<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic OAuth M2M (client-credentials) - getting error with github run in Data Engineering</title>
    <link>https://community.databricks.com/t5/data-engineering/oauth-m2m-client-credentials-getting-error-with-github-run/m-p/168294#M55880</link>
    <description>&lt;P&gt;I'm setting up OAuth M2M (client-credentials) authentication for a service principal, as the long-term replacement for PAT-based auth in a GitHub Actions CI/CD workflow. The token exchange itself succeeds and returns a valid, well-formed access token — but every subsequent API call made with that token, regardless of endpoint, fails with:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;{"error_code": 403, "message": "should_change_password [ReqId: ...]"}&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have not been able to find this error documented anywhere for a service-principal token (service principals don't have passwords), so I'm hoping someone here has hit this before.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Steps to reproduce&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Generate an OAuth secret for the service principal via &lt;STRONG&gt;Settings → Identity and access → Service principals → (your SP) → Secrets tab → Generate secret&lt;/STRONG&gt; (scope: all APIs).&lt;/LI&gt;&lt;LI&gt;Exchange for a token:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;curl -X POST https://&amp;lt;workspace-host&amp;gt;/oidc/v1/token \&lt;BR /&gt;&amp;nbsp; -u "&amp;lt;client_id&amp;gt;:&amp;lt;client_secret&amp;gt;" \&lt;BR /&gt;&amp;nbsp; -d "grant_type=client_credentials" \&lt;BR /&gt;&amp;nbsp; -d "scope=all-apis"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;→ Returns a valid &lt;SPAN&gt;access_token&lt;/SPAN&gt;, &lt;SPAN&gt;token_type: Bearer&lt;/SPAN&gt;, &lt;SPAN&gt;expires_in: 3600&lt;/SPAN&gt;. No errors at this step.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Use that token against any API, e.g.:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;curl -X GET https://&amp;lt;workspace-host&amp;gt;/api/2.0/preview/scim/v2/Me \&lt;BR /&gt;&amp;nbsp; -H "Authorization: Bearer &amp;lt;access_token&amp;gt;"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;→ Returns &lt;SPAN&gt;403 should_change_password&lt;/SPAN&gt;.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Same result reproduced independently against:&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;/api/2.0/unity-catalog/schemas?catalog_name=workspace&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;/api/2.0/clusters/list&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;/api/2.0/sql/statements&lt;/SPAN&gt; (POST)&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;All four endpoints return the identical &lt;SPAN&gt;should_change_password&lt;/SPAN&gt; message, with only the &lt;SPAN&gt;ReqId&lt;/SPAN&gt; differing — this rules out an endpoint-specific permission gap and points at something account/workspace-wide.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Additional context&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Later in troubleshooting, this same &lt;SPAN&gt;should_change_password&lt;/SPAN&gt; error started appearing on a personal-account PAT as well (not just the SP's OAuth token) — so whatever is triggering it does not appear to be specific to service principals or to OAuth vs. PAT auth. It seems to gate the REST/API surface broadly while the interactive workspace UI login continues to work normally with no password-change prompt.&lt;/LI&gt;&lt;LI&gt;The service principal is confirmed &lt;STRONG&gt;Active&lt;/STRONG&gt;, both in the workspace SP page and via SCIM (&lt;SPAN&gt;GET /api/2.0/preview/scim/v2/ServicePrincipals?filter=applicationId eq "&amp;lt;client_id&amp;gt;"&lt;/SPAN&gt;), with entitlements including &lt;SPAN&gt;workspace-access&lt;/SPAN&gt;, &lt;SPAN&gt;databricks-sql-access&lt;/SPAN&gt;, &lt;SPAN&gt;workspace-consume&lt;/SPAN&gt;, and group membership including &lt;SPAN&gt;admins&lt;/SPAN&gt;.&lt;/LI&gt;&lt;LI&gt;Checked &lt;STRONG&gt;Account Console → Security → Enhanced security and compliance&lt;/STRONG&gt;: both "Compliance security profile for new workspaces" and "Enhanced security monitoring for new workspaces" are &lt;STRONG&gt;Disabled&lt;/STRONG&gt;. These also only apply prospectively to new workspaces, so this doesn't look like the direct cause.