<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data Access Control in Databricks in Data Governance</title>
    <link>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/33898#M996</link>
    <description>&lt;P&gt;&lt;B&gt;&lt;U&gt;Data Access Control without Unity Catalog&lt;/U&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;Prior to Unity Catalog, data access was controlled at the cluster level using Table Access Controls.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;For securing access to buckets, folders, and blobs in S3/ADLS/GCS:&lt;OL&gt;&lt;LI&gt;Create an IAM role and instance profile (&lt;A href="https://docs.databricks.com/administration-guide/cloud-configurations/aws/instance-profiles.html" alt="https://docs.databricks.com/administration-guide/cloud-configurations/aws/instance-profiles.html" target="_blank"&gt;AWS&lt;/A&gt;) that has access to the to the AWS S3 buckets/folders you want to grant to a team, create a Service Principal for access to ADLS Gen2 containers/blobs (&lt;A href="https://docs.microsoft.com/en-us/azure/databricks/data/data-sources/azure/azure-storage" alt="https://docs.microsoft.com/en-us/azure/databricks/data/data-sources/azure/azure-storage" target="_blank"&gt;Azure&lt;/A&gt;), or use a Service Account to connect to a GCS bucket (&lt;A href="https://docs.gcp.databricks.com/data/data-sources/google/gcs.html?_ga=2.186972200.1834991441.1661144247-1468227001.1645719051" alt="https://docs.gcp.databricks.com/data/data-sources/google/gcs.html?_ga=2.186972200.1834991441.1661144247-1468227001.1645719051" target="_blank"&gt;GCP&lt;/A&gt;).&lt;/LI&gt;&lt;LI&gt;Attach the instance profile to the DS&amp;amp;E cluster (&lt;A href="https://docs.databricks.com/administration-guide/cloud-configurations/aws/instance-profiles.html#step-6-launch-a-cluster-with-the-instance-profile" alt="https://docs.databricks.com/administration-guide/cloud-configurations/aws/instance-profiles.html#step-6-launch-a-cluster-with-the-instance-profile" target="_blank"&gt;AWS&lt;/A&gt;), mount the ADLS Gen2 container to the workspace using the Service Principal (&lt;A href="https://docs.microsoft.com/en-us/azure/databricks/data/data-sources/azure/azure-storage#--access-azure-data-lake-storage-gen2-or-blob-storage-using-oauth-20-with-an-azure-service-principal" alt="https://docs.microsoft.com/en-us/azure/databricks/data/data-sources/azure/azure-storage#--access-azure-data-lake-storage-gen2-or-blob-storage-using-oauth-20-with-an-azure-service-principal" target="_blank"&gt;Azure&lt;/A&gt;), or add the GCP Service Account email to the DS&amp;amp;E cluster (&lt;A href="https://docs.gcp.databricks.com/data/data-sources/google/gcs.html?_ga=2.186972200.1834991441.1661144247-1468227001.1645719051#step-3-set-up-a-databricks-cluster" alt="https://docs.gcp.databricks.com/data/data-sources/google/gcs.html?_ga=2.186972200.1834991441.1661144247-1468227001.1645719051#step-3-set-up-a-databricks-cluster" target="_blank"&gt;GCP&lt;/A&gt;).&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Use cluster entitlements (&lt;A href="https://docs.databricks.com/administration-guide/access-control/cluster-acl.html?&amp;amp;_ga=2.125170698.1834991441.1661144247-1468227001.1645719051#configure-cluster-creation-entitlement" alt="https://docs.databricks.com/administration-guide/access-control/cluster-acl.html?&amp;amp;_ga=2.125170698.1834991441.1661144247-1468227001.1645719051#configure-cluster-creation-entitlement" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.microsoft.com/en-us/azure/databricks/administration-guide/access-control/cluster-acl#--configure-cluster-creation-entitlement" alt="https://docs.microsoft.com/en-us/azure/databricks/administration-guide/access-control/cluster-acl#--configure-cluster-creation-entitlement" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/administration-guide/access-control/cluster-acl.html#configure-cluster-creation-entitlement" alt="https://docs.gcp.databricks.com/administration-guide/access-control/cluster-acl.html#configure-cluster-creation-entitlement" target="_blank"&gt;GCP&lt;/A&gt;) to turn off unrestricted cluster access to DS&amp;amp;E groups&lt;/LI&gt;&lt;LI&gt;Provide access to that cluster or cluster policy using Cluster ACLs (&lt;A href="https://docs.databricks.com/security/access-control/cluster-acl.html?_ga=2.182312743.1834991441.1661144247-1468227001.1645719051" alt="https://docs.databricks.com/security/access-control/cluster-acl.html?_ga=2.182312743.1834991441.1661144247-1468227001.1645719051" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.microsoft.com/en-us/azure/databricks/security/access-control/cluster-acl" alt="https://docs.microsoft.com/en-us/azure/databricks/security/access-control/cluster-acl" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/security/access-control/cluster-acl.html" alt="https://docs.gcp.databricks.com/security/access-control/cluster-acl.html" target="_blank"&gt;GCP&lt;/A&gt;)&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Continued Below&lt;/B&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Aug 2022 08:23:52 GMT</pubDate>
