<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot remove users group &amp;quot;CAN_MANAGE&amp;quot; from /Shared in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/cannot-remove-users-group-quot-can-manage-quot-from-shared/m-p/113999#M3201</link>
    <description>&lt;P&gt;I have a Unity Catalog enabled workspace and I have full privileges including Account Admin.&amp;nbsp; I would like to be able to remove the "CAN_MANAGE" privilege from the "users" group.&amp;nbsp; According to the documentation, this should be possible.&amp;nbsp; According to the documentation in multiple places this should be posssible -&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/auth/default-permissions#users-group" target="_blank"&gt;https://learn.microsoft.com/en-us/azure/databricks/security/auth/default-permissions#users-group&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;There is no UI element I can see to do this, so I have been working through the Workspace Permissions API (I have made sure my API is also using an account admin level permission), still with no luck.&amp;nbsp; When I have been trying to remove permissions I either don't get a failure message and nothing happens or I get a "&lt;SPAN&gt;{"error_code":"INVALID_PARAMETER_VALUE","message":"Cannot modify permissions of directory [shared directory id]".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have been trying to come at this from a number of different angles with no luck.&amp;nbsp; I haven't come across any other posts or mentions of a similar issue or fix, only that as a workspace admin I should be able to do this.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also as a note, I have already set up separate Entra ID group that I will be using to provide access to the workspace and turn off the access granted by the default system users workspace group.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 30 Mar 2025 17:13:08 GMT</pubDate>
    <dc:creator>m_weirath</dc:creator>
    <dc:date>2025-03-30T17:13:08Z</dc:date>
    <item>
      <title>Cannot remove users group "CAN_MANAGE" from /Shared</title>
      <link>https://community.databricks.com/t5/administration-architecture/cannot-remove-users-group-quot-can-manage-quot-from-shared/m-p/113999#M3201</link>
      <description>&lt;P&gt;I have a Unity Catalog enabled workspace and I have full privileges including Account Admin.&amp;nbsp; I would like to be able to remove the "CAN_MANAGE" privilege from the "users" group.&amp;nbsp; According to the documentation, this should be possible.&amp;nbsp; According to the documentation in multiple places this should be posssible -&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/auth/default-permissions#users-group" target="_blank"&gt;https://learn.microsoft.com/en-us/azure/databricks/security/auth/default-permissions#users-group&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;There is no UI element I can see to do this, so I have been working through the Workspace Permissions API (I have made sure my API is also using an account admin level permission), still with no luck.&amp;nbsp; When I have been trying to remove permissions I either don't get a failure message and nothing happens or I get a "&lt;SPAN&gt;{"error_code":"INVALID_PARAMETER_VALUE","message":"Cannot modify permissions of directory [shared directory id]".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have been trying to come at this from a number of different angles with no luck.&amp;nbsp; I haven't come across any other posts or mentions of a similar issue or fix, only that as a workspace admin I should be able to do this.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also as a note, I have already set up separate Entra ID group that I will be using to provide access to the workspace and turn off the access granted by the default system users workspace group.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Mar 2025 17:13:08 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/cannot-remove-users-group-quot-can-manage-quot-from-shared/m-p/113999#M3201</guid>
      <dc:creator>m_weirath</dc:creator>
      <dc:date>2025-03-30T17:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot remove users group "CAN_MANAGE" from /Shared</title>
      <link>https://community.databricks.com/t5/administration-architecture/cannot-remove-users-group-quot-can-manage-quot-from-shared/m-p/117304#M3311</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Can you please share the entire stacktrace to the cause of&amp;nbsp;&lt;SPAN&gt;Cannot modify permissions of directory. Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 May 2025 06:54:12 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/cannot-remove-users-group-quot-can-manage-quot-from-shared/m-p/117304#M3311</guid>
      <dc:creator>NandiniN</dc:creator>
      <dc:date>2025-05-01T06:54:12Z</dc:date>
    </item>
  </channel>
</rss>

