- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-04-2025 09:54 AM
You cannot create account-level groups in Databricks with Terraform unless your authentication mechanism has account admin privileges. This is a design limitation of both the Databricks API and Terraform provider, which require admin-level permissions for managing resources at the account scope, including account-level groups.
Key Points
-
Account-Level Group Creation: Only users or service principals with "account admin" privileges in Databricks can create or manage account-level groups via the API or Terraform provider. Workspace-level admin does not suffice.
-
UI vs API Behavior: The UI automatically escalates your permissions if you are an account admin, which is why it works there. Without account admin privileges, the API and Terraform will enforce stricter access controls and error out.
-
Azure AD Authentication Errors: The error you see (AADSTS50059, missing tenant-identifying info) is due to authentication failing for account-level admin APIs because your credentials lack the required scope.
-
Workspace vs Account Scope: Using the workspace-scoped provider only lets you create workspace-only groups, not reusable account-level groups.
Possible Workarounds
-
Service Account with Admin Privileges: If you require automation, you must perform group creation with a service principal or user configured as an account admin within Databricks.
-
Manual Creation: You can request your Databricks account admin to create the account-level group via the UI or API, then reference that group in workspace provisioning scripts or Terraform as needed.
-
RBAC Review: Some organizations can temporarily grant account admin privileges to service accounts for specific automation tasks, then revoke them after provisioning is complete.
Why the Restriction Exists
Databricks enforces this restriction for security reasons to prevent broad account-level changes by non-admins. Only account admins can manage entities shared between workspaces (groups, users, service principals) to safeguard cross-workspace governance.
Summary Table
| Method | Account Admin Required? | Scope Created |
|---|---|---|
| Databricks UI | Yes | Account-level |
| API (Terraform Provider) | Yes | Account-level |
| Workspace provider | No | Workspace-level |
Next Steps
To automate account-level group creation, ensure your automation identity is granted account admin rights in Databricks. Otherwise, delegate group creation to an existing admin or perform it manually via the UI.
If Databricks' permissions or API surfaces change in the future to allow delegated account-level group creation, review the Terraform provider documentation and Databricks release notes for updates.