<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unexpected Behavior with Azure Databricks and Entra ID SCIM Integration in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/unexpected-behavior-with-azure-databricks-and-entra-id-scim/m-p/115832#M3270</link>
    <description>&lt;P class=""&gt;Hi everyone,&lt;/P&gt;&lt;P class=""&gt;I'm currently running some tests for a company that uses Entra ID as the backbone of its authentication system. Every employee with a corporate email address is mapped within the organization's Entra ID.&lt;/P&gt;&lt;P class=""&gt;Our company's Azure Databricks is connected to Entra ID via SCIM. However, we've observed some unexpected behavior: a workspace admin in Azure Databricks is able to invite into their workspace any user that exists in the corporate Entra ID—even if that user has never accessed the cloud environment before.&lt;/P&gt;&lt;P class=""&gt;How is this possible? Is there a way to mitigate this?&lt;/P&gt;&lt;P class=""&gt;Ideally, I would expect that only users who have been granted access to the corporate cloud environments should be able to access Databricks.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Apr 2025 10:07:45 GMT</pubDate>
    <dc:creator>antonionuzzo</dc:creator>
    <dc:date>2025-04-18T10:07:45Z</dc:date>
    <item>
      <title>Unexpected Behavior with Azure Databricks and Entra ID SCIM Integration</title>
      <link>https://community.databricks.com/t5/administration-architecture/unexpected-behavior-with-azure-databricks-and-entra-id-scim/m-p/115832#M3270</link>
      <description>&lt;P class=""&gt;Hi everyone,&lt;/P&gt;&lt;P class=""&gt;I'm currently running some tests for a company that uses Entra ID as the backbone of its authentication system. Every employee with a corporate email address is mapped within the organization's Entra ID.&lt;/P&gt;&lt;P class=""&gt;Our company's Azure Databricks is connected to Entra ID via SCIM. However, we've observed some unexpected behavior: a workspace admin in Azure Databricks is able to invite into their workspace any user that exists in the corporate Entra ID—even if that user has never accessed the cloud environment before.&lt;/P&gt;&lt;P class=""&gt;How is this possible? Is there a way to mitigate this?&lt;/P&gt;&lt;P class=""&gt;Ideally, I would expect that only users who have been granted access to the corporate cloud environments should be able to access Databricks.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 10:07:45 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unexpected-behavior-with-azure-databricks-and-entra-id-scim/m-p/115832#M3270</guid>
      <dc:creator>antonionuzzo</dc:creator>
      <dc:date>2025-04-18T10:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected Behavior with Azure Databricks and Entra ID SCIM Integration</title>
      <link>https://community.databricks.com/t5/administration-architecture/unexpected-behavior-with-azure-databricks-and-entra-id-scim/m-p/115919#M3275</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/157648"&gt;@antonionuzzo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This behavior is occurring because Azure Databricks allows workspace administrators to invite users from their organization's Entra ID directory into the Databricks workspace. This capability functions independently of whether the user has explicitly been granted access to a corporate cloud environment. When a SCIM integration is established with Entra ID, it synchronizes user identities to Databricks, enabling these users to be invited.&lt;/P&gt;
&lt;P&gt;To mitigate this&amp;nbsp;Azure Databricks provides a setting to control the ability of workspace administrators to invite users. You can manage this through the workspace's configuration settings using the &lt;CODE&gt;restrict_workspace_admins&lt;/CODE&gt; feature. This limits workspace administrators, allowing only specified users or groups with predetermined access permissions to join the workspace&lt;/P&gt;</description>
      <pubDate>Sat, 19 Apr 2025 21:24:46 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unexpected-behavior-with-azure-databricks-and-entra-id-scim/m-p/115919#M3275</guid>
      <dc:creator>Alberto_Umana</dc:creator>
      <dc:date>2025-04-19T21:24:46Z</dc:date>
    </item>
  </channel>
</rss>

