cancel
Showing results forย 
Search instead forย 
Did you mean:ย 
Administration & Architecture
Explore discussions on Databricks administration, deployment strategies, and architectural best practices. Connect with administrators and architects to optimize your Databricks environment for performance, scalability, and security.
cancel
Showing results forย 
Search instead forย 
Did you mean:ย 

Security Consideration for OAUTH Secrets to use Service Principal to authenticate with Databricks

VJ3
New Contributor III

What are the security consideration we need to keep in mind when we want to us OAUTH Secrets to use a Service Principal to access Azure Databricks when Identity federation is disabled and workspace is not yet on boarded on to Unity Catalog?

 

Can we consider OAUTH secret similar to Personal Access Token?

 

What is time limit when OAUTH secrets expires?

 

How do we get new OAUTH secrets?

 

Can we use Azure Key Vault to store the OAUTH secrets?

 

What is the workflow we use in OAUTH for authentication? Do we use Implicit grant workflow in OAUTH?

 

Do we store secret in .databrickscfg?

 

Who has access to .databrickscfg?

 

How do we ensure that OAUTH secret is stored safely and encrypted using AES256 and higher encryption?

 

https://learn.microsoft.com/en-us/azure/databricks/dev-tools/auth/oauth-m2m

 

Regards,

 

VJ

1 REPLY 1

VJ3
New Contributor III

Thank you @Retired_mod for the response. I do have follow up questions.

- What kind of encryption is used to store OAUTH secret?

-  Is there any way OAUTH can be generated by someone else who is not a manager of that SPN? We need this as a part of segregation of duty

- Can we use OAUTH secret for non M2M authentication? 

- What is the purpose of .databrickscfg file? Can we avoid using it as someone can store Secret in plain text?

- Can we create multiple OAUTH Secret for single SPN?

Connect with Databricks Users in Your Area

Join a Regional User Group to connect with local Databricks users. Events will be happening in your city, and you wonโ€™t want to miss the chance to attend and share knowledge.

If there isnโ€™t a group near you, start one and help create a community that brings people together.

Request a New Group