<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Retrieve Masked Column Information in Unity Catalog in Data Governance</title>
    <link>https://community.databricks.com/t5/data-governance/how-to-retrieve-masked-column-information-in-unity-catalog/m-p/121178#M2498</link>
    <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/105086"&gt;@jv_v&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;There are a few more approaches that you can try which are ideal for large scale scanning,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try using, Unity Catalog System Tables via system.information_schema Instead of &amp;lt;catalog&amp;gt;.information_schema.column_masks&lt;/P&gt;&lt;P&gt;If that doesnt work, use Databricks REST API,&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;GET&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;/api/2.1/unity-catalog/tables/{full_name}&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Reference.:&amp;nbsp;&lt;A href="https://docs.databricks.com/api/workspace/tables/get" target="_blank" rel="noopener"&gt;Get a table | Tables API | REST API reference | Databricks on AWS&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="niteshm_1-1749279819618.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/17397i687FF125CBDA2094/image-size/medium?v=v2&amp;amp;px=400" role="button" title="niteshm_1-1749279819618.png" alt="niteshm_1-1749279819618.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 07 Jun 2025 07:08:03 GMT</pubDate>
    <dc:creator>niteshm</dc:creator>
    <dc:date>2025-06-07T07:08:03Z</dc:date>
    <item>
      <title>How to Retrieve Masked Column Information in Unity Catalog</title>
      <link>https://community.databricks.com/t5/data-governance/how-to-retrieve-masked-column-information-in-unity-catalog/m-p/121048#M2496</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I’ve been working with Unity Catalog in Databricks and using &lt;STRONG&gt;column masking policies&lt;/STRONG&gt; for sensitive fields like SSNs. While trying to retrieve metadata about which columns have masking policies applied, I ran into some challenges and wanted to share my findings + get input from the community.&lt;/P&gt;&lt;H4&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; Tried Approaches&lt;/H4&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;DESCRIBE EXTENDED &amp;lt;table&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;This shows masking policies applied on individual columns under the "Comment" or "Metadata" fields — but it’s not structured and hard to automate for large-scale scans.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;catalog&amp;gt;.information_schema.column_masks&lt;/STRONG&gt;&lt;BR /&gt;Surprisingly, this view is &lt;STRONG&gt;empty&lt;/STRONG&gt; in some client environments — even when I know masking policies are in place and functional. I'm assuming it could be due to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Delayed metadata sync&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Lack of permissions&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Feature not fully available in that workspace&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;H4&gt;&lt;span class="lia-unicode-emoji" title=":question_mark:"&gt;❓&lt;/span&gt; Looking for a Better Way&lt;/H4&gt;&lt;P&gt;Aside from DESCRIBE EXTENDED and the &lt;FONT face="DM Mono, Consolas, monospace" color="#c7254e"&gt;&lt;SPAN&gt;information schema&lt;/SPAN&gt;&lt;/FONT&gt;&amp;nbsp;view:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Is there a more reliable way to programmatically retrieve which columns have masking policies applied?&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Does anyone have experience using &lt;STRONG&gt;Databricks REST API&lt;/STRONG&gt;?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Any internal Unity Catalog system tables or best practices for scanning a catalog/schema and reporting masked fields?&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Would appreciate any guidance, alternate approaches, or scripts you’ve found useful in your projects.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;BR /&gt;—Vyshnavi&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jun 2025 12:55:07 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/how-to-retrieve-masked-column-information-in-unity-catalog/m-p/121048#M2496</guid>
      <dc:creator>jv_v</dc:creator>
      <dc:date>2025-06-05T12:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to Retrieve Masked Column Information in Unity Catalog</title>
      <link>https://community.databricks.com/t5/data-governance/how-to-retrieve-masked-column-information-in-unity-catalog/m-p/121178#M2498</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/105086"&gt;@jv_v&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;There are a few more approaches that you can try which are ideal for large scale scanning,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try using, Unity Catalog System Tables via system.information_schema Instead of &amp;lt;catalog&amp;gt;.information_schema.column_masks&lt;/P&gt;&lt;P&gt;If that doesnt work, use Databricks REST API,&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;GET&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;/api/2.1/unity-catalog/tables/{full_name}&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Reference.:&amp;nbsp;&lt;A href="https://docs.databricks.com/api/workspace/tables/get" target="_blank" rel="noopener"&gt;Get a table | Tables API | REST API reference | Databricks on AWS&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="niteshm_1-1749279819618.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/17397i687FF125CBDA2094/image-size/medium?v=v2&amp;amp;px=400" role="button" title="niteshm_1-1749279819618.png" alt="niteshm_1-1749279819618.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jun 2025 07:08:03 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/how-to-retrieve-masked-column-information-in-unity-catalog/m-p/121178#M2498</guid>
      <dc:creator>niteshm</dc:creator>
      <dc:date>2025-06-07T07:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to Retrieve Masked Column Information in Unity Catalog</title>
      <link>https://community.databricks.com/t5/data-governance/how-to-retrieve-masked-column-information-in-unity-catalog/m-p/169437#M2999</link>
      <description>&lt;P&gt;To build on what &lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/91792"&gt;@niteshm&lt;/a&gt; said - the reason &amp;lt;catalog&amp;gt;.information_schema.column_masks came back empty for you is almost certainly not sync delay or permissions, it's the query scope. Per-catalog information_schema only reflects masks defined within that catalog's own metastore context. Query it from the SYSTEM catalog instead:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SELECT * FROM system.information_schema.column_masks WHERE catalog_name = '&amp;lt;your_catalog&amp;gt;'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's the documented, cross-catalog view and it's the one that's actually reliable for scanning at scale.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One more thing worth checking if that still comes back empty: are your masks applied via ABAC policies (governed tags, catalog/schema-level policies that apply automatically) rather than manual UDF assignment directly on the column? Databricks has two distinct mechanisms now - manual column mask UDFs bound per-column, and newer ABAC policies that apply based on tags across whole catalogs/schemas. column_masks reflects the manual per-column bindings; if your masking is coming from an ABAC policy, it won't show up there at all, since it's not a per-column assignment in the same sense. For that case you'd want to enumerate policies directly - DESCRIBE POLICY on a specific table/policy shows the details, and it's worth checking your workspace's ABAC policies documentation for how to list all active policies rather than assuming column_masks is exhaustive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the practical order I'd check in: query system.information_schema.column_masks (not the catalog-scoped one) first, and if it's still empty despite known masking, that's a strong signal you're on ABAC-based masking rather than direct UDF assignment and need the policy-listing path instead.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 13:19:27 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/how-to-retrieve-masked-column-information-in-unity-catalog/m-p/169437#M2999</guid>
      <dc:creator>DoTA</dc:creator>
      <dc:date>2026-09-22T13:19:27Z</dc:date>
    </item>
  </channel>
</rss>