&lt;/LI&gt;&lt;LI&gt;Our workspace's SCIM group list includes an unusual auto-generated entry along the lines of &lt;SPAN&gt;users-clone-&amp;lt;date&amp;gt;-UTC (created by Databricks)&lt;/SPAN&gt;, suggesting this workspace went through some kind of clone or migration operation at some point. We suspect this may be related — possibly a stale password-policy or credential-state flag carried over from that process and incorrectly being applied to API/token-based auth generally (including to an identity type, service principals, that shouldn't have a password concept at all).&lt;/LI&gt;&lt;LI&gt;A separate, unrelated dead/expired PAT previously existed for this SP and returned a different, expected error (&lt;SPAN&gt;401 Invalid access token&lt;/SPAN&gt;) — that was resolved independently by revoking it. This &lt;SPAN&gt;should_change_password&lt;/SPAN&gt; issue is distinct and newer, and only started surfacing once OAuth M2M auth was correctly configured and producing valid tokens.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Question&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Has anyone seen &lt;SPAN&gt;should_change_password&lt;/SPAN&gt; returned for API/token-based calls (as opposed to an actual interactive login flow)? Is this connected to a workspace clone/migration event, and if so, is there a known remediation an account admin can apply without needing a support ticket? (We don't currently have a Databricks support plan that allows filing a case directly, so posting here first.)&lt;/P&gt;&lt;P&gt;Happy to provide more detail — workspace region, plan tier, etc. — if useful for diagnosis.&lt;/P&gt;</description>
    <pubDate>Fri, 11 Sep 2026 03:12:29 GMT</pubDate>
    <dc:creator>tullius21</dc:creator>
    <dc:date>2026-09-11T03:12:29Z</dc:date>
    <item>
      <title>OAuth M2M (client-credentials) - getting error with github run</title>
      <link>https://community.databricks.com/t5/data-engineering/oauth-m2m-client-credentials-getting-error-with-github-run/m-p/168294#M55880</link>
      <description>&lt;P&gt;I'm setting up OAuth M2M (client-credentials) authentication for a service principal, as the long-term replacement for PAT-based auth in a GitHub Actions CI/CD workflow. The token exchange itself succeeds and returns a valid, well-formed access token — but every subsequent API call made with that token, regardless of endpoint, fails with:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;{"error_code": 403, "message": "should_change_password [ReqId: ...]"}&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have not been able to find this error documented anywhere for a service-principal token (service principals don't have passwords), so I'm hoping someone here has hit this before.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Steps to reproduce&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Generate an OAuth secret for the service principal via &lt;STRONG&gt;Settings → Identity and access → Service principals → (your SP) → Secrets tab → Generate secret&lt;/STRONG&gt; (scope: all APIs).&lt;/LI&gt;&lt;LI&gt;Exchange for a token:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;curl -X POST https://&amp;lt;workspace-host&amp;gt;/oidc/v1/token \&lt;BR /&gt;&amp;nbsp; -u "&amp;lt;client_id&amp;gt;:&amp;lt;client_secret&amp;gt;" \&lt;BR /&gt;&amp;nbsp; -d "grant_type=client_credentials" \&lt;BR /&gt;&amp;nbsp; -d "scope=all-apis"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;→ Returns a valid &lt;SPAN&gt;access_token&lt;/SPAN&gt;, &lt;SPAN&gt;token_type: Bearer&lt;/SPAN&gt;, &lt;SPAN&gt;expires_in: 3600&lt;/SPAN&gt;. No errors at this step.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Use that token against any API, e.g.:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;curl -X GET https://&amp;lt;workspace-host&amp;gt;/api/2.0/preview/scim/v2/Me \&lt;BR /&gt;&amp;nbsp; -H "Authorization: Bearer &amp;lt;access_token&amp;gt;"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;→ Returns &lt;SPAN&gt;403 should_change_password&lt;/SPAN&gt;.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Same result reproduced independently against:&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;/api/2.0/unity-catalog/schemas?catalog_name=workspace&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;/api/2.0/clusters/list&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;/api/2.0/sql/statements&lt;/SPAN&gt; (POST)&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;All four endpoints return the identical &lt;SPAN&gt;should_change_password&lt;/SPAN&gt; message, with only the &lt;SPAN&gt;ReqId&lt;/SPAN&gt; differing — this rules out an endpoint-specific permission gap and points at something account/workspace-wide.