    <dc:creator>isaac_gritz</dc:creator>
    <dc:date>2022-08-23T08:23:52Z</dc:date>
    <item>
      <title>Data Access Control in Databricks</title>
      <link>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/33895#M993</link>
      <description>&lt;P&gt;&lt;B&gt;Best Practices for Securing Access to Data in Databricks&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unity Catalog is the unified governance solution for Data &amp;amp; AI assets in Databricks and greatly simplifies and centralized data access control. This guide includes best practices for both the streamlined approach with Unity Catalog as well as the approach without Unity Catalog.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;U&gt;Data Access Control with Unity Catalog&lt;/U&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;Unity Catalog elevates access to files, databases, tables, rows, and columns and more to the metastore level rather than the cluster level and allows you to set and users, groups, and permissions across workspaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Continued below&lt;/B&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 07:56:40 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/33895#M993</guid>
      <dc:creator>isaac_gritz</dc:creator>
      <dc:date>2022-08-23T07:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: Data Access Control in Databricks</title>
      <link>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/33896#M994</link>
      <description>&lt;OL&gt;&lt;LI&gt;To enable a workspace for Unity Catalog:&lt;OL&gt;&lt;LI&gt;Create an S3 bucket and IAM role&amp;nbsp;(&lt;A href="https://docs.databricks.com/data-governance/unity-catalog/get-started.html?_ga=2.182149223.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f" alt="https://docs.databricks.com/data-governance/unity-catalog/get-started.html?_ga=2.182149223.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/data-governance/unity-catalog/get-started.html?_ga=2.182149223.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f" alt="https://docs.gcp.databricks.com/data-governance/unity-catalog/get-started.html?_ga=2.182149223.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f" target="_blank"&gt;GCP&lt;/A&gt;) or Access Connector (&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/get-started" alt="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/get-started" target="_blank"&gt;Azure&lt;/A&gt;) that Unity Catalog will use as the default for managed tables (&lt;A href="https://docs.databricks.com/data-governance/unity-catalog/index.html#managed-table" alt="https://docs.databricks.com/data-governance/unity-catalog/index.html#managed-table" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/create-tables#--managed-tables" alt="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/create-tables#--managed-tables" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/data-governance/unity-catalog/create-tables.html#managed-tables" alt="https://docs.gcp.databricks.com/data-governance/unity-catalog/create-tables.html#managed-tables" target="_blank"&gt;GCP&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;Create a metastore using that IAM role (&lt;A href="https://docs.databricks.com/data-governance/unity-catalog/get-started.html#create-your-first-metastore-and-attach-a-workspace" alt="https://docs.databricks.com/data-governance/unity-catalog/get-started.html#create-your-first-metastore-and-attach-a-workspace" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/data-governance/unity-catalog/get-started.html#create-your-first-metastore" alt="https://docs.gcp.databricks.com/data-governance/unity-catalog/get-started.html#create-your-first-metastore" target="_blank"&gt;GCP&lt;/A&gt;) or Access Connector (&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/get-started#--create-your-first-metastore-and-attach-a-workspace" alt="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/get-started#--create-your-first-metastore-and-attach-a-workspace" target="_blank"&gt;Azure&lt;/A&gt;) and attach that metastore to each of the workspace you would like have access to that metastore.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;For securing access to buckets, folders, and blobs in S3/ADLS/GCS:&lt;OL&gt;&lt;LI&gt;For access to data in the default S3/ADLS/GCS bucket/container:&lt;OL&gt;&lt;LI&gt;A Managed Storage Credential (&lt;A href="https://docs.