<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: enable databricks in azure for the whole tenant in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/enable-databricks-in-azure-for-the-whole-tenant/m-p/162809#M5421</link>
    <description>&lt;P class=""&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/114460"&gt;@satycse06&lt;/a&gt;&amp;nbsp;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Azure Databricks should be onboarded through a combination of &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Azure tenant/subscription controls&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Azure Databricks account console&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, and standardized &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;workspace deployments&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;. There is not one tenant-wide “Enable Databricks” switch that automatically governs every workspace.&lt;/SPAN&gt;&lt;/P&gt;&lt;H2&gt;&lt;SPAN&gt;1. Initial tenant and account setup&lt;/SPAN&gt;&lt;/H2&gt;&lt;OL&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN&gt;Select the Azure subscriptions that are permitted to host Databricks.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Register the &lt;/SPAN&gt;&lt;SPAN&gt;Microsoft.Databricks&lt;/SPAN&gt;&lt;SPAN&gt; resource provider only in the approved subscriptions. Registration is performed per subscription, not once for the entire tenant. Microsoft recommends registering resource providers only when they are ready to be used.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN&gt;Create the first controlled Databricks workspace.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;The deployment identity needs Azure Contributor/Owner at subscription level,&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN&gt;Establish the Databricks account administrators.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;For the initial account bootstrap, a Microsoft Entra Global Administrator signs in to the Databricks account console and becomes the first Databricks account administrator. That person should then delegate the Account Admin role to two or three dedicated platform administrators and remove the Global Administrator from routine Databricks administration.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN&gt;Use Microsoft Entra ID for authentication and Conditional Access.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Microsoft Entra ID single sign-on is available by default for both the Databricks account console and workspaces. MFA and Conditional Access should therefore be enforced through Entra ID.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;H3&gt;&lt;SPAN&gt;About the Enterprise Application&lt;/SPAN&gt;&lt;/H3&gt;&lt;P class=""&gt;&lt;SPAN&gt;The &lt;/SPAN&gt;&lt;SPAN&gt;AzureDatabricks&lt;/SPAN&gt;&lt;SPAN&gt; enterprise application, whose standard resource/application ID is &lt;/SPAN&gt;&lt;SPAN&gt;2ff814a6-3304-4ab8-85cb-cd0e6f879c1d&lt;/SPAN&gt;&lt;SPAN&gt;, is the Microsoft first-party Databricks service identity. It should not be treated as the main mechanism for assigning access to individual workspaces. Workspace access is managed through Databricks account-level identities, groups and workspace assignments.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;For a new account, use &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Automatic Identity Management&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, which is enabled by default for accounts created after August 1, 2025. It uses Entra ID as the source of record and supports users, service principals, groups and nested groups. If Automatic Identity Management is unavailable for a legacy account, configure the separate &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Azure Databricks SCIM Provisioning Connector&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; enterprise application at account level.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Users should be assigned to workspaces through these account-level groups rather than individually.&lt;/SPAN&gt;&lt;/P&gt;&lt;H2&gt;&lt;SPAN&gt;2. Enabling Databricks only in selected subscriptions&lt;/SPAN&gt;&lt;/H2&gt;&lt;P class=""&gt;&lt;SPAN&gt;Resource-provider registration alone is not sufficient as a security boundary because Azure Contributor and Owner roles include the permission to register resource providers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;The recommended control is:&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;Place approved Databricks subscriptions under a dedicated Azure management group.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Apply an Azure Policy at the parent or root management-group level that denies &lt;/SPAN&gt;&lt;SPAN&gt;Microsoft.Databricks/workspaces&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Exclude only the approved Databricks management group or subscriptions from that deny assignment.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Grant workspace deployment permissions only to the central platform team or deployment service principal in those subscriptions.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Deploy workspaces exclusively through an approved Terraform, Bicep or ARM module.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P class=""&gt;&lt;SPAN&gt;&lt;BR /&gt;If my answer was helpful, please consider marking it as accepted solution.&lt;/SPAN&gt;&lt;/P&gt;&lt;H2&gt;&amp;nbsp;&lt;/H2&gt;</description>
    <pubDate>Mon, 13 Jul 2026 13:43:48 GMT</pubDate>
    <dc:creator>szymon_dybczak</dc:creator>
    <dc:date>2026-07-13T13:43:48Z</dc:date>
    <item>
      <title>enable databricks in azure for the whole tenant</title>
      <link>https://community.databricks.com/t5/administration-architecture/enable-databricks-in-azure-for-the-whole-tenant/m-p/162389#M5408</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have to enable the databricks in azure cloud for the whole organisation in azure.&lt;/P&gt;&lt;P&gt;I want to know the very 1st level i.e how to enable or integrate the databricks account with azure tenant and after that how I can enbale it for selected subscription and apply the compliance and policies.&lt;/P&gt;&lt;P&gt;As per the databricks documetation&amp;nbsp;Azure Databricks appears as an &lt;STRONG&gt;Enterprise application&lt;/STRONG&gt; in Entra ID then how to control the policies for each workspace from the central level and whether need to control the network also i.e vnet injection or it can be taken care as per the azure resource group of vnet .&lt;/P&gt;&lt;P&gt;Need the initial setup process as per the admin perspective&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Satya&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2026 21:26:20 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/enable-databricks-in-azure-for-the-whole-tenant/m-p/162389#M5408</guid>
      <dc:creator>satycse06</dc:creator>
      <dc:date>2026-07-09T21:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: enable databricks in azure for the whole tenant</title>
      <link>https://community.databricks.com/t5/administration-architecture/enable-databricks-in-azure-for-the-whole-tenant/m-p/162758#M5417</link>
