<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No Explicit Deny for User security configurations at the group level? in Data Engineering</title>
    <link>https://community.databricks.com/t5/data-engineering/no-explicit-deny-for-user-security-configurations-at-the-group/m-p/7218#M3145</link>
    <description>&lt;P&gt;@Christopher Shehu​&amp;nbsp;If you don't want the "Users" group is enabled with "Workspace access" and "Databricks SQL access" entitlements, you disable all entitlements. Create separate groups based on your use case and enable the required entitlements. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding parent user groups, a group can be a member(child) of another group(s). As per the screenshot, subgroup is a child of john_test_group and maingroup (parent groups). Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/2550i0D26FE544C2BA8F3/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Mar 2023 17:35:59 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2023-03-24T17:35:59Z</dc:date>
    <item>
      <title>No Explicit Deny for User security configurations at the group level?</title>
      <link>https://community.databricks.com/t5/data-engineering/no-explicit-deny-for-user-security-configurations-at-the-group/m-p/7217#M3144</link>
      <description>&lt;P&gt;Currently when you add new users to the Databricks workspace they get added to a "Users" group that has full access to the workspace. There should be a way to use group security to explicitly deny access to those same settings. This setting should override the default allow access. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/504iC8F8E9178D51583F/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/505i23E1872C4C47A410/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/509i052F12A5E96ADF14/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also noticed the Parent User Groups are empty inside the groups? Is this maybe something we should be using that we're not? &lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 22:20:27 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/no-explicit-deny-for-user-security-configurations-at-the-group/m-p/7217#M3144</guid>
      <dc:creator>Chris_Shehu</dc:creator>
      <dc:date>2023-03-22T22:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: No Explicit Deny for User security configurations at the group level?</title>
      <link>https://community.databricks.com/t5/data-engineering/no-explicit-deny-for-user-security-configurations-at-the-group/m-p/7218#M3145</link>
      <description>&lt;P&gt;@Christopher Shehu​&amp;nbsp;If you don't want the "Users" group is enabled with "Workspace access" and "Databricks SQL access" entitlements, you disable all entitlements. Create separate groups based on your use case and enable the required entitlements. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding parent user groups, a group can be a member(child) of another group(s). As per the screenshot, subgroup is a child of john_test_group and maingroup (parent groups). Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/2550i0D26FE544C2BA8F3/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 17:35:59 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/no-explicit-deny-for-user-security-configurations-at-the-group/m-p/7218#M3145</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2023-03-24T17:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: No Explicit Deny for User security configurations at the group level?</title>
      <link>https://community.databricks.com/t5/data-engineering/no-explicit-deny-for-user-security-configurations-at-the-group/m-p/7219#M3146</link>
      <description>&lt;P&gt;Hi @Christopher Shehu​&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for posting your question in our community! We are happy to assist you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To help us provide you with the most accurate information, could you please take a moment to review the responses and select the one that best answers your question?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will also help other community members who may have similar questions in the future. Thank you for your participation and let us know if you need any further assistance!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 05:01:20 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/no-explicit-deny-for-user-security-configurations-at-the-group/m-p/7219#M3146</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2023-03-27T05:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: No Explicit Deny for User security configurations at the group level?</title>
      <link>https://community.databricks.com/t5/data-engineering/no-explicit-deny-for-user-security-configurations-at-the-group/m-p/7220#M3147</link>
      <description>&lt;P&gt;Yes, there should be a way to use group security to explicitly deny access to the workspace settings for new users added to the "Users" group. This setting should override the default allow access.    &lt;A href="https://www.umrproviderportal.org/" alt="https://www.umrproviderportal.org/" target="_blank"&gt;UMR Provider Portal Login&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 08:10:34 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/no-explicit-deny-for-user-security-configurations-at-the-group/m-p/7220#M3147</guid>
      <dc:creator>deanjames</dc:creator>
      <dc:date>2023-03-28T08:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: No Explicit Deny for User security configurations at the group level?</title>
      <link>https://community.databricks.com/t5/data-engineering/no-explicit-deny-for-user-security-configurations-at-the-group/m-p/7221#M3148</link>
      <description>&lt;P&gt;@dean james​&amp;nbsp;I am not sure about your case why you want to deny access to the group once you create it. Anyhow, we can use deacticate/activate an user using "2.0/preview/scim/v2/Users/{id}" rest API endpoint. We can also deactivate users that have not logged in for a customizable period. Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/dev-tools/api/latest/scim/scim-users.html#activate-and-deactivate-user-by-id" target="test_blank"&gt;https://docs.databricks.com/dev-tools/api/latest/scim/scim-users.html#activate-and-deactivate-user-by-id&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/dev-tools/api/latest/scim/scim-users.html#automatically-deactivate-users" target="test_blank"&gt;https://docs.databricks.com/dev-tools/api/latest/scim/scim-users.html#automatically-deactivate-users&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 10:14:06 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/no-explicit-deny-for-user-security-configurations-at-the-group/m-p/7221#M3148</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2023-03-28T10:14:06Z</dc:date>
    </item>
  </channel>
</rss>

