<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Which role is recommended to create and manage Unity Catalog objects—Workspace Admin or Metastor in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/which-role-is-recommended-to-create-and-manage-unity-catalog/m-p/153342#M5113</link>
    <description>&lt;P&gt;I am designing the security model for our Databricks platform and need guidance on role selection for managing Unity Catalog. Which role should be used for creating and managing Unity Catalog objects such as Storage Credentials, External Locations, Catalogs, Schemas, and Delta Sharing?&lt;/P&gt;&lt;P&gt;Specifically, for automation using Terraform, which role should be assigned to the service principal responsible for creating these Unity Catalog objects and handling future maintenance?&lt;/P&gt;&lt;P&gt;Should we use the Workspace Admin role or the Metastore Admin role, considering security best practices, least privilege, and long-term governance?&lt;/P&gt;</description>
    <pubDate>Sun, 05 Apr 2026 05:03:54 GMT</pubDate>
    <dc:creator>APJESK</dc:creator>
    <dc:date>2026-04-05T05:03:54Z</dc:date>
    <item>
      <title>Which role is recommended to create and manage Unity Catalog objects—Workspace Admin or Metastore Ad</title>
      <link>https://community.databricks.com/t5/administration-architecture/which-role-is-recommended-to-create-and-manage-unity-catalog/m-p/153341#M5112</link>
      <description>&lt;P&gt;Which role is recommended to create and manage Unity Catalog objects (catalog, schema, Storage credentials, External Location)—Workspace Admin or Metastore Admin—and why?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Apr 2026 04:58:32 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/which-role-is-recommended-to-create-and-manage-unity-catalog/m-p/153341#M5112</guid>
      <dc:creator>APJESK</dc:creator>
      <dc:date>2026-04-05T04:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: Which role is recommended to create and manage Unity Catalog objects—Workspace Admin or Metastor</title>
      <link>https://community.databricks.com/t5/administration-architecture/which-role-is-recommended-to-create-and-manage-unity-catalog/m-p/153342#M5113</link>
      <description>&lt;P&gt;I am designing the security model for our Databricks platform and need guidance on role selection for managing Unity Catalog. Which role should be used for creating and managing Unity Catalog objects such as Storage Credentials, External Locations, Catalogs, Schemas, and Delta Sharing?&lt;/P&gt;&lt;P&gt;Specifically, for automation using Terraform, which role should be assigned to the service principal responsible for creating these Unity Catalog objects and handling future maintenance?&lt;/P&gt;&lt;P&gt;Should we use the Workspace Admin role or the Metastore Admin role, considering security best practices, least privilege, and long-term governance?&lt;/P&gt;</description>
      <pubDate>Sun, 05 Apr 2026 05:03:54 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/which-role-is-recommended-to-create-and-manage-unity-catalog/m-p/153342#M5113</guid>
      <dc:creator>APJESK</dc:creator>
      <dc:date>2026-04-05T05:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: Which role is recommended to create and manage Unity Catalog objects—Workspace Admin or Metastor</title>
      <link>https://community.databricks.com/t5/administration-architecture/which-role-is-recommended-to-create-and-manage-unity-catalog/m-p/153353#M5114</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/170854"&gt;@APJESK&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Per Databricks &lt;A href="https://docs.databricks.com/aws/en/lakehouse-architecture/deployment-guide/account-setup" target="_blank"&gt;best practices&lt;/A&gt;, use workspace admin&amp;nbsp;for day-to-day workspace management and metastore admin&amp;nbsp;optionally, but specifically for central data governance and metastore-level storage across workspaces.&lt;/P&gt;
&lt;P&gt;At a high level,&amp;nbsp;use a dedicated service principal with Unity Catalog level privileges (ideally Metastore Admin or equivalent METASTORE grants), not a long-lived Workspace Admin, for Terraform automation.&lt;/P&gt;
&lt;P&gt;For creating and managing UC objects via Terraform, use a service principal with metastore level privileges... preferably via the Metastore Admin role on the target metastore, assigned to a group the SP belongs to.&amp;nbsp;Or via explicit GRANT … ON METASTORE of the specific UC privileges needed.&lt;/P&gt;
&lt;P&gt;For UC object management...&amp;nbsp;Metastore Admin (or equivalent METASTORE grants) is the correct choice.&amp;nbsp; Reserve Workspace Admin for workspace-centric tasks (users, jobs, clusters, workspace catalog), not for central UC governance.&lt;/P&gt;
&lt;P&gt;The only exception is when&amp;nbsp;creating the metastore itself and linking workspaces with Terraform... for which&amp;nbsp;you also need a service principal with Account Admin permissions, per the UC Terraform automation &lt;A href="https://docs.databricks.com/aws/en/dev-tools/terraform/automate-uc" target="_blank"&gt;docs&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P class="p1"&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;&lt;I&gt;If this answer resolves your question, could you mark it as “Accept as Solution”? That helps other users quickly find the correct fix.&lt;/I&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;I&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Apr 2026 10:27:54 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/which-role-is-recommended-to-create-and-manage-unity-catalog/m-p/153353#M5114</guid>
      <dc:creator>Ashwin_DSA</dc:creator>
      <dc:date>2026-04-05T10:27:54Z</dc:date>
    </item>
  </channel>
</rss>