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Additional context&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Later in troubleshooting, this same &lt;SPAN&gt;should_change_password&lt;/SPAN&gt; error started appearing on a personal-account PAT as well (not just the SP's OAuth token) — so whatever is triggering it does not appear to be specific to service principals or to OAuth vs. PAT auth. It seems to gate the REST/API surface broadly while the interactive workspace UI login continues to work normally with no password-change prompt.&lt;/LI&gt;&lt;LI&gt;The service principal is confirmed &lt;STRONG&gt;Active&lt;/STRONG&gt;, both in the workspace SP page and via SCIM (&lt;SPAN&gt;GET /api/2.0/preview/scim/v2/ServicePrincipals?filter=applicationId eq "&amp;lt;client_id&amp;gt;"&lt;/SPAN&gt;), with entitlements including &lt;SPAN&gt;workspace-access&lt;/SPAN&gt;, &lt;SPAN&gt;databricks-sql-access&lt;/SPAN&gt;, &lt;SPAN&gt;workspace-consume&lt;/SPAN&gt;, and group membership including &lt;SPAN&gt;admins&lt;/SPAN&gt;.&lt;/LI&gt;&lt;LI&gt;Checked &lt;STRONG&gt;Account Console → Security → Enhanced security and compliance&lt;/STRONG&gt;: both "Compliance security profile for new workspaces" and "Enhanced security monitoring for new workspaces" are &lt;STRONG&gt;Disabled&lt;/STRONG&gt;. These also only apply prospectively to new workspaces, so this doesn't look like the direct cause.&lt;/LI&gt;&lt;LI&gt;Our workspace's SCIM group list includes an unusual auto-generated entry along the lines of &lt;SPAN&gt;users-clone-&amp;lt;date&amp;gt;-UTC (created by Databricks)&lt;/SPAN&gt;, suggesting this workspace went through some kind of clone or migration operation at some point. We suspect this may be related — possibly a stale password-policy or credential-state flag carried over from that process and incorrectly being applied to API/token-based auth generally (including to an identity type, service principals, that shouldn't have a password concept at all).&lt;/LI&gt;&lt;LI&gt;A separate, unrelated dead/expired PAT previously existed for this SP and returned a different, expected error (&lt;SPAN&gt;401 Invalid access token&lt;/SPAN&gt;) — that was resolved independently by revoking it. This &lt;SPAN&gt;should_change_password&lt;/SPAN&gt; issue is distinct and newer, and only started surfacing once OAuth M2M auth was correctly configured and producing valid tokens.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Question&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Has anyone seen &lt;SPAN&gt;should_change_password&lt;/SPAN&gt; returned for API/token-based calls (as opposed to an actual interactive login flow)? Is this connected to a workspace clone/migration event, and if so, is there a known remediation an account admin can apply without needing a support ticket? (We don't currently have a Databricks support plan that allows filing a case directly, so posting here first.)&lt;/P&gt;&lt;P&gt;Happy to provide more detail — workspace region, plan tier, etc. — if useful for diagnosis.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2026 03:12:29 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/oauth-m2m-client-credentials-getting-error-with-github-run/m-p/168294#M55880</guid>
      <dc:creator>tullius21</dc:creator>
      <dc:date>2026-09-11T03:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: OAuth M2M (client-credentials) - getting error with github run</title>
      <link>https://community.databricks.com/t5/data-engineering/oauth-m2m-client-credentials-getting-error-with-github-run/m-p/168384#M55916</link>
      <description>&lt;P&gt;further refined this problem with below if anyone has any idea how I could address? thanks.&amp;nbsp;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;P class=""&gt;Later in troubleshooting, this same should_change_password error started appearing on a personal-account PAT as well (not just the SP's OAuth token) — so whatever is triggering it does not appear to be specific to service principals or to OAuth vs. PAT auth. It seems to gate the REST/API surface broadly while the interactive workspace UI login continues to work normally with no password-change prompt.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;The service principal is confirmed &lt;STRONG&gt;Active&lt;/STRONG&gt;, both in the workspace SP page and via SCIM (GET /api/2.0/preview/scim/v2/ServicePrincipals?filter=applicationId eq "&amp;lt;client_id&amp;gt;"), with entitlements including workspace-access, databricks-sql-access, workspace-consume, and group membership including admins.