Blob Lifecycle Management Policies](&lt;A href="https://learn.microsoft.com/en-us/azure/storage/blobs/lifecycle-management-policy-configure?tabs=azure-portal#create-or-manage-a-policy" target="_blank"&gt;https://learn.microsoft.com/en-us/azure/storage/blobs/lifecycle-management-policy-configure?tabs=azure-portal#create-or-manage-a-policy&lt;/A&gt;) require access to the storage container, but I am prevented from doing this by the Deny assignment.&lt;/P&gt;&lt;P&gt;I have tried&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;logging in as the managed identity that has access to the storage container, but the managed identity is also blocked by a Deny assignment.&lt;/LI&gt;&lt;LI&gt;creating another managed identity with access to the storage container, but the resource group is blocked by a Deny assignment&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I want to know if there is a way around these Deny assignments as an administrator.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 21:38:04 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/obtain-access-of-azure-metastore-storage-account-to-configure/m-p/82281#M1530</guid>
      <dc:creator>heathwinning</dc:creator>
      <dc:date>2024-08-07T21:38:04Z</dc:date>
    </item>
  </channel>
</rss>