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html" alt="https://docs.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/manage-external-locations-and-credentials" alt="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/manage-external-locations-and-credentials" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html?_ga=2.214066263.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f" alt="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html?_ga=2.214066263.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f" target="_blank"&gt;GCP&lt;/A&gt;) was automatically created when the metastore was set up.&lt;/LI&gt;&lt;LI&gt;Create an External Location (&lt;A href="https://docs.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html?&amp;amp;_ga=2.122243403.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f#manage-external-locations" alt="https://docs.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html?&amp;amp;_ga=2.122243403.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f#manage-external-locations" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/manage-external-locations-and-credentials" alt="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/manage-external-locations-and-credentials" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html" alt="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html" target="_blank"&gt;GCP&lt;/A&gt;) using that Managed Storage Credential to scope down access to the specific storage path within that bucket/container you want to grant access to.&lt;/LI&gt;&lt;LI&gt;Grant access to that External Location to the groups that you want to be able to read/write or create tables on top of those S3/ADLS/GCS locations (&lt;A href="https://docs.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html?&amp;amp;_ga=2.113393735.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f#manage-permissions-for-an-external-location" alt="https://docs.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html?&amp;amp;_ga=2.113393735.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f#manage-permissions-for-an-external-location" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/manage-external-locations-and-credentials#manage-permissions-for-an-external-location" alt="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/manage-external-locations-and-credentials#manage-permissions-for-an-external-location" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html#manage-permissions-for-an-external-location" alt="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html#manage-permissions-for-an-external-location" target="_blank"&gt;GCP&lt;/A&gt;)&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Continued Below&lt;/B&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 07:57:16 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/33896#M994</guid>
      <dc:creator>isaac_gritz</dc:creator>
      <dc:date>2022-08-23T07:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: Data Access Control in Databricks</title>
      <link>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/33897#M995</link>
      <description>&lt;OL&gt;&lt;LI&gt;To enable a workspace for Unity Catalog: (see above)&lt;/LI&gt;&lt;LI&gt;For security access to buckets, folders, and blobs in S3/ADLS/GCS: (see above)&lt;OL&gt;&lt;LI&gt;For access to data in the default S3/ADLS/GCS bucket/container: (see above) &lt;/LI&gt;&lt;LI&gt;For access to data in external S3/ADLS/GCS buckets/containers:&lt;OL&gt;&lt;LI&gt;Create an IAM role (&lt;A href="https://docs.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html?_ga=2.182127847.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f#manage-storage-credentials" alt="https://docs.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html?_ga=2.182127847.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f#manage-storage-credentials" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html#manage-storage-credentials" alt="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html#manage-storage-credentials" target="_blank"&gt;GCP&lt;/A&gt;) or Managed Identity (&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/manage-external-locations-and-credentials#manage-storage-credentials" alt="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/manage-external-locations-and-credentials#manage-storage-credentials" target="_blank"&gt;Azure&lt;/A&gt;) to provide access to this S3/ADLS/GCS bucket/container.&lt;/LI&gt;&lt;LI&gt;Create a Storage Credential with that IAM role (&lt;A href="https://docs.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html?_ga=2.182127847.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f#manage-storage-credentials" alt="https://docs.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html?