<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Folder execute permissions in Data Engineering</title>
    <link>https://community.databricks.com/t5/data-engineering/folder-execute-permissions/m-p/133584#M49885</link>
    <description>&lt;P&gt;Thanks for your response. That's what I imagined although could not confirm as my current project uses Unity Catalog and we are not allowed to run many commands including ACL related PySpark code.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Oct 2025 20:34:35 GMT</pubDate>
    <dc:creator>adrianhernandez</dc:creator>
    <dc:date>2025-10-02T20:34:35Z</dc:date>
    <item>
      <title>Folder execute permissions</title>
      <link>https://community.databricks.com/t5/data-engineering/folder-execute-permissions/m-p/133567#M49881</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;After reading multiple posts, going thru online forums, even asking AI I still don't have an answer for my questions. On the latest Databricks with unity catalog, what happens if I give users Execute permissions on a folder.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Can they view the contents of the folder (E.g. notebooks list)?&lt;/LI&gt;&lt;LI&gt;If they click on a notebook can they view the code? I remember working with PVC (pre Unity catalog) Databricks on AWS, permissions seemed to be different as you could specify Read + Execute and users could view the code and execute it.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;What I'm trying to accomplish (if possible) is to allow users to run notebooks on a given folder but not view the code.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 19:21:53 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/folder-execute-permissions/m-p/133567#M49881</guid>
      <dc:creator>adrianhernandez</dc:creator>
      <dc:date>2025-10-02T19:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: Folder execute permissions</title>
      <link>https://community.databricks.com/t5/data-engineering/folder-execute-permissions/m-p/133573#M49884</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/70490"&gt;@adrianhernandez&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;You're confusing UC catalog permissions with workspace ACL permissions. In UC you have following securable objects on which privileges can be granted:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="szymon_dybczak_0-1759435303669.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/20350i989CAE59B9728FFF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="szymon_dybczak_0-1759435303669.png" alt="szymon_dybczak_0-1759435303669.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In Azure Databricks, you can use access control lists (ACLs) to configure permission to access workspace level objects like folders, files, notebooks, computes etc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You can manage workspace object permissions by adding objects to folders.Objects in a folder inherit all permissions settings of that folder.&lt;BR /&gt;For example, a user that has the CAN RUN permission on a folder has CAN RUN permission on the alerts in that folder. If you grant a user access to an object inside the folder, they can view the parent folder's name, even if they do not have permissions on the parent folder.&lt;BR /&gt;For instance, a notebook named &lt;STRONG&gt;test1.py&lt;/STRONG&gt; is in a folder named &lt;STRONG&gt;Workflows&lt;/STRONG&gt;. If you grant a user &lt;STRONG&gt;CAN VIEW&lt;/STRONG&gt; on &lt;STRONG&gt;test1.py&lt;/STRONG&gt; and no permissions on &lt;STRONG&gt;Workflows&lt;/STRONG&gt;, the user can see that the parent folder is named Workflows. The user cannot view or access any other objects in the Workflows folder unless they have been granted permissions on them.&lt;/P&gt;&lt;P&gt;Below you can find all permission that you can set on Folders:&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/auth/access-control/#folder-acls" target="_blank"&gt;https://learn.microsoft.com/en-us/azure/databricks/security/auth/access-control/#folder-acls&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="szymon_dybczak_1-1759435606247.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/20351i9796806FC94DA428/image-size/medium?v=v2&amp;amp;px=400" role="button" title="szymon_dybczak_1-1759435606247.png" alt="szymon_dybczak_1-1759435606247.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;And here'e a list of ACL you can set on notebooks:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/auth/access-control/#notebook" target="_blank"&gt;https://learn.microsoft.com/en-us/azure/databricks/security/auth/access-control/#notebook&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="szymon_dybczak_2-1759435703327.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/20352i9840A0A45BEA7E34/image-size/medium?v=v2&amp;amp;px=400" role="button" title="szymon_dybczak_2-1759435703327.png" alt="szymon_dybczak_2-1759435703327.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So to sum it up. In my opinion you can't accomplish what you want. Because ACL required to run notebook - &lt;STRONG&gt;CAN RUN&lt;/STRONG&gt; permission - already contains also CAN VIEW permission.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 20:10:08 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/folder-execute-permissions/m-p/133573#M49884</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2025-10-02T20:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: Folder execute permissions</title>
      <link>https://community.databricks.com/t5/data-engineering/folder-execute-permissions/m-p/133584#M49885</link>
      <description>&lt;P&gt;Thanks for your response. That's what I imagined although could not confirm as my current project uses Unity Catalog and we are not allowed to run many commands including ACL related PySpark code.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 20:34:35 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/folder-execute-permissions/m-p/133584#M49885</guid>
      <dc:creator>adrianhernandez</dc:creator>
      <dc:date>2025-10-02T20:34:35Z</dc:date>
    </item>
  </channel>
</rss>

