cancel
Showing results for 
Search instead for 
Did you mean: 
Administration & Architecture
Explore discussions on Databricks administration, deployment strategies, and architectural best practices. Connect with administrators and architects to optimize your Databricks environment for performance, scalability, and security.
cancel
Showing results for 
Search instead for 
Did you mean: 

Disable 'Allow trusted Microsoft services to bypass this firewall' for Azure Key Vault

rdadhichi
New Contributor II

Currently even when using vnet injected Databricks workspace, we are unable to fetch the secrets from AKV if the 'Allow trusted Microsoft services to bypass this firewall' is disabled.
The secret is used a AKV backed secret scope and the key vault is private (public access disabled).

Our security requirement is to disable this and use private endpoints only. We have tried a few things like :
1. NCC configuration to create a private endpoint from databricks to key vault

2. Verifying the dns entries and nslookup from the notebook gives the correct private ip of the kv

Is this a limitation as we could not find any documentation that would help us disabling this without breaking things.
Official troubleshooting doc also asks to keep this enabled
Troubleshooting 403 



2 REPLIES 2

Alberto_Umana
Databricks Employee
Databricks Employee

Hi @rdadhichi,

Have you set "Allow access from" to "Private endpoint and selected networks" on the firewall?

There are no such settings.

We have Disabled Public access . 
We have Private endpoints created for the KV in the same vnet and can do a successfull nslookup from a notebook in our workspace


Our requirement is to dsable the exception : ' Allow Trusted services....'

Please let me know if this is possible or not

rdadhichi_0-1737468820054.png

 

Connect with Databricks Users in Your Area

Join a Regional User Group to connect with local Databricks users. Events will be happening in your city, and you won’t want to miss the chance to attend and share knowledge.

If there isn’t a group near you, start one and help create a community that brings people together.

Request a New Group