<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authorization Issue while creating first Unity catalog table in Data Engineering</title>
    <link>https://community.databricks.com/t5/data-engineering/authorization-issue-while-creating-first-unity-catalog-table/m-p/122238#M46709</link>
    <description>&lt;P&gt;&amp;nbsp;Hi All,&lt;/P&gt;&lt;P&gt;We are setting up our new UC enabled databricks workspace. We have completed the metastore setup for our workspace and we have created new catalog and schema. But while creating a table we are getting authorization issue. Below is the table script and error message.&lt;/P&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;CREATE&lt;/SPAN&gt; &lt;SPAN&gt;TABLE&lt;/SPAN&gt; &lt;SPAN&gt;IF&lt;/SPAN&gt; &lt;SPAN&gt;NOT&lt;/SPAN&gt; &lt;SPAN&gt;EXISTS&lt;/SPAN&gt;&amp;nbsp;mycatalog&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;myschema&lt;/SPAN&gt;&lt;SPAN&gt;.department&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;deptcode &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;INT&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;deptname &amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;STRING&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;location&lt;/SPAN&gt;&lt;SPAN&gt; &amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;STRING&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;);&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Error:shaded.databricks.azurebfs.org.apache.hadoop.fs.azurebfs.contracts.exceptions.AbfsRestOperationException) Operation failed: "This request is not authorized to perform this operation.", 403, GET, &lt;A href="https://mystorageaccount.dfs.core.windows.net/mycontainer?upn=false&amp;amp;resource=filesystem&amp;amp;maxResults=5000&amp;amp;directory=data/__unitystorage/catalogs/3f9da161-4d45-4bde-a982-2737902e4969/tables/4fca3020-f6ff-4e64-9d6a-0a844682af72/_delta_log&amp;amp;continuation=NTU4NjA5OTE0NzQwMTQ1MDUyNyAwIDAwMDAwMDAwMDAwMDAwMDAwMDA=&amp;amp;timeout=90&amp;amp;recursive=false&amp;amp;st=2025-06-18T06:40:55Z&amp;amp;sv=2020-02-10&amp;amp;ske=2025-06-18T08:40:55Z&amp;amp;sig=XXXXX&amp;amp;sktid=513294a0-3e20-41b2-a970-6d30bf1546fa&amp;amp;se=2025-06-18T07:55:48Z&amp;amp;sdd=6&amp;amp;skoid=76563148-066d-4b3dXXXXXXXXXXXXXXXXXX&amp;amp;spr=https&amp;amp;sks=b&amp;amp;skt=2025-06-18T06:40:55Z&amp;amp;sp=rl&amp;amp;skv=2025-01-05&amp;amp;sr=d" target="_blank"&gt;https://mystorageaccount.dfs.core.windows.net/mycontainer?upn=false&amp;amp;resource=filesystem&amp;amp;maxResults=5000&amp;amp;directory=data/__unitystorage/catalogs/3f9da161-4d45-4bde-a982-2737902e4969/tables/4fca3020-f6ff-4e64-9d6a-0a844682af72/_delta_log&amp;amp;continuation=NTU4NjA5OTE0NzQwMTQ1MDUyNyAwIDAwMDAwMDAwMDAwMDAwMDAwMDA=&amp;amp;timeout=90&amp;amp;recursive=false&amp;amp;st=2025-06-18T06:40:55Z&amp;amp;sv=2020-02-10&amp;amp;ske=2025-06-18T08:40:55Z&amp;amp;sig=XXXXX&amp;amp;sktid=513294a0-3e20-41b2-a970-6d30bf1546fa&amp;amp;se=2025-06-18T07:55:48Z&amp;amp;sdd=6&amp;amp;skoid=76563148-066d-4b3dXXXXXXXXXXXXXXXXXX&amp;amp;spr=https&amp;amp;sks=b&amp;amp;skt=2025-06-18T06:40:55Z&amp;amp;sp=rl&amp;amp;skv=2025-01-05&amp;amp;sr=d&lt;/A&gt;, AuthorizationFailure, , "This request is not authorized to perform this operation. RequestId:7acf4e05-901f-0099-461e-e095ff000000 Time:2025-06-18T06:55:52.8249225Z"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Additional Information: We are using Azure Databricks connector as system assigned managed identity to ad access to mystorageaccount at storage account level. We have provided &lt;STRONG&gt;Storage Account Contributor&lt;/STRONG&gt;, Storage Blob Data Contributor, Storage Queue Data Contributor and&amp;nbsp;Storage Table Data Contributor roles to the connector.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;We have also whitelisted the Databricks IP into storage account. &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Any help regarding this issue will be very helpful.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;#&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Thanks&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 19 Jun 2025 11:03:51 GMT</pubDate>
    <dc:creator>AliviaB</dc:creator>
    <dc:date>2025-06-19T11:03:51Z</dc:date>
    <item>
      <title>Authorization Issue while creating first Unity catalog table</title>
      <link>https://community.databricks.com/t5/data-engineering/authorization-issue-while-creating-first-unity-catalog-table/m-p/122238#M46709</link>
