<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Leverage Azure PIM with DataBricks with Contributor role privilege in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/leverage-azure-pim-with-databricks-with-contributor-role/m-p/44040#M377</link>
    <description>&lt;P&gt;Thanks - think we were originally overthinking this.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We determined we were doing this correctly, the user just needed to switch to 'groups' within PIM to request elevation of permissions. &amp;nbsp;The larger issue is actually the 40 min user provisioning cycle as DataBricks does not pick up the change until this runs. &amp;nbsp;This may be an option long-term, but the User Provisioning delay is making this a no go for our team.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Sep 2023 18:38:39 GMT</pubDate>
    <dc:creator>SmileyVille</dc:creator>
    <dc:date>2023-09-07T18:38:39Z</dc:date>
    <item>
      <title>Leverage Azure PIM with DataBricks with Contributor role privilege</title>
      <link>https://community.databricks.com/t5/administration-architecture/leverage-azure-pim-with-databricks-with-contributor-role/m-p/43846#M373</link>
      <description>&lt;P&gt;We are trying to leverage Azure PIM. &amp;nbsp;This works great for most things, however; we've run into a snag. &amp;nbsp;We want to limit the contributor role to a group and only at the resource group level, not subscription. &amp;nbsp;We wish to elevate via PIM. &amp;nbsp;This will then allow the user access within DataBricks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#1 issue - We have to enable PIM at the group level as it doesn't show up for group members within PIM and can't assign a contributor level group within the PIM application in Azure. &amp;nbsp;So an admin has to enable PIM for the user to activate at the group level. &amp;nbsp;We've also tried to do this scenario leveraging the Managed Application Contributor role as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#2 - Delay - We are using the SCIM connector for User Provisioning leveraging Azure AD Groups. &amp;nbsp;This connects to the unity catalog and are able to assign the groups within the Workspace. &amp;nbsp;The issue - after you elevate the users permission in the contributor group at the resource level, you have to wait for 40 minutes for user provisioning to run or stop/start it. &amp;nbsp;Until then, the user remains in an 'inactive' state within DataBricks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We feel we are missing a more fluid way to grant these rights and leverage PIM. &amp;nbsp;Suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 16:03:28 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/leverage-azure-pim-with-databricks-with-contributor-role/m-p/43846#M373</guid>
      <dc:creator>SmileyVille</dc:creator>
      <dc:date>2023-09-06T16:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: Leverage Azure PIM with DataBricks with Contributor role privilege</title>
      <link>https://community.databricks.com/t5/administration-architecture/leverage-azure-pim-with-databricks-with-contributor-role/m-p/44040#M377</link>
      <description>&lt;P&gt;Thanks - think we were originally overthinking this.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We determined we were doing this correctly, the user just needed to switch to 'groups' within PIM to request elevation of permissions. &amp;nbsp;The larger issue is actually the 40 min user provisioning cycle as DataBricks does not pick up the change until this runs. &amp;nbsp;This may be an option long-term, but the User Provisioning delay is making this a no go for our team.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 18:38:39 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/leverage-azure-pim-with-databricks-with-contributor-role/m-p/44040#M377</guid>
      <dc:creator>SmileyVille</dc:creator>
      <dc:date>2023-09-07T18:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: Leverage Azure PIM with DataBricks with Contributor role privilege</title>
      <link>https://community.databricks.com/t5/administration-architecture/leverage-azure-pim-with-databricks-with-contributor-role/m-p/92244#M1938</link>
      <description>&lt;P&gt;Did you find a solution to 20-40min delay?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 03:35:02 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/leverage-azure-pim-with-databricks-with-contributor-role/m-p/92244#M1938</guid>
      <dc:creator>sharadapakala</dc:creator>
      <dc:date>2024-09-30T03:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: Leverage Azure PIM with DataBricks with Contributor role privilege</title>
      <link>https://community.databricks.com/t5/administration-architecture/leverage-azure-pim-with-databricks-with-contributor-role/m-p/113841#M3189</link>
      <description>&lt;P&gt;Never did, so we scrapped PIM with Databricks for now.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 20:27:38 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/leverage-azure-pim-with-databricks-with-contributor-role/m-p/113841#M3189</guid>
      <dc:creator>SmileyVille</dc:creator>
      <dc:date>2025-03-27T20:27:38Z</dc:date>
    </item>
  </channel>
</rss>

