Unity Catalog Upgrade - Maximizing System Availability - Ideas
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-26-2023 02:26 AM
During UC upgrade, we are required to migrate to account groups from workspace local groups. We are unable to add an account group without first deleting first the workspace local group (as they both have the same name).
And, during this process, the permissions given to these groups on various objects like SQL Warehouses, all-purpose clusters are lost.
Is there a way to make the account groups & workspace local groups co-exist for some time so we can delete workspace local groups after we add account groups?
Two advantages of it –
• We don’t to spend say several minutes to re-apply lost permissions
• Platform/System is available for end users (they will be accessing legacy catalog at least)
- Labels:
-
Unity Catalog
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-26-2023 05:04 AM
Hi Kaniz,
Is it possible to just convert/flag workspace local groups in the workspace into account groups? I notice the workspace local groups have a flag against them called "Workspace local".
As we will have the same groups coming from account (via SCIM), if we could do the above conversion, then other alternatives like rename are not needed. And the permissions also will stay in tact.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-26-2023 05:41 AM
also, I realized we cannot even rename workspace local groups as they are coming from AAD for us.