_ga=2.182127847.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f#manage-storage-credentials" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html#manage-storage-credentials" alt="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html#manage-storage-credentials" target="_blank"&gt;GCP&lt;/A&gt;) or Managed Identity (&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/manage-external-locations-and-credentials#manage-storage-credentials" alt="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/manage-external-locations-and-credentials#manage-storage-credentials" target="_blank"&gt;Azure&lt;/A&gt;)&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Create an External Location (&lt;A href="https://docs.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html?&amp;amp;_ga=2.117525705.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f#manage-external-locations" alt="https://docs.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html?&amp;amp;_ga=2.117525705.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f#manage-external-locations" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/manage-external-locations-and-credentials" alt="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/manage-external-locations-and-credentials" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html" alt="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html" target="_blank"&gt;GCP&lt;/A&gt;) using that Managed Storage Credential to scope down access to the specific storage path within that bucket/container you want to grant access to.&lt;/LI&gt;&lt;LI&gt;Grant access to that External Location to the groups that you want to read/write/create tables on top of to those S3/ADLS/GCS locations (&lt;A href="https://docs.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html?&amp;amp;_ga=2.113393735.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f#manage-permissions-for-an-external-location" alt="https://docs.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html?&amp;amp;_ga=2.113393735.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f#manage-permissions-for-an-external-location" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/manage-external-locations-and-credentials#manage-permissions-for-an-external-location" alt="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/manage-external-locations-and-credentials#manage-permissions-for-an-external-location" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html#manage-permissions-for-an-external-location" alt="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-external-locations-and-credentials.html#manage-permissions-for-an-external-location" target="_blank"&gt;GCP&lt;/A&gt;)&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;For database, tables:&lt;OL&gt;&lt;LI&gt;Use the UI or SQL to grant/revoke access to Databases, Tables (&lt;A href="https://docs.databricks.com/data-governance/unity-catalog/data-permissions.html?_ga=2.184756713.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f" alt="https://docs.databricks.com/data-governance/unity-catalog/data-permissions.html?_ga=2.184756713.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/data-permissions" alt="https://docs.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/data-permissions" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-privileges/index.html" alt="https://docs.gcp.databricks.com/data-governance/unity-catalog/manage-privileges/index.html" target="_blank"&gt;GCP&lt;/A&gt;)&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Enable clusters and SQL warehouses to leverage Unity Catalog&lt;OL&gt;&lt;LI&gt;Enable Shared (SQL, Python), or Single User (R, Scala) security mode on DS&amp;amp;E clusters (&lt;A href="https://docs.databricks.com/data-governance/unity-catalog/compute.html?_ga=2.184756713.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f" alt="https://docs.databricks.com/data-governance/unity-catalog/compute.html?_ga=2.184756713.170713615.1681109729-8249db01-ef25-401f-aa12-ca0e7ef20c0f" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/compute" alt="https://docs.