<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to prevent direct workspace changes in Databricks by vendors / external users? in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/how-to-prevent-direct-workspace-changes-in-databricks-by-vendors/m-p/156502#M5230</link>
    <description>&lt;P class=""&gt;&lt;SPAN&gt;Thanks for adding more details.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Since PAT and Databricks personnel workspace access are already disabled, I would suggest first reviewing audit logs to identify whether the change was made by a workspace admin, account admin, service principal, Terraform, CLI, API, or vendor user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Customer-controlled changes should generally be traceable through audit logs. For Databricks platform-side updates, new feature rollouts, or backend service changes, Databricks Support would be the right team to confirm what can be controlled, deferred, monitored, or audited.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;For stronger governance, you can consider limiting workspace admin access, managing changes through IaC/CI-CD, disabling previews in production, separating dev/test/prod workspaces, and setting alerts for workspace setting or policy changes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 09 May 2026 20:49:25 GMT</pubDate>
    <dc:creator>Brahmareddy</dc:creator>
    <dc:date>2026-05-09T20:49:25Z</dc:date>
    <item>
      <title>How to prevent direct workspace changes in Databricks by vendors / external users?</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-prevent-direct-workspace-changes-in-databricks-by-vendors/m-p/156499#M5227</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I’m looking for guidance on workspace governance and change control in Databricks, specifically related to vendor access.&lt;/P&gt;&lt;P&gt;We recently observed that workspace-level changes seem to be applied directly, and we want to understand how this is happening and how to better control it.&lt;/P&gt;&lt;DIV&gt;Is it possible for the Databricks (service provider) internal team to apply direct changes to a customer workspace (such as policies, configurations, or settings), and if so, how can organizations enforce controls to ensure all workspace changes are applied only through approved mechanisms with full auditability?&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;SPAN&gt;can you find out from Databricks how workspace changes are applied directly from vendor? &lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 09 May 2026 18:14:01 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-prevent-direct-workspace-changes-in-databricks-by-vendors/m-p/156499#M5227</guid>
      <dc:creator>koti521</dc:creator>
      <dc:date>2026-05-09T18:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent direct workspace changes in Databricks by vendors / external users?</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-prevent-direct-workspace-changes-in-databricks-by-vendors/m-p/156500#M5228</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;How are you doing today? as per my understanding,&amp;nbsp;&lt;SPAN&gt;we can first validate whether &lt;/SPAN&gt;Databricks personnel access&lt;SPAN&gt; is enabled for your workspace. If it is enabled, we should confirm whether any recent workspace-level changes were performed as part of an approved support case, vendor activity, or internal admin action.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;To get better clarity, we can review the workspace audit logs and check details such as who made the change, when it was made, what was changed, and whether it was linked to an approved change request or support ticket.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Going forward, you may want to keep vendor access disabled by default and enable it only when required for a specific support case, with a clear approval, defined time window, and audit tracking. Any workspace-level changes such as policies, configurations, permissions, or settings should ideally go through our standard change control process.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Hope this helps ensure better visibility, accountability, and full auditability for all Databricks workspace changes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Let me know for any additional questions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Brahma&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 May 2026 20:00:15 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-prevent-direct-workspace-changes-in-databricks-by-vendors/m-p/156500#M5228</guid>
      <dc:creator>Brahmareddy</dc:creator>
      <dc:date>2026-05-09T20:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent direct workspace changes in Databricks by vendors / external users?</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-prevent-direct-workspace-changes-in-databricks-by-vendors/m-p/156501#M5229</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/102548"&gt;@Brahmareddy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;In our current Databricks workspace, the Personal Access Tokens (PAT) option is disabled, and we are reviewing additional controls to strengthen governance around workspace-level changes.&lt;/P&gt;&lt;P&gt;I have also seen the setting “Workspace access for Azure Databricks personnel,” which appears to allow Databricks engineers to access the workspace for troubleshooting purposes. However, this option seems limited to support scenarios and does not fully address our broader governance requirement. this also disabled right now.&lt;/P&gt;&lt;P&gt;With that context, I would like to understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;How are workspace-level changes (such as configurations, policies, or new platform features/enhancements) applied from the Databricks platform side?&lt;/LI&gt;&lt;LI&gt;Is it possible for such changes to be applied directly to customer workspaces outside of customer-controlled processes?&lt;/LI&gt;&lt;LI&gt;Are there any workspace settings, controls, or design approaches available to restrict or manage how such changes are applied, so they can be reviewed, validated, and aligned with internal change management processes?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Our goal is to ensure that no changes are applied directly to the workspace without visibility, control, and proper approval, particularly in production environments.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 09 May 2026 20:32:29 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-prevent-direct-workspace-changes-in-databricks-by-vendors/m-p/156501#M5229</guid>
      <dc:creator>koti521</dc:creator>
      <dc:date>2026-05-09T20:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent direct workspace changes in Databricks by vendors / external users?</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-prevent-direct-workspace-changes-in-databricks-by-vendors/m-p/156502#M5230</link>
      <description>&lt;P class=""&gt;&lt;SPAN&gt;Thanks for adding more details.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Since PAT and Databricks personnel workspace access are already disabled, I would suggest first reviewing audit logs to identify whether the change was made by a workspace admin, account admin, service principal, Terraform, CLI, API, or vendor user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Customer-controlled changes should generally be traceable through audit logs. For Databricks platform-side updates, new feature rollouts, or backend service changes, Databricks Support would be the right team to confirm what can be controlled, deferred, monitored, or audited.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;For stronger governance, you can consider limiting workspace admin access, managing changes through IaC/CI-CD, disabling previews in production, separating dev/test/prod workspaces, and setting alerts for workspace setting or policy changes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 May 2026 20:49:25 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-prevent-direct-workspace-changes-in-databricks-by-vendors/m-p/156502#M5230</guid>
      <dc:creator>Brahmareddy</dc:creator>
      <dc:date>2026-05-09T20:49:25Z</dc:date>
    </item>
  </channel>
</rss>