      <description>&lt;P&gt;is anyone can give some reference documents to plan it well&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2026 07:45:29 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/enable-databricks-in-azure-for-the-whole-tenant/m-p/162758#M5417</guid>
      <dc:creator>satycse06</dc:creator>
      <dc:date>2026-07-13T07:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: enable databricks in azure for the whole tenant</title>
      <link>https://community.databricks.com/t5/administration-architecture/enable-databricks-in-azure-for-the-whole-tenant/m-p/162809#M5421</link>
      <description>&lt;P class=""&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/114460"&gt;@satycse06&lt;/a&gt;&amp;nbsp;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Azure Databricks should be onboarded through a combination of &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Azure tenant/subscription controls&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Azure Databricks account console&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, and standardized &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;workspace deployments&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;. There is not one tenant-wide “Enable Databricks” switch that automatically governs every workspace.&lt;/SPAN&gt;&lt;/P&gt;&lt;H2&gt;&lt;SPAN&gt;1. Initial tenant and account setup&lt;/SPAN&gt;&lt;/H2&gt;&lt;OL&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN&gt;Select the Azure subscriptions that are permitted to host Databricks.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Register the &lt;/SPAN&gt;&lt;SPAN&gt;Microsoft.Databricks&lt;/SPAN&gt;&lt;SPAN&gt; resource provider only in the approved subscriptions. Registration is performed per subscription, not once for the entire tenant. Microsoft recommends registering resource providers only when they are ready to be used.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN&gt;Create the first controlled Databricks workspace.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;The deployment identity needs Azure Contributor/Owner at subscription level,&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN&gt;Establish the Databricks account administrators.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;For the initial account bootstrap, a Microsoft Entra Global Administrator signs in to the Databricks account console and becomes the first Databricks account administrator. That person should then delegate the Account Admin role to two or three dedicated platform administrators and remove the Global Administrator from routine Databricks administration.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN&gt;Use Microsoft Entra ID for authentication and Conditional Access.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Microsoft Entra ID single sign-on is available by default for both the Databricks account console and workspaces. MFA and Conditional Access should therefore be enforced through Entra ID.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;H3&gt;&lt;SPAN&gt;About the Enterprise Application&lt;/SPAN&gt;&lt;/H3&gt;&lt;P class=""&gt;&lt;SPAN&gt;The &lt;/SPAN&gt;&lt;SPAN&gt;AzureDatabricks&lt;/SPAN&gt;&lt;SPAN&gt; enterprise application, whose standard resource/application ID is &lt;/SPAN&gt;&lt;SPAN&gt;2ff814a6-3304-4ab8-85cb-cd0e6f879c1d&lt;/SPAN&gt;&lt;SPAN&gt;, is the Microsoft first-party Databricks service identity. It should not be treated as the main mechanism for assigning access to individual workspaces. Workspace access is managed through Databricks account-level identities, groups and workspace assignments.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;For a new account, use &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Automatic Identity Management&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, which is enabled by default for accounts created after August 1, 2025. It uses Entra ID as the source of record and supports users, service principals, groups and nested groups. If Automatic Identity Management is unavailable for a legacy account, configure the separate &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Azure Databricks SCIM Provisioning Connector&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; enterprise application at account level.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Users should be assigned to workspaces through these account-level groups rather than individually.&lt;/SPAN&gt;&lt;/P&gt;&lt;H2&gt;&lt;SPAN&gt;2. Enabling Databricks only in selected subscriptions&lt;/SPAN&gt;&lt;/H2&gt;&lt;P class=""&gt;&lt;SPAN&gt;Resource-provider registration alone is not sufficient as a security boundary because Azure Contributor and Owner roles include the permission to register resource providers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;The recommended control is:&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;Place approved Databricks subscriptions under a dedicated Azure management group.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Apply an Azure Policy at the parent or root management-group level that denies &lt;/SPAN&gt;&lt;SPAN&gt;Microsoft.Databricks/workspaces&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Exclude only the approved Databricks management group or subscriptions from that deny assignment.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Grant workspace deployment permissions only to the central platform team or deployment service principal in those subscriptions.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Deploy workspaces exclusively through an approved Terraform, Bicep or ARM module.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P class=""&gt;&lt;SPAN&gt;&lt;BR /&gt;If my answer was helpful, please consider marking it as accepted solution.&lt;/SPAN&gt;&lt;/P&gt;&lt;H2&gt;&amp;nbsp;&lt;/H2&gt;</description>
      <pubDate>Mon, 13 Jul 2026 13:43:48 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/enable-databricks-in-azure-for-the-whole-tenant/m-p/162809#M5421</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2026-07-13T13:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: enable databricks in azure for the whole tenant</title>
      <link>https://community.databricks.com/t5/administration-architecture/enable-databricks-in-azure-for-the-whole-tenant/m-p/162919#M5431</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/110502"&gt;@szymon_dybczak&lt;/a&gt;&amp;nbsp;Thanks for the response and well explanation.&lt;/P&gt;&lt;P&gt;I have another question related to vnet injection architecture. So as per you we can create a management group and include all the subscription in that management group and will apply the polices at root level. But what about network shall I assign each vnet for each of the subscription which will be part of the mangement group or a hub spoke architecture so that we can manage the network policies centrally like not allowing the public IP accessibility of databricks workspace&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 07:42:18 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/enable-databricks-in-azure-for-the-whole-tenant/m-p/162919#M5431</guid>
      <dc:creator>satycse06</dc:creator>
      <dc:date>2026-07-14T07:42:18Z</dc:date>
    </item>
  </channel>
</rss>

