<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unity Catalog Setup: Why must the first Azure Databricks account admin must be an Azure Active Directory Global Administrator at the time that they first log in to the Azure Databricks account console? in Data Governance</title>
    <link>https://community.databricks.com/t5/data-governance/unity-catalog-setup-why-must-the-first-azure-databricks-account/m-p/20021#M708</link>
    <description>&lt;P&gt;We are attempting to setup Unity Catalog and our security team is requesting justification on why this level of access is required. Why must the first Azure Databricks account admin must be an Azure Active Directory Global Administrator at the time that they first log in to the Azure Databricks account console?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Nov 2022 15:28:19 GMT</pubDate>
    <dc:creator>Matt101122</dc:creator>
    <dc:date>2022-11-29T15:28:19Z</dc:date>
    <item>
      <title>Unity Catalog Setup: Why must the first Azure Databricks account admin must be an Azure Active Directory Global Administrator at the time that they first log in to the Azure Databricks account console?</title>
      <link>https://community.databricks.com/t5/data-governance/unity-catalog-setup-why-must-the-first-azure-databricks-account/m-p/20021#M708</link>
      <description>&lt;P&gt;We are attempting to setup Unity Catalog and our security team is requesting justification on why this level of access is required. Why must the first Azure Databricks account admin must be an Azure Active Directory Global Administrator at the time that they first log in to the Azure Databricks account console?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 15:28:19 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/unity-catalog-setup-why-must-the-first-azure-databricks-account/m-p/20021#M708</guid>
      <dc:creator>Matt101122</dc:creator>
      <dc:date>2022-11-29T15:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unity Catalog Setup: Why must the first Azure Databricks account admin must be an Azure Active Directory Global Administrator at the time that they first log in to the Azure Databricks account console?</title>
      <link>https://community.databricks.com/t5/data-governance/unity-catalog-setup-why-must-the-first-azure-databricks-account/m-p/20022#M709</link>
      <description>&lt;P&gt;Hi @Matthew Dalesio​&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From our eng. team:&lt;/P&gt;&lt;P&gt;"The high privileged is only used to make sure &lt;B&gt;only&lt;/B&gt; highly privileged users get access to Databricks account admin role as this is a highly-privileged role and they can make anyone else an account admin. This is only checked at the time of bootstrapping first login and we only check whether the user is a global admin in their tenant. Databricks itself is not getting any access to the organization’s Azure resources. Because this is such a highly-privileged role, we only granted Azure global admins the default Databricks account-admin role."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We don't do anything other than to call the graph API to check the global admin's token claim and verify if he/she is indeed the global administrator on Azure and flip the switch for them to become account admins on Databricks - it is a super user role and it is required to ensure that there are no privilege escalations&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that answers the question. Basically just a matter of security &lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 16:44:31 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/unity-catalog-setup-why-must-the-first-azure-databricks-account/m-p/20022#M709</guid>
      <dc:creator>LandanG</dc:creator>
      <dc:date>2022-11-29T16:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: Unity Catalog Setup: Why must the first Azure Databricks account admin must be an Azure Active Directory Global Administrator at the time that they first log in to the Azure Databricks account console?</title>
      <link>https://community.databricks.com/t5/data-governance/unity-catalog-setup-why-must-the-first-azure-databricks-account/m-p/20023#M710</link>
      <description>&lt;P&gt;So after "making anyone else an account admin" by  the first super admin (aka azure global AAD admin) can we remove him from the databricks account or downgrade his databricks account admin role?  Our azure AAD admin doesn't use or need to manage our databricks setup &lt;/P&gt;</description>
      <pubDate>Sun, 25 Dec 2022 03:46:12 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/unity-catalog-setup-why-must-the-first-azure-databricks-account/m-p/20023#M710</guid>
      <dc:creator>prasadvaze</dc:creator>
      <dc:date>2022-12-25T03:46:12Z</dc:date>
    </item>
  </channel>
</rss>