      <description>&lt;P&gt;&amp;nbsp;Hi All,&lt;/P&gt;&lt;P&gt;We are setting up our new UC enabled databricks workspace. We have completed the metastore setup for our workspace and we have created new catalog and schema. But while creating a table we are getting authorization issue. Below is the table script and error message.&lt;/P&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;CREATE&lt;/SPAN&gt; &lt;SPAN&gt;TABLE&lt;/SPAN&gt; &lt;SPAN&gt;IF&lt;/SPAN&gt; &lt;SPAN&gt;NOT&lt;/SPAN&gt; &lt;SPAN&gt;EXISTS&lt;/SPAN&gt;&amp;nbsp;mycatalog&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;myschema&lt;/SPAN&gt;&lt;SPAN&gt;.department&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;deptcode &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;INT&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;deptname &amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;STRING&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;location&lt;/SPAN&gt;&lt;SPAN&gt; &amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;STRING&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;);&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Error:shaded.databricks.azurebfs.org.apache.hadoop.fs.azurebfs.contracts.exceptions.AbfsRestOperationException) Operation failed: "This request is not authorized to perform this operation.", 403, GET, &lt;A href="https://mystorageaccount.dfs.core.windows.net/mycontainer?upn=false&amp;amp;resource=filesystem&amp;amp;maxResults=5000&amp;amp;directory=data/__unitystorage/catalogs/3f9da161-4d45-4bde-a982-2737902e4969/tables/4fca3020-f6ff-4e64-9d6a-0a844682af72/_delta_log&amp;amp;continuation=NTU4NjA5OTE0NzQwMTQ1MDUyNyAwIDAwMDAwMDAwMDAwMDAwMDAwMDA=&amp;amp;timeout=90&amp;amp;recursive=false&amp;amp;st=2025-06-18T06:40:55Z&amp;amp;sv=2020-02-10&amp;amp;ske=2025-06-18T08:40:55Z&amp;amp;sig=XXXXX&amp;amp;sktid=513294a0-3e20-41b2-a970-6d30bf1546fa&amp;amp;se=2025-06-18T07:55:48Z&amp;amp;sdd=6&amp;amp;skoid=76563148-066d-4b3dXXXXXXXXXXXXXXXXXX&amp;amp;spr=https&amp;amp;sks=b&amp;amp;skt=2025-06-18T06:40:55Z&amp;amp;sp=rl&amp;amp;skv=2025-01-05&amp;amp;sr=d" target="_blank"&gt;https://mystorageaccount.dfs.core.windows.net/mycontainer?upn=false&amp;amp;resource=filesystem&amp;amp;maxResults=5000&amp;amp;directory=data/__unitystorage/catalogs/3f9da161-4d45-4bde-a982-2737902e4969/tables/4fca3020-f6ff-4e64-9d6a-0a844682af72/_delta_log&amp;amp;continuation=NTU4NjA5OTE0NzQwMTQ1MDUyNyAwIDAwMDAwMDAwMDAwMDAwMDAwMDA=&amp;amp;timeout=90&amp;amp;recursive=false&amp;amp;st=2025-06-18T06:40:55Z&amp;amp;sv=2020-02-10&amp;amp;ske=2025-06-18T08:40:55Z&amp;amp;sig=XXXXX&amp;amp;sktid=513294a0-3e20-41b2-a970-6d30bf1546fa&amp;amp;se=2025-06-18T07:55:48Z&amp;amp;sdd=6&amp;amp;skoid=76563148-066d-4b3dXXXXXXXXXXXXXXXXXX&amp;amp;spr=https&amp;amp;sks=b&amp;amp;skt=2025-06-18T06:40:55Z&amp;amp;sp=rl&amp;amp;skv=2025-01-05&amp;amp;sr=d&lt;/A&gt;, AuthorizationFailure, , "This request is not authorized to perform this operation. RequestId:7acf4e05-901f-0099-461e-e095ff000000 Time:2025-06-18T06:55:52.8249225Z"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Additional Information: We are using Azure Databricks connector as system assigned managed identity to ad access to mystorageaccount at storage account level. We have provided &lt;STRONG&gt;Storage Account Contributor&lt;/STRONG&gt;, Storage Blob Data Contributor, Storage Queue Data Contributor and&amp;nbsp;Storage Table Data Contributor roles to the connector.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;We have also whitelisted the Databricks IP into storage account. &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Any help regarding this issue will be very helpful.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;#&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Thanks&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 19 Jun 2025 11:03:51 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/authorization-issue-while-creating-first-unity-catalog-table/m-p/122238#M46709</guid>
      <dc:creator>AliviaB</dc:creator>
      <dc:date>2025-06-19T11:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue while creating first Unity catalog table</title>
      <link>https://community.databricks.com/t5/data-engineering/authorization-issue-while-creating-first-unity-catalog-table/m-p/122404#M46762</link>
      <description>&lt;P&gt;Are there locations specified for the catalog/table/schema? Or do you keep these at defaults?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, do you have a storage credential and external location set for mystorageaccount/mycontainer?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 21:55:07 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/authorization-issue-while-creating-first-unity-catalog-table/m-p/122404#M46762</guid>
      <dc:creator>cgrant</dc:creator>
      <dc:date>2025-06-20T21:55:07Z</dc:date>
    </item>
  </channel>
</rss>

