<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: on-behalf-of token creation (for SPN) in Data Engineering</title>
    <link>https://community.databricks.com/t5/data-engineering/on-behalf-of-token-creation-for-spn/m-p/38595#M26683</link>
    <description>&lt;P&gt;My understanding is that Microsoft has this disabled this but it's not very clear in any of the MS documentation. Our MS rep had to do some digging to get to that conclusion.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jul 2023 19:42:02 GMT</pubDate>
    <dc:creator>Chris_Shehu</dc:creator>
    <dc:date>2023-07-27T19:42:02Z</dc:date>
    <item>
      <title>on-behalf-of token creation (for SPN)</title>
      <link>https://community.databricks.com/t5/data-engineering/on-behalf-of-token-creation-for-spn/m-p/32451#M23646</link>
      <description>&lt;P&gt;I am trying to create an on-behalf-token for and SPN on my Azure Databricks Premium instance. The response is a FEATURE_DISABLED error message ("On-behalf-of token creation for service principals is not enabled for this workspace"). How do I turn on this feature? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 12:55:02 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/on-behalf-of-token-creation-for-spn/m-p/32451#M23646</guid>
      <dc:creator>clapton79</dc:creator>
      <dc:date>2022-09-06T12:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: on-behalf-of token creation (for SPN)</title>
      <link>https://community.databricks.com/t5/data-engineering/on-behalf-of-token-creation-for-spn/m-p/32452#M23647</link>
      <description>&lt;P&gt;HI @Laszlo Katai-Pal​&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to provide &lt;B&gt;CAN_USE&lt;/B&gt; permission to the service principal in the token manage permission, you can see this option in : Admin-&amp;gt;workspace setting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/1526iF8C68B2591E1718A/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/1532iFDBCF4AC7DF633D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;Once you provide this permission to your SP , you can create token on behalf of SP&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 06:08:06 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/on-behalf-of-token-creation-for-spn/m-p/32452#M23647</guid>
      <dc:creator>User16752245772</dc:creator>
      <dc:date>2022-09-20T06:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: on-behalf-of token creation (for SPN)</title>
      <link>https://community.databricks.com/t5/data-engineering/on-behalf-of-token-creation-for-spn/m-p/38592#M26681</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I've performed the above steps and am trying to create an OBO token via CLI 0.2 using "databricks&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;token&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;management create&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;obo&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;token &amp;lt;app-id-here&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;3600"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;but I continue to get the error message: "On-behalf-of token creation for service principals is not enabled for this workspace"&lt;/P&gt;&lt;P&gt;Is there anything else that's a prerequisite to allowing these tokens to be created? The SP has been added to a group which has been added to the workspace, and given CAN_USE on tokens via the admin screen. Do the SPs need admin rights on the workspace?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 18:58:39 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/on-behalf-of-token-creation-for-spn/m-p/38592#M26681</guid>
      <dc:creator>gklassen</dc:creator>
      <dc:date>2023-07-27T18:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: on-behalf-of token creation (for SPN)</title>
      <link>https://community.databricks.com/t5/data-engineering/on-behalf-of-token-creation-for-spn/m-p/38595#M26683</link>
      <description>&lt;P&gt;My understanding is that Microsoft has this disabled this but it's not very clear in any of the MS documentation. Our MS rep had to do some digging to get to that conclusion.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 19:42:02 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/on-behalf-of-token-creation-for-spn/m-p/38595#M26683</guid>
      <dc:creator>Chris_Shehu</dc:creator>
      <dc:date>2023-07-27T19:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: on-behalf-of token creation (for SPN)</title>
      <link>https://community.databricks.com/t5/data-engineering/on-behalf-of-token-creation-for-spn/m-p/45537#M27922</link>
      <description>&lt;P&gt;&lt;A href="https://community.databricks.com/t5/user/viewprofilepage/user-id/44214" target="_self"&gt;&lt;SPAN class=""&gt;gklassen&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;SPAN class=""&gt;&lt;A href="https://community.databricks.com/t5/user/viewprofilepage/user-id/82981" target="_self"&gt;&lt;SPAN class=""&gt;Chris_Shehu&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;: Any further luck on this issue. Is it resolved.. ? I am also facing the same issue..&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 14:26:45 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/on-behalf-of-token-creation-for-spn/m-p/45537#M27922</guid>
      <dc:creator>chaitanyak</dc:creator>
      <dc:date>2023-09-21T14:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: on-behalf-of token creation (for SPN)</title>
      <link>https://community.databricks.com/t5/data-engineering/on-behalf-of-token-creation-for-spn/m-p/49746#M28615</link>
      <description>&lt;P&gt;&lt;SPAN&gt;There is no On-behalf-of token on Azure - just generate an AAD token for the Service Principal and use it to create PAT (make sure that SP has permission to use PATs).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The easiest way of doing it is to use the new Databricks CLI that supports &lt;A href="https://learn.microsoft.com/en-us/azure/databricks/dev-tools/auth#--azure-service-principal-authentication" target="_self"&gt;unified authentication&lt;/A&gt; - just set the correct environment variables or define all parameters as a profile in the configuration file, and use "databricks tokens create" command to generate tokens. Something like this:&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;SPAN&gt;export DATABRICKS_HOST=https://adb-....17.azuredatabricks.net&lt;BR /&gt;export ARM_CLIENT_SECRET=&amp;lt;sp_secret&amp;gt;&lt;BR /&gt;export ARM_CLIENT_ID=&amp;lt;application_id&amp;gt;&lt;BR /&gt;export ARM_TENANT_ID=&amp;lt;tenant_id&amp;gt;&lt;BR /&gt;databricks tokens create --lifetime-seconds 30 --comment "test"&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;Here is a &lt;A href="https://stackoverflow.com/questions/74613470/create-databricks-token-for-another-user/74614770#74614770" target="_self"&gt;reference implementation&lt;/A&gt; for the Databricks Terraform provider.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 14:43:03 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/on-behalf-of-token-creation-for-spn/m-p/49746#M28615</guid>
      <dc:creator>alexott</dc:creator>
      <dc:date>2023-10-23T14:43:03Z</dc:date>
    </item>
  </channel>
</rss>

