<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure Databricks Enterprise Application User Impersonation Token Group Claims Issue in Get Started Discussions</title>
    <link>https://community.databricks.com/t5/get-started-discussions/azure-databricks-enterprise-application-user-impersonation-token/m-p/105110#M9480</link>
    <description>&lt;P&gt;I tried it like this, however it still adds group claims in the access token:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;export const getDatabricksToken = async () =&amp;gt; {
    const account = msalInstance.getActiveAccount();
    const response = await msalInstance.acquireTokenSilent({
        scopes: ["2ff814a6-3304-4ab8-85cb-cd0e6f879c1d/user_impersonation"],
        account: account,
        claims: JSON.stringify({
            "access_token": {
                "groups": null
            }
        })        
    })
    return response.accessToken
};&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jan 2025 05:54:41 GMT</pubDate>
    <dc:creator>ahsan_aj</dc:creator>
    <dc:date>2025-01-10T05:54:41Z</dc:date>
    <item>
      <title>Azure Databricks Enterprise Application User Impersonation Token Group Claims Issue</title>
      <link>https://community.databricks.com/t5/get-started-discussions/azure-databricks-enterprise-application-user-impersonation-token/m-p/91931#M9475</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;I am using the Azure Databricks Microsoft Managed Enterprise Application scope (2ff814a6-3304-4ab8-85cb-cd0e6f879c1d/user_impersonation) to fetch an access token on behalf of a user. The authentication process is successful; however, the access token includes group claims. For users who are part of many Azure AD groups, the token becomes quite large because it lists all the groups in the claims. How can I modify my request for the token to exclude group claims from the access token?&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;I am using the React MSAL library, and here’s a sample of the code I am working with:&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;export const getDatabricksToken = async () =&amp;gt; {
    const account = msalInstance.getActiveAccount();
    const response = await msalInstance.acquireTokenSilent({
        scopes: ["2ff814a6-3304-4ab8-85cb-cd0e6f879c1d/user_impersonation"],
        account: account,
    })
    return response.accessToken
};&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 16:10:20 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/azure-databricks-enterprise-application-user-impersonation-token/m-p/91931#M9475</guid>
      <dc:creator>ahsan_aj</dc:creator>
      <dc:date>2024-09-26T16:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Databricks Enterprise Application User Impersonation Token Group Claims Issue</title>
      <link>https://community.databricks.com/t5/get-started-discussions/azure-databricks-enterprise-application-user-impersonation-token/m-p/105069#M9476</link>
      <description>&lt;P&gt;Hi, did you find an answer for it?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 19:14:10 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/azure-databricks-enterprise-application-user-impersonation-token/m-p/105069#M9476</guid>
      <dc:creator>skraszki</dc:creator>
      <dc:date>2025-01-09T19:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Databricks Enterprise Application User Impersonation Token Group Claims Issue</title>
      <link>https://community.databricks.com/t5/get-started-discussions/azure-databricks-enterprise-application-user-impersonation-token/m-p/105071#M9477</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/95317"&gt;@ahsan_aj&lt;/a&gt;,&lt;/P&gt;
&lt;P class="p1"&gt;You can modify your token request by adding a claims parameter&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;const claimsRequest = {&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;"access_token": {&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;"groups": null&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;}&lt;/P&gt;
&lt;P class="p1"&gt;&lt;A href="https://learn.microsoft.com/en-us/security/zero-trust/develop/configure-tokens-group-claims-app-roles" target="_blank"&gt;https://learn.microsoft.com/en-us/security/zero-trust/develop/configure-tokens-group-claims-app-roles&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 19:55:07 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/azure-databricks-enterprise-application-user-impersonation-token/m-p/105071#M9477</guid>
      <dc:creator>Alberto_Umana</dc:creator>
      <dc:date>2025-01-09T19:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Databricks Enterprise Application User Impersonation Token Group Claims Issue</title>
      <link>https://community.databricks.com/t5/get-started-discussions/azure-databricks-enterprise-application-user-impersonation-token/m-p/105108#M9478</link>
      <description>&lt;P&gt;I got in touch with Microsoft support and they mentioned it is not possible as the Azure Databricks app registration is managed by Databricks and changing the manifest to exclude group claims on that application is not possible and it impacts all users.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 05:39:01 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/azure-databricks-enterprise-application-user-impersonation-token/m-p/105108#M9478</guid>
      <dc:creator>ahsan_aj</dc:creator>
      <dc:date>2025-01-10T05:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Databricks Enterprise Application User Impersonation Token Group Claims Issue</title>
      <link>https://community.databricks.com/t5/get-started-discussions/azure-databricks-enterprise-application-user-impersonation-token/m-p/105109#M9479</link>
      <description>&lt;P&gt;Let me try this and get back to you.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 05:39:15 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/azure-databricks-enterprise-application-user-impersonation-token/m-p/105109#M9479</guid>
      <dc:creator>ahsan_aj</dc:creator>
      <dc:date>2025-01-10T05:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Databricks Enterprise Application User Impersonation Token Group Claims Issue</title>
      <link>https://community.databricks.com/t5/get-started-discussions/azure-databricks-enterprise-application-user-impersonation-token/m-p/105110#M9480</link>
      <description>&lt;P&gt;I tried it like this, however it still adds group claims in the access token:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;export const getDatabricksToken = async () =&amp;gt; {
    const account = msalInstance.getActiveAccount();
    const response = await msalInstance.acquireTokenSilent({
        scopes: ["2ff814a6-3304-4ab8-85cb-cd0e6f879c1d/user_impersonation"],
        account: account,
        claims: JSON.stringify({
            "access_token": {
                "groups": null
            }
        })        
    })
    return response.accessToken
};&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 05:54:41 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/azure-databricks-enterprise-application-user-impersonation-token/m-p/105110#M9480</guid>
      <dc:creator>ahsan_aj</dc:creator>
      <dc:date>2025-01-10T05:54:41Z</dc:date>
    </item>
  </channel>
</rss>

