Service Principal can be deleted but permissions not managed
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-23-2024 08:28 AM
On Azure I added a service principal X to my databricks workspace. I therefore had the Service Prinicpal Manager role on that service principal X. I accidentally downgraded my rights to Service Principal User and now can's get my Managers role back. I am an workspace admin and can delete the service principal entry X. If I add the just deleted service principal X again, I will only receive the Service Principal User role, not the Manager role.
If I create any new service prinicpal Y with a syntactically valid app-id I will receive the Service Principal Manager role for Y.
This seems inconsistent, since I can delete it but not manage it. How can I reclaim my Service Managers role back?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-23-2024 09:57 AM - edited 02-23-2024 10:02 AM
Do you have federated identity enabled on your workspace?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-27-2024 07:58 AM
I believe so because the described effect was also observed in another databricks workspace, where I did NOT make the accidental change
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-27-2024 08:06 AM
Also note, I am only a workspace admin, and do not have access to the account console