โ03-27-2025 06:49 AM
We have implemented SCIM Provisioning using Azure AD (MS Entra) to Azure Databricks.
All is good.
Except, we would like to know if it is possible to disable the ability to create users within Azure Databricks, so that none can be "accidentally" created?
Many thanks
โ04-30-2025 11:11 PM
To disable the ability to create users directly within Azure Databricks to prevent accidental user creation, you can configure your identity provider (IdP) setup.
When SCIM is in use, Azure AD becomes the source of truth for identities. Any users or groups that need access to Azure Databricks must be provisioned through Azure AD.
https://learn.microsoft.com/en-us/azure/databricks/admin/users-groups/scim/
โ05-01-2025 02:49 AM
Thanks for the reply, but this is what we are already doing. However it does not actually "disallow" the creation of users within Databricks itself, which is what we really want to achieve.
a week ago
Greetings @ThePussCat , I would like to add what my colleague posted above.
a week ago
Louis, Many thanks! I really appreciate this reply. However perhaps you could provide more info on this statement:
Databricks SSO setting: In each workspace, go to Admin settings > Authentication/SSO and disable the setting labeled โAuto user creation,โ โAdd users on first login,โ or similar wording.
I know the Databricks UI is forever changing, but I have looked around and cannot find anything that looks like what you describe.Is this perhaps a legacy setting that we have disabled?
Thanks again - I'll be talking to our MS Entra admin in the morning!
a week ago
Are you a workspace admin?
a week ago
I'm the Account Admin.
We try to avoid workspace specific configuration settings where we can, other than allowing some beta/preview on our DEV workspaces.
a week ago
Got it. I found a little more information that might help. Give this a read and let me know if it helps.
Wednesday
Thank you! Thats really clear now, and hopefully helpful to others.
Ours is set to (default) OFF - we do not want JIT provisioning enabled.
Passionate about hosting events and connecting people? Help us grow a vibrant local communityโsign up today to get started!
Sign Up Now