cancel
Showing results forย 
Search instead forย 
Did you mean:ย 
Administration & Architecture
Explore discussions on Databricks administration, deployment strategies, and architectural best practices. Connect with administrators and architects to optimize your Databricks environment for performance, scalability, and security.
cancel
Showing results forย 
Search instead forย 
Did you mean:ย 

How to disable storage account key access of workspace storage accounts?

Charuvil
New Contributor III

Each Azure Databricks workspace has an associated Azure storage account in a managed resource group known as the workspace storage account. The workspace storage account includes workspace system data (job output, system settings, and logs), DBFS root, and in some cases a Unity Catalog workspace catalog.

We noticed that these storage accounts have Storage account key access as Enabled by default. This is raising security concerns within our team. Is there any way to disable the storage account key access? Is Databricks using this key for any kind of authentication purpose? As far as I know Databricks discourage the use of keys and recommends to use managed identities for authentication.

3 REPLIES 3

Raman_Unifeye
Contributor III

@Charuvil - you've rightly observed. 

Databricks uses the Storage Account Access Key to authenticate the connection between the Databricks Control Plane and the Data Plane and you cannot simple disable it.

will love to see the alternate solution from the community.


RG #Driving Business Outcomes with Data Intelligence

nayan_wylde
Esteemed Contributor

Do not disable Storage account key access for the storage account backing the DBFS root. Disabling this setting leads to unexpected behaviors and errors. Moreover it is in Microsoft managed resource group. Any changes to it might require to raise a Microsoft support ticket. I have a recent experience. I wanted to calculate the size of one of the containers. I had to raise a Microsoft support ticket.

Charuvil
New Contributor III

Thank you @Raman_Unifeye  and @nayan_wylde  it helped