<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Unity catalog grant the access to a file inside azure datalake storage? in Data Engineering</title>
    <link>https://community.databricks.com/t5/data-engineering/can-unity-catalog-grant-the-access-to-a-file-inside-azure/m-p/11561#M6509</link>
    <description>&lt;P&gt;As @werners said service principal needs to have access to the file level.&lt;/P&gt;&lt;P&gt;In the unity catalog, you can use "READ FILES"/"WRITE FILES" permission to give someone the possibility of reading files from the storage level (but through databricks).&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jan 2023 20:31:18 GMT</pubDate>
    <dc:creator>Hubert-Dudek</dc:creator>
    <dc:date>2023-01-17T20:31:18Z</dc:date>
    <item>
      <title>Can Unity catalog grant the access to a file inside azure datalake storage?</title>
      <link>https://community.databricks.com/t5/data-engineering/can-unity-catalog-grant-the-access-to-a-file-inside-azure/m-p/11559#M6507</link>
      <description>&lt;P&gt;Hi databricks community,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have searched quite a while through the internet but did not find an answer. If I have configured the azure datalake connection in Unity data catalog, is it possible to grant the access to users for a specific file or a folder to them? Have seen quite a lot of examples so far for the structured data only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 14:42:45 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/can-unity-catalog-grant-the-access-to-a-file-inside-azure/m-p/11559#M6507</guid>
      <dc:creator>maaaxx</dc:creator>
      <dc:date>2023-01-17T14:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: Can Unity catalog grant the access to a file inside azure datalake storage?</title>
      <link>https://community.databricks.com/t5/data-engineering/can-unity-catalog-grant-the-access-to-a-file-inside-azure/m-p/11560#M6508</link>
      <description>&lt;P&gt;No.&lt;/P&gt;&lt;P&gt;Unity catalog enforces permissions on the table level (and catalog and schema etc), but not on the storage level.&lt;/P&gt;&lt;P&gt;Unity itself uses a managed identity or service principal for storage access btw.  This id should have access to the data lake.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you can do is create dynamic views to make a row-level security setup.&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/data-governance/table-acls/object-privileges#row-level-permissions" target="test_blank"&gt;https://learn.microsoft.com/en-us/azure/databricks/data-governance/table-acls/object-privileges#row-level-permissions&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 15:20:56 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/can-unity-catalog-grant-the-access-to-a-file-inside-azure/m-p/11560#M6508</guid>
      <dc:creator>-werners-</dc:creator>
      <dc:date>2023-01-17T15:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can Unity catalog grant the access to a file inside azure datalake storage?</title>
      <link>https://community.databricks.com/t5/data-engineering/can-unity-catalog-grant-the-access-to-a-file-inside-azure/m-p/11561#M6509</link>
      <description>&lt;P&gt;As @werners said service principal needs to have access to the file level.&lt;/P&gt;&lt;P&gt;In the unity catalog, you can use "READ FILES"/"WRITE FILES" permission to give someone the possibility of reading files from the storage level (but through databricks).&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 20:31:18 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/can-unity-catalog-grant-the-access-to-a-file-inside-azure/m-p/11561#M6509</guid>
      <dc:creator>Hubert-Dudek</dc:creator>
      <dc:date>2023-01-17T20:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can Unity catalog grant the access to a file inside azure datalake storage?</title>
      <link>https://community.databricks.com/t5/data-engineering/can-unity-catalog-grant-the-access-to-a-file-inside-azure/m-p/11562#M6510</link>
      <description>&lt;P&gt;Hi @Hubert Dudek​&amp;nbsp;@Werner Stinckens​&amp;nbsp;, thank you for the idea. In our scenario, we would need to share the files inside the azure datalake in the same folder.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Imagine that we have a folder ORDER001 and file1, file2 and file3. Can we use databricks to share the access to user A the access of file1 and file2 but for user B the access to file3?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some people have suggested to copy the files outside and create separate container. However, this will unavoidably create duplication and we would like to avoid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you an idea how the acsess control in this scenario could be achieve through databricks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 11:26:04 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/can-unity-catalog-grant-the-access-to-a-file-inside-azure/m-p/11562#M6510</guid>
      <dc:creator>maaaxx</dc:creator>
      <dc:date>2023-01-26T11:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can Unity catalog grant the access to a file inside azure datalake storage?</title>
      <link>https://community.databricks.com/t5/data-engineering/can-unity-catalog-grant-the-access-to-a-file-inside-azure/m-p/11563#M6511</link>
      <description>&lt;P&gt;It is messy as:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Files are in the same folder (so it complicates using an external location and read-write permission)&lt;/LI&gt;&lt;LI&gt;Unity Catalog is designed to have tables, and you grant access to tables&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know what the files are. Unstructured data can be included in the delta file / metastore table (array or binary).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also put these files outside of databricks and manage access separately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@Werner Stinckens,​&amp;nbsp;is it possible to have Unity Catalog and mount another storage container under the dbfs path using credentials passthrough?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 17:08:05 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/can-unity-catalog-grant-the-access-to-a-file-inside-azure/m-p/11563#M6511</guid>
      <dc:creator>Hubert-Dudek</dc:creator>
      <dc:date>2023-01-26T17:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Can Unity catalog grant the access to a file inside azure datalake storage?</title>
      <link>https://community.databricks.com/t5/data-engineering/can-unity-catalog-grant-the-access-to-a-file-inside-azure/m-p/11564#M6512</link>
      <description>&lt;P&gt;I am not sure.  Someone at Databricks once told me that mounts and Unity are not friends.&lt;/P&gt;&lt;P&gt;The easiest way to achieve this on file level is either:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;not using Unity and use AAD credential passtrough.  then define the file access with ACLs on the data lake.&lt;/LI&gt;&lt;LI&gt;forget about the file access and use dynamic views f.e. to create row level security.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frankly using ACLs always gets on my nerves.  Hard to maintain.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 09:05:56 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/can-unity-catalog-grant-the-access-to-a-file-inside-azure/m-p/11564#M6512</guid>
      <dc:creator>-werners-</dc:creator>
      <dc:date>2023-01-27T09:05:56Z</dc:date>
    </item>
  </channel>
</rss>

