<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Attaching to Serverless from Azure Data Factory via Service Principal in Data Engineering</title>
    <link>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/95688#M39149</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have issues trying to run Databricks notebooks orchestrated with Azure Data Factory. We have been doing this for a while now without any issues when we use Job Clusters, Existing General Purpose Clusters, or Cluster Pools. We use an Azure Data Factory Managed Service Identity (service principal) that we have integrated into our Databricks workspace.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is when we try to use an existing Serverless SQL Warehouse. We are able to get the ID and all necessary parameters. When we test the connection it is successful. However, we are not able to run the notebook. We get the error:&lt;/P&gt;&lt;P&gt;"Run aborted because the job run-as lacks Attach permissions on the underlying cluster"&lt;/P&gt;&lt;P&gt;As shown below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArturOA_0-1729677593083.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/12224iC63FBE1801685FF3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ArturOA_0-1729677593083.png" alt="ArturOA_0-1729677593083.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I am able to run the same notebook successfully when I use my PAT to connect to the Serverles warehouse.&lt;/P&gt;&lt;P&gt;Any idea on how to solve the issue? We really don't want to run our jobs based on personal credentials...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Oct 2024 10:01:52 GMT</pubDate>
    <dc:creator>ArturOA</dc:creator>
    <dc:date>2024-10-23T10:01:52Z</dc:date>
    <item>
      <title>Attaching to Serverless from Azure Data Factory via Service Principal</title>
      <link>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/95688#M39149</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have issues trying to run Databricks notebooks orchestrated with Azure Data Factory. We have been doing this for a while now without any issues when we use Job Clusters, Existing General Purpose Clusters, or Cluster Pools. We use an Azure Data Factory Managed Service Identity (service principal) that we have integrated into our Databricks workspace.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is when we try to use an existing Serverless SQL Warehouse. We are able to get the ID and all necessary parameters. When we test the connection it is successful. However, we are not able to run the notebook. We get the error:&lt;/P&gt;&lt;P&gt;"Run aborted because the job run-as lacks Attach permissions on the underlying cluster"&lt;/P&gt;&lt;P&gt;As shown below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArturOA_0-1729677593083.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/12224iC63FBE1801685FF3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ArturOA_0-1729677593083.png" alt="ArturOA_0-1729677593083.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I am able to run the same notebook successfully when I use my PAT to connect to the Serverles warehouse.&lt;/P&gt;&lt;P&gt;Any idea on how to solve the issue? We really don't want to run our jobs based on personal credentials...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 10:01:52 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/95688#M39149</guid>
      <dc:creator>ArturOA</dc:creator>
      <dc:date>2024-10-23T10:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: Attaching to Serverless from Azure Data Factory via Service Principal</title>
      <link>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/96089#M39214</link>
      <description>&lt;P&gt;No one? &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 07:18:59 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/96089#M39214</guid>
      <dc:creator>ArturOA</dc:creator>
      <dc:date>2024-10-25T07:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: Attaching to Serverless from Azure Data Factory via Service Principal</title>
      <link>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/96148#M39225</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/104244"&gt;@ArturOA&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Maybe you forget to give permission to ADF MSI to this serverless warehouse? Check how's your permission tab looks like.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="szymon_dybczak_0-1729867118954.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/12304iB7FF3596AE3A026A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="szymon_dybczak_0-1729867118954.png" alt="szymon_dybczak_0-1729867118954.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 14:39:18 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/96148#M39225</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2024-10-25T14:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: Attaching to Serverless from Azure Data Factory via Service Principal</title>
      <link>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/97739#M39528</link>
      <description>&lt;P&gt;Hei &lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/110502"&gt;@szymon_dybczak&lt;/a&gt; ,&lt;BR /&gt;&lt;BR /&gt;Your suggestion only allows giving permissions to individuals. We need to give permission to a Service Principal, and this is not possible.&lt;BR /&gt;&lt;BR /&gt;It seems it is not allowed by design, unfortunately...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 11:58:08 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/97739#M39528</guid>
      <dc:creator>ArturOA</dc:creator>
      <dc:date>2024-11-05T11:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Attaching to Serverless from Azure Data Factory via Service Principal</title>
      <link>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/97754#M39532</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/104244"&gt;@ArturOA&lt;/a&gt;&amp;nbsp; you can try adding a service principal in AD group and Add that AD Group to the server permissions.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 13:52:48 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/97754#M39532</guid>
      <dc:creator>chvamsi07</dc:creator>
      <dc:date>2024-11-05T13:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: Attaching to Serverless from Azure Data Factory via Service Principal</title>
      <link>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/97802#M39555</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/104244"&gt;@ArturOA&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;I think you're wrong here. Let's have a look at below screenshot. I'm able to add&amp;nbsp; permission to ADF managed identity to Serveless Warehouse. You can also create group and put service principal/managed identity inside this group and give permission to entire group.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="szymon_dybczak_0-1730828239111.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/12656i63949E625F8A2A1F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="szymon_dybczak_0-1730828239111.png" alt="szymon_dybczak_0-1730828239111.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="szymon_dybczak_1-1730828323758.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/12657i9E8434F88C5129FC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="szymon_dybczak_1-1730828323758.png" alt="szymon_dybczak_1-1730828323758.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 17:39:30 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/97802#M39555</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2024-11-05T17:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: Attaching to Serverless from Azure Data Factory via Service Principal</title>
      <link>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/97907#M39571</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/104244"&gt;@ArturOA&lt;/a&gt;&amp;nbsp;Have you synced this Managed Identity of ADF as SPN to Databricks?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 10:51:21 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/97907#M39571</guid>
      <dc:creator>JakubSkibicki</dc:creator>
      <dc:date>2024-11-06T10:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: Attaching to Serverless from Azure Data Factory via Service Principal</title>
      <link>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/98146#M39622</link>
      <description>&lt;P&gt;Does the service principal has access and permission for the notebook?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 22:01:53 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/attaching-to-serverless-from-azure-data-factory-via-service/m-p/98146#M39622</guid>
      <dc:creator>h_h_ak</dc:creator>
      <dc:date>2024-11-07T22:01:53Z</dc:date>
    </item>
  </channel>
</rss>

