Share notebooks with a AD-user assigned via group
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-24-2025 08:26 AM - edited 07-24-2025 08:53 AM
Hi everybody,
I try to share a notebook with a user that was assigned to the workspace via a AD-Group (using the new automatic sync). But I only see users directly assigned to the workspace.
My expectation would be that I see all users that are within the AD group as those are also added to the workspace as users. Or do I have to assign all of the AD-Users as users to the workspace as well? That would kind of destroy the usage and concept of groups.
When setting permissions on the Unity Catalog all the users in the AD group are there. The problem only occurs with notebooks/workspace objects
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-24-2025 09:46 AM
Key Points
-
AD Group Membership: When users are assigned to a workspace through an AD group, they should automatically have access to certain resources, including Unity Catalog objects. However, for notebooks and other workspace objects, it appears that only users directly assigned to the workspace are recognized when sharing.
-
Current Behavior: The observed behavior you described, where you can see users directly assigned to the workspace but not those in AD groups, is consistent with how Azure Databricks manages permissions for notebooks and workspace objects. This can be confusing and feels counter to the concept of AD groups.
-
Unity Catalog vs. Notebooks: The difference in visibility and permission settings can be attributed to the distinct ways Azure Databricks integrates with Microsoft Entra ID for Unity Catalog versus workspace objects. While AD group members can access data in Unity Catalog without being individually added to the workspace, this does not carry over to notebook sharing.
Recommendations
-
User Assignment: Unfortunately, if you want to share notebooks with all users in an AD group, you may need to assign those users directly to the workspace. This does feel like a breakdown in leveraging AD groups effectively, but it currently aligns with the specified architecture of Azure Databricks.
-
Look for Updates: Keep an eye on updates from Azure Databricks, particularly around automatic identity management. Features and functionalities evolve, and future enhancements may address this limitation.
Conclusion
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-24-2025 11:21 PM
Thank you for this llm-generated non-answer.
It just takes what I have said and puts an "may need" and other phrases to it. Without make clear statements or even linking to a source in the documentation that I might have missed.
Can you confirm that my observation is the way things currently work with permissions in the workspace? what is the reason for this limitation? and are there specific plans to work on it? If you don't know its just fine, just don't please put out an generated answer.
Thank you 🙂