<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PERMISSION_DENIED: Request for user delegation key is not authorized. in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/permission-denied-request-for-user-delegation-key-is-not/m-p/144044#M4731</link>
    <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/110502"&gt;@szymon_dybczak&lt;/a&gt;&amp;nbsp;Can you provide a link to the documentation you noted? I confirmed this with my own testing, that the Storage Blob Delegator role must be at the ADLS account-level, and Storage Blob Data Reader can then be applied at the container-level. However, I couldn't find any documentation to support this.&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jan 2026 14:23:36 GMT</pubDate>
    <dc:creator>hietpas</dc:creator>
    <dc:date>2026-01-14T14:23:36Z</dc:date>
    <item>
      <title>PERMISSION_DENIED: Request for user delegation key is not authorized.</title>
      <link>https://community.databricks.com/t5/administration-architecture/permission-denied-request-for-user-delegation-key-is-not/m-p/143802#M4721</link>
      <description>&lt;P&gt;I am attempting to copy files from an Azure Storage container using an Azure Databricks Volume. When attempting to list files using dbutils.fs.ls('&lt;SPAN&gt;/Volumes/myCatalog/mySchema/myVolume' I get the following error:&lt;BR /&gt;&lt;SPAN class=""&gt;ExecutionError: &lt;/SPAN&gt;&lt;SPAN&gt;(com.databricks.sql.managedcatalog.acl.UnauthorizedAccessException) PERMISSION_DENIED: Request for user delegation key is not authorized. Details: None&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Note that this differs from previous error messages where a user has insufficient grants. I cannot find any other references to "delegation key" that address this.&lt;/P&gt;&lt;P&gt;The Volume is based on an External Location pointing to the ADLS container. I am using an access connector for Databricks identity, which has Storage Blob Data Reader role on the container. I granted READ VOLUME on the volume. I granted USE SCHEMA and USE CATALOG on the catalog containing the schema / volume. I granted BROWSE and READ FILES on the External Location. Within the catalog explore, I can test the External Location connection and confirm read access and files are listed. The Volume also displays the files. Any idea why the "delegation" might fail?&lt;/P&gt;&lt;P&gt;I previously tested a similar scenario and it worked.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 20:27:03 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/permission-denied-request-for-user-delegation-key-is-not/m-p/143802#M4721</guid>
      <dc:creator>hietpas</dc:creator>
      <dc:date>2026-01-12T20:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: PERMISSION_DENIED: Request for user delegation key is not authorized.</title>
      <link>https://community.databricks.com/t5/administration-architecture/permission-denied-request-for-user-delegation-key-is-not/m-p/143812#M4722</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/192918"&gt;@hietpas&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I think your access connector doesn't have sufficient permission to storage account. Check below documentation entry. Try to grant Storage Blob Data Contributor role for your connector.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="szymon_dybczak_0-1768255094402.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/22926i87B18623B540D917/image-size/medium?v=v2&amp;amp;px=400" role="button" title="szymon_dybczak_0-1768255094402.png" alt="szymon_dybczak_0-1768255094402.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 21:58:53 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/permission-denied-request-for-user-delegation-key-is-not/m-p/143812#M4722</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2026-01-12T21:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: PERMISSION_DENIED: Request for user delegation key is not authorized.</title>
      <link>https://community.databricks.com/t5/administration-architecture/permission-denied-request-for-user-delegation-key-is-not/m-p/144044#M4731</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/110502"&gt;@szymon_dybczak&lt;/a&gt;&amp;nbsp;Can you provide a link to the documentation you noted? I confirmed this with my own testing, that the Storage Blob Delegator role must be at the ADLS account-level, and Storage Blob Data Reader can then be applied at the container-level. However, I couldn't find any documentation to support this.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2026 14:23:36 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/permission-denied-request-for-user-delegation-key-is-not/m-p/144044#M4731</guid>
      <dc:creator>hietpas</dc:creator>
      <dc:date>2026-01-14T14:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: PERMISSION_DENIED: Request for user delegation key is not authorized.</title>
      <link>https://community.databricks.com/t5/administration-architecture/permission-denied-request-for-user-delegation-key-is-not/m-p/144067#M4735</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/192918"&gt;@hietpas&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Sure, here it is:&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/connect/unity-catalog/cloud-storage/azure-managed-identities#grant" target="_blank"&gt;Use Azure managed identities in Unity Catalog to access storage - Azure Databricks | Microsoft Learn&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2026 16:36:56 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/permission-denied-request-for-user-delegation-key-is-not/m-p/144067#M4735</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2026-01-14T16:36:56Z</dc:date>
    </item>
  </channel>
</rss>