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;STRONG&gt;Workspace assignment ruled out.&lt;/STRONG&gt; Checked Account Console → Workspaces → [workspace] → Permissions directly: both the service principal and the admin user account are listed with &lt;STRONG&gt;Admin&lt;/STRONG&gt; permission, assigned directly (not via group inheritance). So this is not an account-to-workspace assignment gap.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;STRONG&gt;Not limited to OAuth/SCIM/SQL.&lt;/STRONG&gt; Also tested the On-Behalf-Of token creation endpoint (POST /api/2.0/token-management/on-behalf-of/tokens), attempting to mint a fresh SP-scoped PAT using the admin's own (already-authenticated-to-the-UI) session — this also returns the identical should_change_password, meaning even the credential-issuance path itself is blocked, not just downstream data-plane calls.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;STRONG&gt;Not a blanket account lockout.&lt;/STRONG&gt; Other admin actions in the workspace UI return normal, correctly-scoped errors — e.g., attempting to manage Git credentials for a group without permission returns a proper "User does not have permission to manage Git credentials for group &amp;lt;id&amp;gt;. Please ask an admin of the group to manage the credential." This tells us the account can still receive well-formed, specific permission errors elsewhere; should_change_password appears isolated to a specific set of surfaces (SCIM, Unity Catalog, clusters, SQL Statement Execution, Token Management), which look like they may share a common underlying auth-check code path that other UI actions don't hit.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Checked &lt;STRONG&gt;Account Console → Security → Enhanced security and compliance&lt;/STRONG&gt;: both "Compliance security profile for new workspaces" and "Enhanced security monitoring for new workspaces" are &lt;STRONG&gt;Disabled&lt;/STRONG&gt;. These also only apply prospectively to new workspaces, so this doesn't look like the direct cause.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Our workspace's SCIM group list includes an unusual auto-generated entry along the lines of users-clone-&amp;lt;date&amp;gt;-UTC (created by Databricks), flagged in the UI as "Workspace local — not yet migrated to the account level," suggesting this workspace went through some kind of entitlement-control migration at some point. We tested granting this group Admin-level entitlement directly (in case group-level state was involved) — no change to the error. This rules the group out as a direct cause, though its creation timing is suspiciously close to when things were still working normally.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;A separate, unrelated dead/expired PAT previously existed for this SP and returned a different, expected error (401 Invalid access token) — that was resolved independently by revoking it. This should_change_password issue is distinct and newer, and only started surfacing once OAuth M2M auth was correctly configured and producing valid tokens.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H2 id="question"&gt;Question&lt;/H2&gt;&lt;P class=""&gt;Has anyone seen should_change_password returned for API/token-based calls (as opposed to an actual interactive login flow)? Given workspace assignment, group entitlements, and security-profile settings have all been ruled out as the cause, and the failure is consistent across every credential type and issuance path we can access ourselves (PAT, OAuth M2M, OBO-token minting) — this looks like it may require a server-side flag reset on the account/identity record that only Databricks engineering can clear. Is this connected to a workspace clone/migration event, and if so, is there a known remediation an account admin can apply without needing a support ticket? (We don't currently have a Databricks support plan that allows filing a case directly, so posting here first.)&lt;/P&gt;&lt;P class=""&gt;Happy to provide more detail — workspace region, plan tier, etc. — if useful for diagnosis&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2026 15:50:28 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/oauth-m2m-client-credentials-getting-error-with-github-run/m-p/168384#M55916</guid>
      <dc:creator>tullius21</dc:creator>
      <dc:date>2026-09-11T15:50:28Z</dc:date>
    </item>
  </channel>
</rss>