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/compute" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/data-governance/unity-catalog/compute.html" alt="https://docs.gcp.databricks.com/data-governance/unity-catalog/compute.html" target="_blank"&gt;GCP&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;Databricks SQL warehouses are enabled for Unity Catalog by default&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Fine-grained access control&lt;OL&gt;&lt;LI&gt;Row and column level security and dynamic data masking can be administered using Dynamic View Functions (&lt;A href="https://docs.databricks.com/security/access-control/table-acls/object-privileges.html#dynamic-view-functions" alt="https://docs.databricks.com/security/access-control/table-acls/object-privileges.html#dynamic-view-functions" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.microsoft.com/en-us/azure/databricks/security/access-control/table-acls/object-privileges" alt="https://docs.microsoft.com/en-us/azure/databricks/security/access-control/table-acls/object-privileges" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/security/access-control/table-acls/object-privileges.html" alt="https://docs.gcp.databricks.com/security/access-control/table-acls/object-privileges.html" target="_blank"&gt;GCP&lt;/A&gt;)&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Continued Below&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 07:58:02 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/33897#M995</guid>
      <dc:creator>isaac_gritz</dc:creator>
      <dc:date>2022-08-23T07:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: Data Access Control in Databricks</title>
      <link>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/33898#M996</link>
      <description>&lt;P&gt;&lt;B&gt;&lt;U&gt;Data Access Control without Unity Catalog&lt;/U&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;Prior to Unity Catalog, data access was controlled at the cluster level using Table Access Controls.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;For securing access to buckets, folders, and blobs in S3/ADLS/GCS:&lt;OL&gt;&lt;LI&gt;Create an IAM role and instance profile (&lt;A href="https://docs.databricks.com/administration-guide/cloud-configurations/aws/instance-profiles.html" alt="https://docs.databricks.com/administration-guide/cloud-configurations/aws/instance-profiles.html" target="_blank"&gt;AWS&lt;/A&gt;) that has access to the to the AWS S3 buckets/folders you want to grant to a team, create a Service Principal for access to ADLS Gen2 containers/blobs (&lt;A href="https://docs.microsoft.com/en-us/azure/databricks/data/data-sources/azure/azure-storage" alt="https://docs.microsoft.com/en-us/azure/databricks/data/data-sources/azure/azure-storage" target="_blank"&gt;Azure&lt;/A&gt;), or use a Service Account to connect to a GCS bucket (&lt;A href="https://docs.gcp.databricks.com/data/data-sources/google/gcs.html?_ga=2.186972200.1834991441.1661144247-1468227001.1645719051" alt="https://docs.gcp.databricks.com/data/data-sources/google/gcs.html?_ga=2.186972200.1834991441.1661144247-1468227001.1645719051" target="_blank"&gt;GCP&lt;/A&gt;).&lt;/LI&gt;&lt;LI&gt;Attach the instance profile to the DS&amp;amp;E cluster (&lt;A href="https://docs.databricks.com/administration-guide/cloud-configurations/aws/instance-profiles.html#step-6-launch-a-cluster-with-the-instance-profile" alt="https://docs.databricks.com/administration-guide/cloud-configurations/aws/instance-profiles.html#step-6-launch-a-cluster-with-the-instance-profile" target="_blank"&gt;AWS&lt;/A&gt;), mount the ADLS Gen2 container to the workspace using the Service Principal (&lt;A href="https://docs.microsoft.com/en-us/azure/databricks/data/data-sources/azure/azure-storage#--access-azure-data-lake-storage-gen2-or-blob-storage-using-oauth-20-with-an-azure-service-principal" alt="https://docs.microsoft.com/en-us/azure/databricks/data/data-sources/azure/azure-storage#--access-azure-data-lake-storage-gen2-or-blob-storage-using-oauth-20-with-an-azure-service-principal" target="_blank"&gt;Azure&lt;/A&gt;), or add the GCP Service Account email to the DS&amp;amp;E cluster (&lt;A href="https://docs.gcp.databricks.com/data/data-sources/google/gcs.html?_ga=2.186972200.1834991441.1661144247-1468227001.1645719051#step-3-set-up-a-databricks-cluster" alt="https://docs.gcp.databricks.com/data/data-sources/google/gcs.html?_ga=2.186972200.1834991441.1661144247-1468227001.1645719051#step-3-set-up-a-databricks-cluster" target="_blank"&gt;GCP&lt;/A&gt;).&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Use cluster entitlements (&lt;A href="https://docs.databricks.com/administration-guide/access-control/cluster-acl.html?&amp;amp;_ga=2.125170698.1834991441.1661144247-1468227001.1645719051#configure-cluster-creation-entitlement" alt="https://docs.databricks.com/administration-guide/access-control/cluster-acl.html?&amp;amp;_ga=2.125170698.1834991441.1661144247-1468227001.1645719051#configure-cluster-creation-entitlement" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.microsoft.com/en-us/azure/databricks/administration-guide/access-control/cluster-acl#--configure-cluster-creation-entitlement" alt="https://docs.microsoft.com/en-us/azure/databricks/administration-guide/access-control/cluster-acl#--configure-cluster-creation-entitlement" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/administration-guide/access-control/cluster-acl.html#configure-cluster-creation-entitlement" alt="https://docs.gcp.databricks.com/administration-guide/access-control/cluster-acl.html#configure-cluster-creation-entitlement" target="_blank"&gt;GCP&lt;/A&gt;) to turn off unrestricted cluster access to DS&amp;amp;E groups&lt;/LI&gt;&lt;LI&gt;Provide access to that cluster or cluster policy using Cluster ACLs (&lt;A href="https://docs.databricks.com/security/access-control/cluster-acl.html?