cancel
Showing results forย 
Search instead forย 
Did you mean:ย 
Administration & Architecture
Explore discussions on Databricks administration, deployment strategies, and architectural best practices. Connect with administrators and architects to optimize your Databricks environment for performance, scalability, and security.
cancel
Showing results forย 
Search instead forย 
Did you mean:ย 

Change default workspace access to Consumer access

Raman_Unifeye
Contributor III

When Databricks One was launched, the default behaviour of the system-managed users group was a major issue. Since every new user is automatically added to users group, and that group traditionally came with "Workspace Access" entitlements, admins had to manually strip permissions downgrade people to the Consumer access only.

Databricks has now acknowledged this messy workaround and released the Group Cloning feature specifically to solve the "Author vs. Consumer" split.

Admins can now set Consumer access as the default for new users by using the 'group cloning' tool. This transition migrates current authors to a new group while restricting the default users group to a view-only experience in Databricks One. New users will automatically receive a simplified interface for dashboards and apps, safeguarding workspace integrity without disrupting current workflows.

Databricks Official Documentation - https://docs.databricks.com/aws/en/security/auth/change-default-workspace-access

So What?? :

  • Security by Default:Now it is following a "Least Privilege" model. Users must be promoted to an Author group to build things, rather than being demoted after they've already seen the technical "guts" of the platform.
  • Onboarding at Scale: Now one can add 100s business users at once without worrying about them accidentally spinning up expensive clusters or cluttering the workspace.

 

I just used this in our all workspaces and its very neat!!!!

 


RG #Driving Business Outcomes with Data Intelligence
0 REPLIES 0