<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable 'Allow trusted Microsoft services to bypass this firewall' for Azure Key Vault in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/disable-allow-trusted-microsoft-services-to-bypass-this-firewall/m-p/106451#M2808</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/142274"&gt;@rdadhichi&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Have you set "Allow access from" to "Private endpoint and selected networks" on the firewall?&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jan 2025 12:58:49 GMT</pubDate>
    <dc:creator>Alberto_Umana</dc:creator>
    <dc:date>2025-01-21T12:58:49Z</dc:date>
    <item>
      <title>Disable 'Allow trusted Microsoft services to bypass this firewall' for Azure Key Vault</title>
      <link>https://community.databricks.com/t5/administration-architecture/disable-allow-trusted-microsoft-services-to-bypass-this-firewall/m-p/106446#M2805</link>
      <description>&lt;P&gt;Currently even when using vnet injected Databricks workspace, we are unable to fetch the secrets from AKV if the '&lt;STRONG&gt;Allow trusted Microsoft services to bypass this firewall' is disabled.&lt;BR /&gt;&lt;/STRONG&gt;The secret is used a AKV backed secret scope and the key vault is private (public access disabled).&lt;BR /&gt;&lt;BR /&gt;Our security requirement is to disable this and use private endpoints only. We have tried a few things like :&lt;BR /&gt;1. NCC configuration to create a private endpoint from databricks to key vault&lt;/P&gt;&lt;P&gt;2. Verifying the dns entries and nslookup from the notebook gives the correct private ip of the kv&lt;BR /&gt;&lt;BR /&gt;Is this a limitation as we could not find any documentation that would help us disabling this without breaking things.&lt;BR /&gt;Official troubleshooting doc also asks to keep this enabled&lt;BR /&gt;&lt;A href="https://kb.databricks.com/security/troubleshoot-key-vault-access#:~:text=Inspect%20the%20firewall%20configuration%20on%20the%20key%20vault&amp;amp;text=Click%20Networking.,firewall%3F%20is%20set%20to%20Yes." target="_self"&gt;Troubleshooting 403&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 12:42:52 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/disable-allow-trusted-microsoft-services-to-bypass-this-firewall/m-p/106446#M2805</guid>
      <dc:creator>rdadhichi</dc:creator>
      <dc:date>2025-01-21T12:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: Disable 'Allow trusted Microsoft services to bypass this firewall' for Azure Key Vault</title>
      <link>https://community.databricks.com/t5/administration-architecture/disable-allow-trusted-microsoft-services-to-bypass-this-firewall/m-p/106451#M2808</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/142274"&gt;@rdadhichi&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Have you set "Allow access from" to "Private endpoint and selected networks" on the firewall?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 12:58:49 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/disable-allow-trusted-microsoft-services-to-bypass-this-firewall/m-p/106451#M2808</guid>
      <dc:creator>Alberto_Umana</dc:creator>
      <dc:date>2025-01-21T12:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: Disable 'Allow trusted Microsoft services to bypass this firewall' for Azure Key Vault</title>
      <link>https://community.databricks.com/t5/administration-architecture/disable-allow-trusted-microsoft-services-to-bypass-this-firewall/m-p/106500#M2810</link>
      <description>&lt;P&gt;There are no such settings.&lt;BR /&gt;&lt;BR /&gt;We have Disabled Public access .&amp;nbsp;&lt;BR /&gt;We have Private endpoints created for the KV in the same vnet and can do a successfull nslookup from a notebook in our workspace&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Our requirement is to dsable the exception : ' Allow Trusted services....'&lt;BR /&gt;&lt;BR /&gt;Please let me know if this is possible or not&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rdadhichi_0-1737468820054.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/14246i4F5664AB67DF5990/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rdadhichi_0-1737468820054.png" alt="rdadhichi_0-1737468820054.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 14:16:10 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/disable-allow-trusted-microsoft-services-to-bypass-this-firewall/m-p/106500#M2810</guid>
      <dc:creator>rdadhichi</dc:creator>
      <dc:date>2025-01-21T14:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: Disable 'Allow trusted Microsoft services to bypass this firewall' for Azure Key Vault</title>
      <link>https://community.databricks.com/t5/administration-architecture/disable-allow-trusted-microsoft-services-to-bypass-this-firewall/m-p/115657#M3264</link>
      <description>&lt;P&gt;Any update on this? Is it possible to disable the&amp;nbsp;&lt;SPAN&gt;' Allow Trusted services....' rule if you are using a private endpoint or whitelist certain IPs? Or is it required no matter what?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 12:52:21 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/disable-allow-trusted-microsoft-services-to-bypass-this-firewall/m-p/115657#M3264</guid>
      <dc:creator>bauerbrett1</dc:creator>
      <dc:date>2025-04-16T12:52:21Z</dc:date>
    </item>
  </channel>
</rss>

