<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to restrict Databricks Apps and Vector Search endpoint creation for workspace users in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/how-to-restrict-databricks-apps-and-vector-search-endpoint/m-p/147683#M4822</link>
    <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/22314"&gt;@saurabh18cs&lt;/a&gt;&amp;nbsp;- user do not have cluster creation permission except the serverless compute which I dont want to block for rest of the work.&lt;/P&gt;&lt;P&gt;User do not have admin or unrestricted cluster creation.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Feb 2026 12:17:39 GMT</pubDate>
    <dc:creator>Raman_Unifeye</dc:creator>
    <dc:date>2026-02-09T12:17:39Z</dc:date>
    <item>
      <title>How to restrict Databricks Apps and Vector Search endpoint creation for workspace users</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-restrict-databricks-apps-and-vector-search-endpoint/m-p/146761#M4802</link>
      <description>&lt;P&gt;I am looking to restrict all workspace users' access to create Databricks Apps and Vector Search endpoints.&lt;/P&gt;&lt;P&gt;I am aware there is no simple toggle, what is the best way to implement it?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 22:37:39 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-restrict-databricks-apps-and-vector-search-endpoint/m-p/146761#M4802</guid>
      <dc:creator>Raman_Unifeye</dc:creator>
      <dc:date>2026-02-03T22:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict Databricks Apps and Vector Search endpoint creation for workspace users</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-restrict-databricks-apps-and-vector-search-endpoint/m-p/146763#M4803</link>
      <description>&lt;P&gt;I propose a CI/CD process that automatically deletes apps or vector searches within three days if they are not listed in your configuration. For Databricks apps, you can also implement a scheduler to automatically pause the app.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2026 00:27:04 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-restrict-databricks-apps-and-vector-search-endpoint/m-p/146763#M4803</guid>
      <dc:creator>Kartikb</dc:creator>
      <dc:date>2026-02-04T00:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict Databricks Apps and Vector Search endpoint creation for workspace users</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-restrict-databricks-apps-and-vector-search-endpoint/m-p/146795#M4804</link>
      <description>&lt;P&gt;That's a reactive approach. Is there any proactive way to stop that esp Apps?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2026 09:57:39 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-restrict-databricks-apps-and-vector-search-endpoint/m-p/146795#M4804</guid>
      <dc:creator>Raman_Unifeye</dc:creator>
      <dc:date>2026-02-04T09:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict Databricks Apps and Vector Search endpoint creation for workspace users</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-restrict-databricks-apps-and-vector-search-endpoint/m-p/147667#M4819</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/179607"&gt;@Raman_Unifeye&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;Users &lt;STRONG&gt;cannot create an app without compute&lt;/STRONG&gt;.&lt;BR /&gt;Restrict compute creation/attachment via &lt;STRONG&gt;Cluster Policies ??&amp;nbsp;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;Also remove admin acess and unrestricted cluster creation acces at workspace level for added user or group/&lt;/STRONG&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 09 Feb 2026 11:04:19 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-restrict-databricks-apps-and-vector-search-endpoint/m-p/147667#M4819</guid>
      <dc:creator>saurabh18cs</dc:creator>
      <dc:date>2026-02-09T11:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict Databricks Apps and Vector Search endpoint creation for workspace users</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-restrict-databricks-apps-and-vector-search-endpoint/m-p/147683#M4822</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/22314"&gt;@saurabh18cs&lt;/a&gt;&amp;nbsp;- user do not have cluster creation permission except the serverless compute which I dont want to block for rest of the work.&lt;/P&gt;&lt;P&gt;User do not have admin or unrestricted cluster creation.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2026 12:17:39 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-restrict-databricks-apps-and-vector-search-endpoint/m-p/147683#M4822</guid>
      <dc:creator>Raman_Unifeye</dc:creator>
      <dc:date>2026-02-09T12:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict Databricks Apps and Vector Search endpoint creation for workspace users</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-restrict-databricks-apps-and-vector-search-endpoint/m-p/147796#M4825</link>
      <description>&lt;P&gt;Hi Raman,&lt;/P&gt;&lt;P&gt;You can use a budget policy and define which groups or users are allowed to use that budget policy. A budget policy can be attached to an app or a Vector Search. Stop all apps that are running without a budget policy.&lt;BR /&gt;You can find cost burn for apps or Vector Searches without a policy by using system tables, and this information can be shared with the team. Databricks has published a cost dashboard that also helps you filter app and Vector Search costs.&lt;BR /&gt;Second, use CI/CD automation to operate workloads on a schedule.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Kartik&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2026 22:54:37 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-restrict-databricks-apps-and-vector-search-endpoint/m-p/147796#M4825</guid>
      <dc:creator>KartikBhatnagar</dc:creator>
