<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAT Tool Scan other workspaces in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134462#M4184</link>
    <description>&lt;P&gt;I was reading the SAT GitHub page and this might be network issue as well.&lt;/P&gt;&lt;P&gt;If you run SAT on Serverless compute or behind IP ACLs, cross‑workspace API calls can be blocked.&lt;BR /&gt;The Setup guide notes that SAT can’t analyze other workspaces when:&lt;/P&gt;&lt;P&gt;The destination workspaces (or account) use IP ACLs that block the SAT workspace/compute, or&lt;BR /&gt;The SAT workspace enforces serverless egress control that prevents outbound calls.&lt;BR /&gt;Fix: Allow the egress/IPs, run SAT on classic compute, or deploy a separate SAT instance in the restricted workspace&lt;/P&gt;</description>
    <pubDate>Thu, 09 Oct 2025 19:49:29 GMT</pubDate>
    <dc:creator>nayan_wylde</dc:creator>
    <dc:date>2025-10-09T19:49:29Z</dc:date>
    <item>
      <title>SAT Tool Scan other workspaces</title>
      <link>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134438#M4177</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have been setting up SAT in my Databricks workspace and i am able to do it and scan in my workspace. i have provided my SP access to all other Workspaces as well&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i run the initialize job (SAT Initializer Notebook (one-time)) , I could notice that all workspaces in my account is being listed in the the "configs/workspace_configs.csv"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;But when i trigger the job&amp;nbsp; "SAT Driver Notebook" it is still scanning only on current workspace. No other workspace are being scanned&lt;/P&gt;&lt;P&gt;can anybody help me out in scanning all other workspace as well in the SAT job or provide some clear documentation on this&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 16:51:32 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134438#M4177</guid>
      <dc:creator>vvijay61</dc:creator>
      <dc:date>2025-10-09T16:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: SAT Tool Scan other workspaces</title>
      <link>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134454#M4180</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/190072"&gt;@vvijay61&lt;/a&gt;Just confirming if your SPN have workspace admin access also you can make sure in the config csv if&amp;nbsp;analysis_enabled = True&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 18:31:37 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134454#M4180</guid>
      <dc:creator>nayan_wylde</dc:creator>
      <dc:date>2025-10-09T18:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: SAT Tool Scan other workspaces</title>
      <link>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134455#M4181</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My SP have workspace admin access. When running initialization job. It is fetching all workspace ID&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 18:28:20 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134455#M4181</guid>
      <dc:creator>vvijay61</dc:creator>
      <dc:date>2025-10-09T18:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: SAT Tool Scan other workspaces</title>
      <link>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134457#M4182</link>
      <description>&lt;P&gt;Can you also&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;make sure in the config csv if&amp;nbsp;analysis_enabled = True&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 18:32:33 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134457#M4182</guid>
      <dc:creator>nayan_wylde</dc:creator>
      <dc:date>2025-10-09T18:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: SAT Tool Scan other workspaces</title>
      <link>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134458#M4183</link>
      <description>&lt;P&gt;Its already set to true.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 19:29:27 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134458#M4183</guid>
      <dc:creator>vvijay61</dc:creator>
      <dc:date>2025-10-09T19:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: SAT Tool Scan other workspaces</title>
      <link>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134462#M4184</link>
      <description>&lt;P&gt;I was reading the SAT GitHub page and this might be network issue as well.&lt;/P&gt;&lt;P&gt;If you run SAT on Serverless compute or behind IP ACLs, cross‑workspace API calls can be blocked.&lt;BR /&gt;The Setup guide notes that SAT can’t analyze other workspaces when:&lt;/P&gt;&lt;P&gt;The destination workspaces (or account) use IP ACLs that block the SAT workspace/compute, or&lt;BR /&gt;The SAT workspace enforces serverless egress control that prevents outbound calls.&lt;BR /&gt;Fix: Allow the egress/IPs, run SAT on classic compute, or deploy a separate SAT instance in the restricted workspace&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 19:49:29 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134462#M4184</guid>
      <dc:creator>nayan_wylde</dc:creator>
      <dc:date>2025-10-09T19:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: SAT Tool Scan other workspaces</title>
      <link>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134537#M4190</link>
      <description>&lt;P&gt;I have tried some trouble shooting and was able to detect the second WS for SAT scan&lt;BR /&gt;i have added the WS details in table&amp;nbsp;"admin.security_analysis.account_workspaces"&lt;BR /&gt;and when i run the Job it fetched this&lt;BR /&gt;&lt;BR /&gt;but eventually the check was not completed with following error message&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;Forbidden 2025-10-10 13:51:19,378 - _profiler_ - INFO - {"error_code":403,"message":"Cert validation failed. &lt;STRONG&gt;Cross workspace access is denied due to network policies&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Can we have a suitable solution to this. We are using SAT in serverless&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 13:58:09 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134537#M4190</guid>
      <dc:creator>vvijay61</dc:creator>
      <dc:date>2025-10-10T13:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: SAT Tool Scan other workspaces</title>
      <link>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134539#M4192</link>
      <description>&lt;P&gt;It seems like a access is denied by network policy. You have to update Network Policy for Serverless at account level&lt;/P&gt;&lt;P&gt;In Account Console → Cloud Resources → Policies → Serverless Egress Control → default-policy&lt;BR /&gt;Check the Allow access to all destinations (unrestricted outbound) OR&lt;BR /&gt;Keep Restricted Access but add the FQDNs of all target workspaces (e.g., adb-&amp;lt;workspace-id&amp;gt;.azuredatabricks.net) to the Allowed Domains list.&lt;/P&gt;&lt;P&gt;It will require Account Admin Permissions&lt;/P&gt;&lt;P&gt;-----------------------------------------------------------------------------------------------------------------------------------------------&lt;BR /&gt;If PrivateLink is enforced in your workspaces, create NCC rules to allow managed private endpoints for cross-workspace API calls.&lt;BR /&gt;NCC is account-level and can attach to multiple workspaces.&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/network/serverless-network-security/" target="_blank" rel="noopener"&gt;https://learn.microsoft.com/en-us/azure/databricks/security/network/serverless-network-security/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 14:21:54 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/sat-tool-scan-other-workspaces/m-p/134539#M4192</guid>
      <dc:creator>nayan_wylde</dc:creator>
      <dc:date>2025-10-10T14:21:54Z</dc:date>
    </item>
  </channel>
</rss>