_ga=2.182312743.1834991441.1661144247-1468227001.1645719051" alt="https://docs.databricks.com/security/access-control/cluster-acl.html?_ga=2.182312743.1834991441.1661144247-1468227001.1645719051" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.microsoft.com/en-us/azure/databricks/security/access-control/cluster-acl" alt="https://docs.microsoft.com/en-us/azure/databricks/security/access-control/cluster-acl" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/security/access-control/cluster-acl.html" alt="https://docs.gcp.databricks.com/security/access-control/cluster-acl.html" target="_blank"&gt;GCP&lt;/A&gt;)&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Continued Below&lt;/B&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 08:23:52 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/33898#M996</guid>
      <dc:creator>isaac_gritz</dc:creator>
      <dc:date>2022-08-23T08:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: Data Access Control in Databricks</title>
      <link>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/33899#M997</link>
      <description>&lt;OL&gt;&lt;LI&gt;For securing access to buckets, folders, and blobs in S3/ADLS/GCS: (see above)&lt;/LI&gt;&lt;LI&gt;For database, tables:&lt;OL&gt;&lt;LI&gt;Use cluster entitlements (&lt;A href="https://docs.databricks.com/administration-guide/access-control/cluster-acl.html?&amp;amp;_ga=2.125170698.1834991441.1661144247-1468227001.1645719051#configure-cluster-creation-entitlement" alt="https://docs.databricks.com/administration-guide/access-control/cluster-acl.html?&amp;amp;_ga=2.125170698.1834991441.1661144247-1468227001.1645719051#configure-cluster-creation-entitlement" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.microsoft.com/en-us/azure/databricks/administration-guide/access-control/cluster-acl#--configure-cluster-creation-entitlement" alt="https://docs.microsoft.com/en-us/azure/databricks/administration-guide/access-control/cluster-acl#--configure-cluster-creation-entitlement" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/administration-guide/access-control/cluster-acl.html#configure-cluster-creation-entitlement" alt="https://docs.gcp.databricks.com/administration-guide/access-control/cluster-acl.html#configure-cluster-creation-entitlement" target="_blank"&gt;GCP&lt;/A&gt;) to turn off unrestricted cluster access to groups. Or restrict them only to Databricks SQL.&lt;OL&gt;&lt;LI&gt;For using SQL/Python within notebooks but restricting access to Databases/Tables&lt;OL&gt;&lt;LI&gt;Create a cluster that has Shared Access mode (&lt;A href="https://docs.databricks.com/clusters/configure.html#what-is-cluster-access-mode" alt="https://docs.databricks.com/clusters/configure.html#what-is-cluster-access-mode" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://learn.microsoft.com/en-us/azure/databricks/clusters/configure#--what-is-cluster-access-mode" alt="https://learn.microsoft.com/en-us/azure/databricks/clusters/configure#--what-is-cluster-access-mode" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/clusters/configure.html#what-is-cluster-access-mode" alt="https://docs.gcp.databricks.com/clusters/configure.html#what-is-cluster-access-mode" target="_blank"&gt;GCP&lt;/A&gt;) enabled&lt;/LI&gt;&lt;LI&gt;Provide access to that cluster or policy using Cluster ACLs (&lt;A href="https://docs.databricks.com/security/access-control/cluster-acl.html?_ga=2.182312743.1834991441.1661144247-1468227001.1645719051" alt="https://docs.databricks.com/security/access-control/cluster-acl.html?_ga=2.182312743.1834991441.1661144247-1468227001.1645719051" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.microsoft.com/en-us/azure/databricks/security/access-control/cluster-acl" alt="https://docs.microsoft.com/en-us/azure/databricks/security/access-control/cluster-acl" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/security/access-control/cluster-acl.html" alt="https://docs.gcp.databricks.com/security/access-control/cluster-acl.html" target="_blank"&gt;GCP&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;Use SQL GRANT statements (&lt;A href="https://docs.databricks.com/security/access-control/table-acls/object-privileges.html?&amp;amp;_ga=2.116365318.1834991441.1661144247-1468227001.1645719051#data-governance-model" alt="https://docs.databricks.com/security/access-control/table-acls/object-privileges.html?