<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting up Databricks with Unity Catalog using a service principal (instead of managed identity) in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/49395#M508</link>
    <description>&lt;P&gt;Thanks to all for the suggestions.&amp;nbsp; Ultimately, we went with the Managed Identity configuration (after all that investigation).&amp;nbsp; Answers very much appreciated.&amp;nbsp; Thank you.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Oct 2023 15:28:11 GMT</pubDate>
    <dc:creator>m997al</dc:creator>
    <dc:date>2023-10-17T15:28:11Z</dc:date>
    <item>
      <title>Setting up Databricks with Unity Catalog using a service principal (instead of managed identity)</title>
      <link>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48786#M490</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are attempting to set up Databricks with Unity Catalog (metastore) using a service principal (as opposed to the managed identity).&lt;/P&gt;&lt;P&gt;Instructions we are using are here:&amp;nbsp;&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/create-metastore#create-a-metastore-that-is-accessed-using-a-service-principal" target="_blank"&gt;Create a Unity Catalog metastore - Azure Databricks | Microsoft Learn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The challenge is that when we attempt to create the metastore in the Databricks account console, there is a &lt;STRONG&gt;required&lt;/STRONG&gt; entry of "Access Connector ID".&amp;nbsp; In a previous trial, we successfully configured a Databricks metastore using a Databricks Access Connector and a managed identity.&lt;/P&gt;&lt;P&gt;But we deleted that metastore, and we are trying to use the service principal setup instead (a requirement by IT).&amp;nbsp; It is unclear what the "Access Connector ID" field should be, or if we still need a Databricks Access Connector if we are using a service principal.&lt;/P&gt;&lt;P&gt;The steps in the instructions do not mention anything about an "Access Connector ID" for the creation of a metastore using a service principal, so we are confused as to how to proceed.&lt;/P&gt;&lt;P&gt;Has anyone run into this?&amp;nbsp; Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 20:10:43 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48786#M490</guid>
      <dc:creator>m997al</dc:creator>
      <dc:date>2023-10-09T20:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Databricks with Unity Catalog using a service principal (instead of managed identity)</title>
      <link>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48829#M493</link>
      <description>&lt;P&gt;The UI only supports configuring metastore with Managed Identity + Access Connector, to configure it with a service principal, you would need to do programmatic via the API -&amp;nbsp;&lt;A href="https://docs.databricks.com/api/azure/workspace/storagecredentials/create" target="_blank"&gt;https://docs.databricks.com/api/azure/workspace/storagecredentials/create&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 09:01:11 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48829#M493</guid>
      <dc:creator>nkvuong</dc:creator>
      <dc:date>2023-10-10T09:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Databricks with Unity Catalog using a service principal (instead of managed identity)</title>
      <link>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48833#M494</link>
      <description>&lt;P&gt;We only support an API workflow for SP based UC set up. Please note that it will not work if your ADLS is behind a firewall (which is where MI is required)&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 09:19:45 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48833#M494</guid>
      <dc:creator>som_natarajan</dc:creator>
      <dc:date>2023-10-10T09:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Databricks with Unity Catalog using a service principal (instead of managed identity)</title>
      <link>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48858#M496</link>
      <description>&lt;P&gt;Hi - thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 14:47:51 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48858#M496</guid>
      <dc:creator>m997al</dc:creator>
      <dc:date>2023-10-10T14:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Databricks with Unity Catalog using a service principal (instead of managed identity)</title>
      <link>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48871#M497</link>
      <description>&lt;P&gt;Hi - I am a bit worried about this not working behind a firewall.&amp;nbsp; Our ADLS Gen2 will indeed have a private endpoint.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 18:57:29 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48871#M497</guid>
      <dc:creator>m997al</dc:creator>
      <dc:date>2023-10-10T18:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Databricks with Unity Catalog using a service principal (instead of managed identity)</title>
      <link>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48873#M498</link>
      <description>&lt;P&gt;Yes..hence the recommended approach to use MI instead of SPs..which is also why the UI only supports MI based pathway to setting up UC&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 19:04:53 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48873#M498</guid>
      <dc:creator>som_natarajan</dc:creator>
      <dc:date>2023-10-10T19:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Databricks with Unity Catalog using a service principal (instead of managed identity)</title>
      <link>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48882#M499</link>
      <description>&lt;P&gt;So there is no way, even with whitelisting, to get the service principal approach to work with a private ADLS Gen2 endpoint?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 19:59:42 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48882#M499</guid>
      <dc:creator>m997al</dc:creator>
      <dc:date>2023-10-10T19:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Databricks with Unity Catalog using a service principal (instead of managed identity)</title>
      <link>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48884#M500</link>
      <description>&lt;P&gt;No&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 20:27:02 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/48884#M500</guid>
      <dc:creator>som_natarajan</dc:creator>
      <dc:date>2023-10-10T20:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Databricks with Unity Catalog using a service principal (instead of managed identity)</title>
      <link>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/49393#M507</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/86358"&gt;@m997al&lt;/a&gt;&amp;nbsp;For UC ADLS Gen 2 behind Firewall config is not needed and support wise limitations as far as i know, if you have security concerns you can Restrict ADLS Gen2 folders to be access by particular users/ groups , which we can do from ADLS Gen 2 config settings.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 15:20:26 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/49393#M507</guid>
      <dc:creator>karthik_p</dc:creator>
      <dc:date>2023-10-17T15:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Databricks with Unity Catalog using a service principal (instead of managed identity)</title>
      <link>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/49395#M508</link>
      <description>&lt;P&gt;Thanks to all for the suggestions.&amp;nbsp; Ultimately, we went with the Managed Identity configuration (after all that investigation).&amp;nbsp; Answers very much appreciated.&amp;nbsp; Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 15:28:11 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/setting-up-databricks-with-unity-catalog-using-a-service/m-p/49395#M508</guid>
      <dc:creator>m997al</dc:creator>
      <dc:date>2023-10-17T15:28:11Z</dc:date>
    </item>
  </channel>
</rss>

