<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: azure databricks automatic user provisioning via terraform in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/azure-databricks-automatic-user-provisioning-via-terraform/m-p/119430#M3367</link>
    <description>&lt;P&gt;see &lt;A href="https://github.com/databricks/terraform-provider-databricks/issues/4687#issuecomment-2875157936" target="_blank"&gt;https://github.com/databricks/terraform-provider-databricks/issues/4687#issuecomment-2875157936&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 16 May 2025 09:00:04 GMT</pubDate>
    <dc:creator>oktarinet</dc:creator>
    <dc:date>2025-05-16T09:00:04Z</dc:date>
    <item>
      <title>azure databricks automatic user provisioning via terraform</title>
      <link>https://community.databricks.com/t5/administration-architecture/azure-databricks-automatic-user-provisioning-via-terraform/m-p/118922#M3343</link>
      <description>&lt;P&gt;Hi community,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Azure databricks recently announced a new user management feature (now in public preview) called&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/admin/users-groups/automatic-identity-management#enable-automatic-identity-management" target="_self"&gt;automatic-identity-management&lt;/A&gt;&amp;nbsp;, which allows Azure databricks to access Azure Entra ID directly and grant users and groups permissions and roles in Databricks directly, without needing a SCIM provisioning application.&lt;BR /&gt;&lt;BR /&gt;I have enabled this feature and have successfully provisioned test users into my workspace. However, I have not been successful at configuring this through Terraform.&lt;BR /&gt;Here is some code I have attempted:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;resource "databricks_group" "test" {
  display_name         = "auto-provisioning-test"
  allow_cluster_create = true
  workspace_access     = true
}
data "azuread_group" "test" {
  display_name = "SGA_DATABRICKS_Test" # Entra group
}

resource "databricks_group_member" "test" {
  group_id  = databricks_group.test.id
  member_id = data.azuread_group.test.object_id
}&lt;/LI-CODE&gt;&lt;P&gt;I also tried&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;data "databricks_group" "test" {
  display_name = "SGA_DATABRICKS_Test" # Entra group
}&lt;/LI-CODE&gt;&lt;P&gt;But both attempts gave me a "&lt;SPAN class=""&gt;Error: &lt;/SPAN&gt;&lt;SPAN class=""&gt;cannot read group member: Group has no member" error.&lt;BR /&gt;&lt;BR /&gt;Is there a correct way to do this?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 15:37:29 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/azure-databricks-automatic-user-provisioning-via-terraform/m-p/118922#M3343</guid>
      <dc:creator>oktarinet</dc:creator>
      <dc:date>2025-05-12T15:37:29Z</dc:date>
    </item>
    <item>
      <title>Re: azure databricks automatic user provisioning via terraform</title>
      <link>https://community.databricks.com/t5/administration-architecture/azure-databricks-automatic-user-provisioning-via-terraform/m-p/119430#M3367</link>
      <description>&lt;P&gt;see &lt;A href="https://github.com/databricks/terraform-provider-databricks/issues/4687#issuecomment-2875157936" target="_blank"&gt;https://github.com/databricks/terraform-provider-databricks/issues/4687#issuecomment-2875157936&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 May 2025 09:00:04 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/azure-databricks-automatic-user-provisioning-via-terraform/m-p/119430#M3367</guid>
      <dc:creator>oktarinet</dc:creator>
      <dc:date>2025-05-16T09:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: azure databricks automatic user provisioning via terraform</title>
      <link>https://community.databricks.com/t5/administration-architecture/azure-databricks-automatic-user-provisioning-via-terraform/m-p/119437#M3369</link>
      <description>&lt;P&gt;Hi , I think&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;automatic identity management&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;feature provisions Azure Entra ID users and groups directly into Databricks. However, Terraform's&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;databricks_group&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;databricks_group_member&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;resources are designed for managing groups and memberships&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;within Databricks&lt;/STRONG&gt;, not for managing Azure Entra ID groups directly.&lt;/LI&gt;&lt;LI&gt;The error&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Group has no member&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;occurs because the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;databricks_group&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;resource is trying to manage a group that is already being managed by Azure Entra ID through automatic provisioning.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 16 May 2025 10:16:14 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/azure-databricks-automatic-user-provisioning-via-terraform/m-p/119437#M3369</guid>
      <dc:creator>saurabh18cs</dc:creator>
      <dc:date>2025-05-16T10:16:14Z</dc:date>
    </item>
  </channel>
</rss>

