<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot downgrade workspace object permissions using API in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/cannot-downgrade-workspace-object-permissions-using-api/m-p/98996#M2318</link>
    <description>&lt;P&gt;Hello Alberto,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to disable user access to their folders in our production workspace via API, or maybe limit to can_read.&amp;nbsp; When I do I get a similar message as the posting above. By default users receive the can_manage for their folders. Is there any other way to do lock down these folders? Users are created automatically via AD Groups, so it has to be done programmatically.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be grately appreciated!&lt;/P&gt;</description>
    <pubDate>Fri, 15 Nov 2024 21:37:16 GMT</pubDate>
    <dc:creator>alexzet</dc:creator>
    <dc:date>2024-11-15T21:37:16Z</dc:date>
    <item>
      <title>Cannot downgrade workspace object permissions using API</title>
      <link>https://community.databricks.com/t5/administration-architecture/cannot-downgrade-workspace-object-permissions-using-api/m-p/97999#M2244</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;I'd like to restrict some users' permissions using REST API and got an issue while trying to update a permission on 'directories'.&lt;/P&gt;&lt;P&gt;I'm trying to set a user's permission on their default username folder in the workspace to 'can edit' so that they cannot create a new notebook until further approval. This works fine on UI, but if I try with API I get the following error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{'error_code': 'INVALID_PARAMETER_VALUE', 'message': "Cannot downgrade xxx@abc.com's CAN_MANAGE permission on xxxxxxxxxx"}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way to make this work programmaticaly?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 16:49:43 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/cannot-downgrade-workspace-object-permissions-using-api/m-p/97999#M2244</guid>
      <dc:creator>takak</dc:creator>
      <dc:date>2024-11-06T16:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot downgrade workspace object permissions using API</title>
      <link>https://community.databricks.com/t5/administration-architecture/cannot-downgrade-workspace-object-permissions-using-api/m-p/98007#M2245</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/131364"&gt;@takak&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Greetings from Databricks!&lt;/P&gt;
&lt;P&gt;What is the REST API you are making the call to?&lt;/P&gt;
&lt;P&gt;Looks like this might not be supported programmatically, but will try to test it internally.&amp;nbsp;it appears that the &lt;CODE&gt;CAN_MANAGE&lt;/CODE&gt; permission is a higher-level permission that cannot be downgraded programmatically through the API. This restriction is likely in place to prevent accidental loss of critical management permissions.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 18:52:07 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/cannot-downgrade-workspace-object-permissions-using-api/m-p/98007#M2245</guid>
      <dc:creator>Alberto_Umana</dc:creator>
      <dc:date>2024-11-06T18:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot downgrade workspace object permissions using API</title>
      <link>https://community.databricks.com/t5/administration-architecture/cannot-downgrade-workspace-object-permissions-using-api/m-p/98031#M2247</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/106294"&gt;@Alberto_Umana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response!&lt;/P&gt;&lt;P&gt;The endpoint I'm calling is `&lt;SPAN&gt;/api/2.0/permissions/{workspace_object_type}/{workspace_object_id}`.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It would be great if it can be tested indeed, thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 04:35:08 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/cannot-downgrade-workspace-object-permissions-using-api/m-p/98031#M2247</guid>
      <dc:creator>takak</dc:creator>
      <dc:date>2024-11-07T04:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot downgrade workspace object permissions using API</title>
      <link>https://community.databricks.com/t5/administration-architecture/cannot-downgrade-workspace-object-permissions-using-api/m-p/98996#M2318</link>
      <description>&lt;P&gt;Hello Alberto,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to disable user access to their folders in our production workspace via API, or maybe limit to can_read.&amp;nbsp; When I do I get a similar message as the posting above. By default users receive the can_manage for their folders. Is there any other way to do lock down these folders? Users are created automatically via AD Groups, so it has to be done programmatically.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be grately appreciated!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 21:37:16 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/cannot-downgrade-workspace-object-permissions-using-api/m-p/98996#M2318</guid>
      <dc:creator>alexzet</dc:creator>
      <dc:date>2024-11-15T21:37:16Z</dc:date>
    </item>
  </channel>
</rss>