      <dc:date>2026-02-09T22:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict Databricks Apps and Vector Search endpoint creation for workspace users</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-restrict-databricks-apps-and-vector-search-endpoint/m-p/150193#M4979</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/179607"&gt;@Raman_Unifeye&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You are correct that there is no single toggle to block creation of these resources today. Here is a breakdown of the proactive and detective controls available for each.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;VECTOR SEARCH ENDPOINTS&lt;/P&gt;
&lt;P&gt;Vector Search endpoints use access control lists (ACLs) with these permission levels: CAN CREATE, CAN USE, CAN MANAGE, and NO PERMISSIONS.&lt;/P&gt;
&lt;P&gt;The key mechanism is the Permissions API. A workspace admin can remove the CAN CREATE permission from the "users" group at the workspace level, then grant CAN CREATE (or CAN MANAGE) only to specific groups or service principals that should be allowed to create endpoints. You can do this through the Permissions API:&lt;/P&gt;
&lt;P&gt;PUT /api/2.0/permissions/vector-search-endpoints&lt;BR /&gt;{&lt;BR /&gt;"access_control_list": [&lt;BR /&gt;{&lt;BR /&gt;"group_name": "vector-search-admins",&lt;BR /&gt;"permission_level": "CAN_MANAGE"&lt;BR /&gt;}&lt;BR /&gt;]&lt;BR /&gt;}&lt;/P&gt;
&lt;P&gt;This sets object-level permissions on all vector search endpoints. By granting only your designated admin group the create/manage permission and not granting it to the broader "users" group, you effectively restrict who can create new endpoints.&lt;/P&gt;
&lt;P&gt;Documentation reference:&lt;BR /&gt;&lt;A href="https://docs.databricks.com/aws/en/security/auth/access-control/index.html" target="_blank"&gt;https://docs.databricks.com/aws/en/security/auth/access-control/index.html&lt;/A&gt; (see the "Vector search endpoint ACLs" section)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;DATABRICKS APPS&lt;/P&gt;
&lt;P&gt;Databricks Apps currently follow the same model as other serverless products: any user in a workspace can create an app. There is no ACL-based creation restriction for Apps the way there is for Vector Search endpoints.&lt;/P&gt;
&lt;P&gt;Here are the proactive strategies available today:&lt;/P&gt;
&lt;P&gt;1. Workspace segmentation: If you need strict control, consider dedicating a separate workspace for app development and only granting access to that workspace to approved developers. Users who should not create apps simply do not have access to the app-enabled workspace.&lt;/P&gt;
&lt;P&gt;2. Serverless budget policies: While these are primarily for cost attribution, they give you visibility and some guardrails. You can create a budget policy and assign it only to approved groups. When a user who is not assigned a budget policy tries to create an app, the policy enforcement may limit them depending on your configuration. More details here:&lt;BR /&gt;&lt;A href="https://docs.databricks.com/aws/en/admin/usage/budget-policies.html" target="_blank"&gt;https://docs.databricks.com/aws/en/admin/usage/budget-policies.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;3. Automated cleanup via API: Use the Databricks Apps API to periodically list all apps and delete or stop any that were created by unauthorized users. This can be scheduled as a job:&lt;/P&gt;
&lt;P&gt;import requests&lt;/P&gt;
&lt;P&gt;host = "https://&amp;lt;workspace-url&amp;gt;"&lt;BR /&gt;headers = {"Authorization": "Bearer &amp;lt;token&amp;gt;"}&lt;/P&gt;
&lt;P&gt;# List all apps&lt;BR /&gt;response = requests.get(f"{host}/api/2.0/apps", headers=headers)&lt;BR /&gt;apps = response.json().get("apps", [])&lt;/P&gt;
&lt;P&gt;# Define allowed creators&lt;BR /&gt;allowed_creators = ["admin-user@company.com", "app-team@company.com"]&lt;/P&gt;
&lt;P&gt;for app in apps:&lt;BR /&gt;creator = app.get("creator")&lt;BR /&gt;if creator not in allowed_creators:&lt;BR /&gt;app_name = app.get("name")&lt;BR /&gt;# Stop the app&lt;BR /&gt;requests.post(f"{host}/api/2.0/apps/{app_name}/stop", headers=headers)&lt;BR /&gt;# Or delete it&lt;BR /&gt;requests.delete(f"{host}/api/2.0/apps/{app_name}", headers=headers)&lt;/P&gt;
&lt;P&gt;4. System tables monitoring: Query the system.billing.usage table to monitor for app creation events and set up alerts. This gives you near-real-time detection if someone creates an unauthorized app.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;SUMMARY OF APPROACHES&lt;/P&gt;
&lt;P&gt;Proactive (prevents creation):&lt;BR /&gt;- Vector Search: Use Permissions API to restrict CAN CREATE to specific groups&lt;BR /&gt;- Apps: Use workspace segmentation (separate workspace for app development)&lt;/P&gt;
&lt;P&gt;Detective/Reactive (detects and remediates):&lt;BR /&gt;- Both: Automated cleanup scripts via REST API&lt;BR /&gt;- Both: System tables monitoring and alerts&lt;BR /&gt;- Both: Serverless budget policies for cost visibility and attribution&lt;/P&gt;
&lt;P&gt;The Vector Search endpoint restriction is straightforward through ACLs. For Databricks Apps, workspace segmentation is the most reliable proactive approach until a dedicated creation-restriction mechanism is available.&lt;/P&gt;
&lt;P&gt;* This reply used an agent system I built to research and draft this response based on the wide set of documentation I have available and previous memory. I personally review the draft for any obvious issues and for monitoring system reliability and update it when I detect any drift, but there is still a small chance that something is inaccurate, especially if you are experimenting with brand new features.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2026 07:36:26 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-restrict-databricks-apps-and-vector-search-endpoint/m-p/150193#M4979</guid>
      <dc:creator>SteveOstrowski</dc:creator>
      <dc:date>2026-03-08T07:36:26Z</dc:date>
    </item>
  </channel>
</rss>

