cancel
Showing results for 
Search instead for 
Did you mean: 
Data Governance
Join discussions on data governance practices, compliance, and security within the Databricks Community. Exchange strategies and insights to ensure data integrity and regulatory compliance.
cancel
Showing results for 
Search instead for 
Did you mean: 

Unity Catalog Upgrade - Maximizing System Availability - Ideas

NOOR_BASHASHAIK
Contributor

During UC upgrade, we are required to migrate to account groups from workspace local groups. We are unable to add an account group without first deleting first the workspace local group (as they both have the same name).

And, during this process, the permissions given to these groups on various objects like SQL Warehouses, all-purpose clusters are lost.

Is there a way to make the account groups & workspace local groups co-exist for some time so we can delete workspace local groups after we add account groups?

Two advantages of it –

• We don’t to spend say several minutes to re-apply lost permissions
• Platform/System is available for end users (they will be accessing legacy catalog at least)

2 REPLIES 2

Hi Kaniz,

Is it possible to just convert/flag workspace local groups in the workspace into account groups? I notice the workspace local groups have a flag against them called "Workspace local".

As we will have the same groups coming from account (via SCIM), if we could do the above conversion, then other alternatives like rename are not needed. And the permissions also will stay in tact.

 

also, I realized we cannot even rename workspace local groups as they are coming from AAD for us.

Connect with Databricks Users in Your Area

Join a Regional User Group to connect with local Databricks users. Events will be happening in your city, and you won’t want to miss the chance to attend and share knowledge.

If there isn’t a group near you, start one and help create a community that brings people together.

Request a New Group