<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Serverless Compute – ADLS Gen2 Authorization Failure with RBAC in Data Engineering</title>
    <link>https://community.databricks.com/t5/data-engineering/serverless-compute-adls-gen2-authorization-failure-with-rbac/m-p/140879#M51557</link>
    <description>&lt;P&gt;&lt;SPAN&gt;We are facing an authorization issue when using &lt;STRONG&gt;serverless compute&lt;/STRONG&gt; with ADLS Gen2 storage. Queries fail with:&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Code&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;PRE&gt;AbfsRestOperationException: Operation failed: "This request is not authorized to perform this operation.", 403 AuthorizationFailure&lt;/PRE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Details:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt; Azure Databricks with Unity Catalog enabled&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Storage:&lt;/STRONG&gt; ADLS Gen2, external location configured&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Authentication:&lt;/STRONG&gt; Unity Catalog storage credential using Service Principal (not SAS token)&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;RBAC:&lt;/STRONG&gt; Service Principal has &lt;STRONG&gt;Storage Blob Data Contributor&lt;/STRONG&gt; role at the storage account level&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Behavior:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Queries succeed when using &lt;STRONG&gt;general purpose compute clusters&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Queries fail with 403 when using &lt;STRONG&gt;serverless compute&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Steps Tried:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Verified RBAC role assignment at both account and container level.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Confirmed external location is bound to the storage credential.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Granted usage on external location to UC groups.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Tested access via CLI with the same Service Principal — works fine.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Request for Help:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Are there additional RBAC permissions or workspace entitlements required for &lt;STRONG&gt;serverless compute&lt;/STRONG&gt; to access ADLS Gen2?&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Does serverless compute require a different configuration for Unity Catalog storage credentials compared to general compute?&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Impact:&lt;/STRONG&gt; We are currently using general compute clusters as a workaround, but need serverless compute enabled for production workloads.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Dec 2025 14:41:24 GMT</pubDate>
    <dc:creator>Charansai</dc:creator>
    <dc:date>2025-12-02T14:41:24Z</dc:date>
    <item>
      <title>Serverless Compute – ADLS Gen2 Authorization Failure with RBAC</title>
      <link>https://community.databricks.com/t5/data-engineering/serverless-compute-adls-gen2-authorization-failure-with-rbac/m-p/140879#M51557</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We are facing an authorization issue when using &lt;STRONG&gt;serverless compute&lt;/STRONG&gt; with ADLS Gen2 storage. Queries fail with:&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Code&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;PRE&gt;AbfsRestOperationException: Operation failed: "This request is not authorized to perform this operation.", 403 AuthorizationFailure&lt;/PRE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Details:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt; Azure Databricks with Unity Catalog enabled&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Storage:&lt;/STRONG&gt; ADLS Gen2, external location configured&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Authentication:&lt;/STRONG&gt; Unity Catalog storage credential using Service Principal (not SAS token)&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;RBAC:&lt;/STRONG&gt; Service Principal has &lt;STRONG&gt;Storage Blob Data Contributor&lt;/STRONG&gt; role at the storage account level&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Behavior:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Queries succeed when using &lt;STRONG&gt;general purpose compute clusters&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Queries fail with 403 when using &lt;STRONG&gt;serverless compute&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Steps Tried:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Verified RBAC role assignment at both account and container level.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Confirmed external location is bound to the storage credential.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Granted usage on external location to UC groups.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Tested access via CLI with the same Service Principal — works fine.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Request for Help:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Are there additional RBAC permissions or workspace entitlements required for &lt;STRONG&gt;serverless compute&lt;/STRONG&gt; to access ADLS Gen2?&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Does serverless compute require a different configuration for Unity Catalog storage credentials compared to general compute?&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Impact:&lt;/STRONG&gt; We are currently using general compute clusters as a workaround, but need serverless compute enabled for production workloads.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 14:41:24 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/serverless-compute-adls-gen2-authorization-failure-with-rbac/m-p/140879#M51557</guid>
      <dc:creator>Charansai</dc:creator>
      <dc:date>2025-12-02T14:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: Serverless Compute – ADLS Gen2 Authorization Failure with RBAC</title>
      <link>https://community.databricks.com/t5/data-engineering/serverless-compute-adls-gen2-authorization-failure-with-rbac/m-p/140882#M51559</link>
      <description>&lt;P&gt;private link from serverless, as probably you are not allowing public internet access.&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-gb/azure/databricks/security/network/serverless-network-security/serverless-private-link" target="_blank"&gt;Configure private connectivity to Azure resources - Azure Databricks | Microsoft Learn&lt;/A&gt;&amp;nbsp;you need to add both dfs and blob&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 14:50:49 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/serverless-compute-adls-gen2-authorization-failure-with-rbac/m-p/140882#M51559</guid>
      <dc:creator>Hubert-Dudek</dc:creator>
      <dc:date>2025-12-02T14:50:49Z</dc:date>
    </item>
  </channel>
</rss>

