Hi @AnandGNR ,

My understanding based on above error was your org has a policy: "Private endpoint must be configured for Key Vault" with effect deny. When Databricks tries to programmatically grant its SP Get/List on your vault during scope creation, Azure Policy intercepts that ARM call and blocks it because the vault modification is being initiated outside the private endpoint path.

The ball is in your Azure Policy admin's court. The Databricks control plane has no way to route its ARM calls through a private endpoint.

This is purely my understanding , please talk to you Azure policy Admin @AnandGNR .

 

 

LR