<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic network security perimeter post-setup questions in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/network-security-perimeter-post-setup-questions/m-p/158147#M5293</link>
    <description>&lt;P&gt;I've set up the network security perimeter with Terraform using&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/network/serverless-network-security/serverless-nsp-firewall" target="_blank"&gt;Configure an Azure network security perimeter for Azure resources - Azure Databricks | Microsoft Learn&lt;/A&gt;&amp;nbsp;as my guide.&amp;nbsp; All of the resources associated to the NSP, and the Status of each is "Succeeded (View issues)"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rjdudley_0-1780421763241.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/27475iB0A0CEFF90330FC3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Rjdudley_0-1780421763241.png" alt="Rjdudley_0-1780421763241.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When I view the issue, it says&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Provisioning state&lt;BR /&gt;Succeeded&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Issue type&lt;BR /&gt;MissingIdentityConfiguration&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Description&lt;BR /&gt;Enabling a managed identity (MI) is required to support intra-perimeter communication between resources. Only requests authenticated using MI are permitted for intra‑perimeter access. While some capabilities for certain resources may continue to function without a MI, enabling one is strongly recommended to ensure secure access within the same perimeter or across linked perimeters.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Suggested access rules&lt;BR /&gt;None&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Suggested resource IDs&lt;BR /&gt;None&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Suggested fix&lt;BR /&gt;Enable managed identity (MI) to ensure this resource can securely access other resources within the same perimeter or across linked perimeters. This is recommended even though certain capabilities may still operate without one.&lt;/P&gt;&lt;P&gt;I didn't see anything in the docs one way or the other for this, is it a problem or can we ignore it?&lt;/P&gt;&lt;P&gt;Following the "Verify ..." step, I get this response (the path was copied from the table's Details)&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;[RequestId={guid} ErrorClass=INVALID_PARAMETER_VALUE.LOCATION_OVERLAP] Input path url 'abfss://{container}@{storage account}.dfs.core.windows.net/__unitystorage/schemas/{guid}/tables/{guid}' overlaps with managed storage within 'CheckPathAccess' call.&lt;/P&gt;&lt;P&gt;It looks like that is working, but then again, no discussion one way or the other.&amp;nbsp; Is this expected since all our data access us through UC tables and therefore all locations are UC managed?&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jun 2026 17:41:19 GMT</pubDate>
    <dc:creator>Rjdudley</dc:creator>
    <dc:date>2026-06-02T17:41:19Z</dc:date>
    <item>
      <title>network security perimeter post-setup questions</title>
      <link>https://community.databricks.com/t5/administration-architecture/network-security-perimeter-post-setup-questions/m-p/158147#M5293</link>
      <description>&lt;P&gt;I've set up the network security perimeter with Terraform using&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/network/serverless-network-security/serverless-nsp-firewall" target="_blank"&gt;Configure an Azure network security perimeter for Azure resources - Azure Databricks | Microsoft Learn&lt;/A&gt;&amp;nbsp;as my guide.&amp;nbsp; All of the resources associated to the NSP, and the Status of each is "Succeeded (View issues)"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rjdudley_0-1780421763241.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/27475iB0A0CEFF90330FC3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Rjdudley_0-1780421763241.png" alt="Rjdudley_0-1780421763241.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When I view the issue, it says&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Provisioning state&lt;BR /&gt;Succeeded&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Issue type&lt;BR /&gt;MissingIdentityConfiguration&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Description&lt;BR /&gt;Enabling a managed identity (MI) is required to support intra-perimeter communication between resources. Only requests authenticated using MI are permitted for intra‑perimeter access. While some capabilities for certain resources may continue to function without a MI, enabling one is strongly recommended to ensure secure access within the same perimeter or across linked perimeters.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Suggested access rules&lt;BR /&gt;None&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Suggested resource IDs&lt;BR /&gt;None&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Suggested fix&lt;BR /&gt;Enable managed identity (MI) to ensure this resource can securely access other resources within the same perimeter or across linked perimeters. This is recommended even though certain capabilities may still operate without one.&lt;/P&gt;&lt;P&gt;I didn't see anything in the docs one way or the other for this, is it a problem or can we ignore it?&lt;/P&gt;&lt;P&gt;Following the "Verify ..." step, I get this response (the path was copied from the table's Details)&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;[RequestId={guid} ErrorClass=INVALID_PARAMETER_VALUE.LOCATION_OVERLAP] Input path url 'abfss://{container}@{storage account}.dfs.core.windows.net/__unitystorage/schemas/{guid}/tables/{guid}' overlaps with managed storage within 'CheckPathAccess' call.&lt;/P&gt;&lt;P&gt;It looks like that is working, but then again, no discussion one way or the other.&amp;nbsp; Is this expected since all our data access us through UC tables and therefore all locations are UC managed?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 17:41:19 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/network-security-perimeter-post-setup-questions/m-p/158147#M5293</guid>
      <dc:creator>Rjdudley</dc:creator>
      <dc:date>2026-06-02T17:41:19Z</dc:date>
    </item>
  </channel>
</rss>

