cancel
Showing results for 
Search instead for 
Did you mean: 
Administration & Architecture
Explore discussions on Databricks administration, deployment strategies, and architectural best practices. Connect with administrators and architects to optimize your Databricks environment for performance, scalability, and security.
cancel
Showing results for 
Search instead for 
Did you mean: 

How Can a Workspace Admin Grant Workspace Admin Permissions to a Group?

TakuyaOmi
Contributor III

I want to grant Workspace Admin permissions to a group instead of individual users, but I haven’t found a way to do this. I considered assigning permissions by adding the group to the Databricks-managed 'admins' group (establishing a parent-child relationship), but it seems there’s a restriction that only users or service principals can be added to the 'admins' group.

Is it only possible for the account admin to grant Workspace Admin permissions to a group via the Account Console?
Do you have any suggestions or better ideas? Thank you!

3 REPLIES 3

Alberto_Umana
Databricks Employee
Databricks Employee

Hi @TakuyaOmi,

It is not possible to add a group to the Databricks-managed 'admins' group directly. Only users or service principals can be added to the 'admins' group.

 

To grant Workspace Admin permissions to a group, the account admin must use the Account Console. Here are the steps you can follow:

  1. Log in to the Account Console: As an account admin, log in to the Databricks account console.
  2. Navigate to User Management: In the sidebar, click on "User management."
  3. Select Groups: Click on the "Groups" tab.
  4. Add Group: Click "Add Group" to create a new group or select an existing group.
  5. Assign Roles: Assign the Workspace Admin role to the group. This can be done by selecting the group and then assigning the appropriate roles.

Alternatively, you can manage group roles using the Accounts Access Control API if you prefer to automate this process

https://docs.databricks.com/en/admin/users-groups/groups.html

TakuyaOmi
Contributor III

@Alberto_Umana 

Thank you for your response.

I now understand that granting Workspace Admin permissions to a group can only be done by an Account Admin.

Do you know if there are any plans on the roadmap to enable Workspace Admins to assign permissions to groups in the future? This seems like an essential feature for customers who prefer decentralized management at the workspace level, rather than centralized control by an Account Admin.

Alberto_Umana
Databricks Employee
Databricks Employee

No problem! I will check internally if there is any feature request of this nature. You can use the "admins" group for adding admin users or SPs.

Connect with Databricks Users in Your Area

Join a Regional User Group to connect with local Databricks users. Events will be happening in your city, and you won’t want to miss the chance to attend and share knowledge.

If there isn’t a group near you, start one and help create a community that brings people together.

Request a New Group