<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AIM with Entra ID Groups – Users and Service Principals not visible in Workspace in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/aim-with-entra-id-groups-users-and-service-principals-not/m-p/135298#M4237</link>
    <description>&lt;P&gt;In Azure Databricks, when AIM is enabled,&amp;nbsp;&lt;SPAN&gt;Entra users, service principals, and groups are available in Azure Databricks as soon as they’re granted permissions. Group memberships, including nested groups, flow directly from Entra ID, so permissions always reflect the latest updates.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can you please check the &lt;A href="https://learn.microsoft.com/en-us/azure/databricks/admin/users-groups/automatic-identity-management#-user-and-group-statuses" target="_self"&gt;status&lt;/A&gt;&amp;nbsp;of these principals in the account or workspace? Refer to this&amp;nbsp;&lt;A href="https://www.databricks.com/blog/automatic-identity-management-entra-id-now-generally-available-azure-databricks" target="_self"&gt;blog&lt;/A&gt;. And the &lt;A href="https://youtu.be/BA2QR_lF9qA" target="_self"&gt;demo&lt;/A&gt; which shows the statuses of the principals.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 18 Oct 2025 01:54:42 GMT</pubDate>
    <dc:creator>dkushari</dc:creator>
    <dc:date>2025-10-18T01:54:42Z</dc:date>
    <item>
      <title>AIM with Entra ID Groups – Users and Service Principals not visible in Workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/aim-with-entra-id-groups-users-and-service-principals-not/m-p/134620#M4195</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello Community,&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I am testing Automatic Identity Management (AIM) in Databricks with Unity Catalog enabled.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Steps I did:&lt;/DIV&gt;&lt;DIV&gt;      •     AIM is activated&lt;/DIV&gt;&lt;DIV&gt;      •     In Microsoft Entra ID I created a group g1 and added user u1 and service principal sp1&lt;/DIV&gt;&lt;DIV&gt;      •     I expected auto sync between Databricks Account, Workspace (UC enabled) and Entra ID&lt;/DIV&gt;&lt;DIV&gt;      •     I assigned group g1 to Databricks Workspace w1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Expectation in workspace w1:&lt;/DIV&gt;&lt;DIV&gt;      •     Group g1 should be available&lt;/DIV&gt;&lt;DIV&gt;      •     User u1 should be visible as a workspace user&lt;/DIV&gt;&lt;DIV&gt;      •     Service principal sp1 should be visible in the workspace&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Actual result:&lt;/DIV&gt;&lt;DIV&gt;      •     Group g1 appears in w1&lt;/DIV&gt;&lt;DIV&gt;      •     u1 and sp1 are not visible in the workspace&lt;/DIV&gt;&lt;DIV&gt;      •     User u1 could not access the workspace even though this user is in g1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Question:&lt;/DIV&gt;&lt;DIV&gt;Do I need to add users and service principals manually to the workspace (and in Terraform)? I expected that adding them to the group in Entra ID would automatically provision them in the workspace.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thanks in advance.&lt;/DIV&gt;</description>
      <pubDate>Sat, 11 Oct 2025 08:06:10 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/aim-with-entra-id-groups-users-and-service-principals-not/m-p/134620#M4195</guid>
      <dc:creator>hasanakhuy</dc:creator>
      <dc:date>2025-10-11T08:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: AIM with Entra ID Groups – Users and Service Principals not visible in Workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/aim-with-entra-id-groups-users-and-service-principals-not/m-p/135298#M4237</link>
      <description>&lt;P&gt;In Azure Databricks, when AIM is enabled,&amp;nbsp;&lt;SPAN&gt;Entra users, service principals, and groups are available in Azure Databricks as soon as they’re granted permissions. Group memberships, including nested groups, flow directly from Entra ID, so permissions always reflect the latest updates.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can you please check the &lt;A href="https://learn.microsoft.com/en-us/azure/databricks/admin/users-groups/automatic-identity-management#-user-and-group-statuses" target="_self"&gt;status&lt;/A&gt;&amp;nbsp;of these principals in the account or workspace? Refer to this&amp;nbsp;&lt;A href="https://www.databricks.com/blog/automatic-identity-management-entra-id-now-generally-available-azure-databricks" target="_self"&gt;blog&lt;/A&gt;. And the &lt;A href="https://youtu.be/BA2QR_lF9qA" target="_self"&gt;demo&lt;/A&gt; which shows the statuses of the principals.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Oct 2025 01:54:42 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/aim-with-entra-id-groups-users-and-service-principals-not/m-p/135298#M4237</guid>
      <dc:creator>dkushari</dc:creator>
      <dc:date>2025-10-18T01:54:42Z</dc:date>
    </item>
  </channel>
</rss>

