<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Removing access to Lakehouse and only allowing Databricks One? in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/removing-access-to-lakehouse-and-only-allowing-databricks-one/m-p/142278#M4662</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to set up a user group for business users in our Azure Databricks that will only be able to query data. It looks like Databricks One is the solution to use. So I followed the documentation and granted the user group Consumer Access in the Workspace. I made sure the other entitlements were not checked. The user has use catalog access to the default catalog, the catalog where the data they're querying is, and select on the gold level schema under the catalog.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I log in as a test user using the Databricks One URL I can log in and query data as the user. When I go to the switch applications menu I see Lakehouse as an option. I can access lake house and create jobs and do things our project owner would like to have restricted. I remember reading all permissions have to be removed from the workspace and only Consumer Access assigned. I've tried removing access to the catalog, gold level data, and compute from the user. When I do Databricks One queries no longer work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a step I'm missing to force the user into Databricks One and remove the Lakehouse from the Switch Apps Menu?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Dec 2025 19:43:59 GMT</pubDate>
    <dc:creator>NatJ</dc:creator>
    <dc:date>2025-12-19T19:43:59Z</dc:date>
    <item>
      <title>Removing access to Lakehouse and only allowing Databricks One?</title>
      <link>https://community.databricks.com/t5/administration-architecture/removing-access-to-lakehouse-and-only-allowing-databricks-one/m-p/142278#M4662</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to set up a user group for business users in our Azure Databricks that will only be able to query data. It looks like Databricks One is the solution to use. So I followed the documentation and granted the user group Consumer Access in the Workspace. I made sure the other entitlements were not checked. The user has use catalog access to the default catalog, the catalog where the data they're querying is, and select on the gold level schema under the catalog.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I log in as a test user using the Databricks One URL I can log in and query data as the user. When I go to the switch applications menu I see Lakehouse as an option. I can access lake house and create jobs and do things our project owner would like to have restricted. I remember reading all permissions have to be removed from the workspace and only Consumer Access assigned. I've tried removing access to the catalog, gold level data, and compute from the user. When I do Databricks One queries no longer work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a step I'm missing to force the user into Databricks One and remove the Lakehouse from the Switch Apps Menu?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2025 19:43:59 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/removing-access-to-lakehouse-and-only-allowing-databricks-one/m-p/142278#M4662</guid>
      <dc:creator>NatJ</dc:creator>
      <dc:date>2025-12-19T19:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: Removing access to Lakehouse and only allowing Databricks One?</title>
      <link>https://community.databricks.com/t5/administration-architecture/removing-access-to-lakehouse-and-only-allowing-databricks-one/m-p/142343#M4665</link>
      <description>&lt;P&gt;Hi, have you checked inherited access? So the "users" and "account users" groups by default have "workspace access" and "Databricks SQL" access by default. You would need to remove this access from these groups as well otherwise you'll never be able to grant a single user consumer access only. You will then need to create new groups for anyone who still needs workspace access.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Dec 2025 09:30:14 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/removing-access-to-lakehouse-and-only-allowing-databricks-one/m-p/142343#M4665</guid>
      <dc:creator>emma_s</dc:creator>
      <dc:date>2025-12-22T09:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: Removing access to Lakehouse and only allowing Databricks One?</title>
      <link>https://community.databricks.com/t5/administration-architecture/removing-access-to-lakehouse-and-only-allowing-databricks-one/m-p/142359#M4666</link>
      <description>&lt;P&gt;Yeah, that was it. I had set up Databricks with Entra groups from the beginning and had done all my permission work there. I didn't even think of checking the default groups. Thank you!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Dec 2025 14:26:28 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/removing-access-to-lakehouse-and-only-allowing-databricks-one/m-p/142359#M4666</guid>
      <dc:creator>NatJ</dc:creator>
      <dc:date>2025-12-22T14:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: Removing access to Lakehouse and only allowing Databricks One?</title>
      <link>https://community.databricks.com/t5/administration-architecture/removing-access-to-lakehouse-and-only-allowing-databricks-one/m-p/142360#M4667</link>
      <description>&lt;P&gt;No problem, glad I could help.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Dec 2025 14:28:32 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/removing-access-to-lakehouse-and-only-allowing-databricks-one/m-p/142360#M4667</guid>
      <dc:creator>emma_s</dc:creator>
      <dc:date>2025-12-22T14:28:32Z</dc:date>
    </item>
  </channel>
</rss>