&amp;amp;_ga=2.116365318.1834991441.1661144247-1468227001.1645719051#data-governance-model" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.microsoft.com/en-us/azure/databricks/security/access-control/table-acls/object-privileges" alt="https://docs.microsoft.com/en-us/azure/databricks/security/access-control/table-acls/object-privileges" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/security/access-control/table-acls/object-privileges.html" alt="https://docs.gcp.databricks.com/security/access-control/table-acls/object-privileges.html" target="_blank"&gt;GCP&lt;/A&gt;) to grant/revoke permissions&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;For using Databricks SQL but restricting access to Databases/Tables&lt;OL&gt;&lt;LI&gt;Databricks SQL Warehouses automatically have Shared Access mode enabled&lt;/LI&gt;&lt;LI&gt;Use the Databricks SQL UI or SQL (&lt;A href="https://docs.databricks.com/sql/user/security/data-access-overview.html?_ga=2.114202247.1834991441.1661144247-1468227001.1645719051" alt="https://docs.databricks.com/sql/user/security/data-access-overview.html?_ga=2.114202247.1834991441.1661144247-1468227001.1645719051" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.microsoft.com/en-us/azure/databricks/sql/user/security/data-access-overview" alt="https://docs.microsoft.com/en-us/azure/databricks/sql/user/security/data-access-overview" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/sql/user/security/data-access-overview.html" alt="https://docs.gcp.databricks.com/sql/user/security/data-access-overview.html" target="_blank"&gt;GCP&lt;/A&gt;) to grant/revoke access to Databases, Tables&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Fine-grained access control&lt;OL&gt;&lt;LI&gt;Row and column level security and dynamic data masking can be administered using Dynamic View Functions (&lt;A href="https://docs.databricks.com/security/access-control/table-acls/object-privileges.html#dynamic-view-functions" alt="https://docs.databricks.com/security/access-control/table-acls/object-privileges.html#dynamic-view-functions" target="_blank"&gt;AWS&lt;/A&gt; | &lt;A href="https://docs.microsoft.com/en-us/azure/databricks/security/access-control/table-acls/object-privileges" alt="https://docs.microsoft.com/en-us/azure/databricks/security/access-control/table-acls/object-privileges" target="_blank"&gt;Azure&lt;/A&gt; | &lt;A href="https://docs.gcp.databricks.com/security/access-control/table-acls/object-privileges.html" alt="https://docs.gcp.databricks.com/security/access-control/table-acls/object-privileges.html" target="_blank"&gt;GCP&lt;/A&gt;)&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Wed, 12 Apr 2023 07:09:47 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/33899#M997</guid>
      <dc:creator>isaac_gritz</dc:creator>
      <dc:date>2023-04-12T07:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Data Access Control in Databricks</title>
      <link>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/33900#M998</link>
      <description>&lt;P&gt;Let us know if this walkthrough helped you set up data access control and let us know how your journey to leveraging Unity Catalog is going!&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 07:10:41 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/33900#M998</guid>
      <dc:creator>isaac_gritz</dc:creator>
      <dc:date>2023-04-12T07:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: Data Access Control in Databricks</title>
      <link>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/153333#M2814</link>
      <description>&lt;P&gt;Which roles are recommended to securely create and manage Unity Catalog objects (Storage Credentials, External Locations, Catalogs, Schemas, and Delta Sharing)?” and why ?&lt;/P&gt;</description>
      <pubDate>Sat, 04 Apr 2026 21:03:19 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/153333#M2814</guid>
      <dc:creator>APJESK</dc:creator>
      <dc:date>2026-04-04T21:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: Data Access Control in Databricks</title>
      <link>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/153334#M2815</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Which roles ( workspace admin or &lt;/SPAN&gt;Metastore&lt;SPAN&gt; Admin) are recommended to securely create and manage Unity Catalog objects (Storage Credentials, External Locations, Catalogs, Schemas, and Delta Sharing)?” and why ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Apr 2026 21:08:50 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/data-access-control-in-databricks/m-p/153334#M2815</guid>
      <dc:creator>APJESK</dc:creator>
      <dc:date>2026-04-04T21:08:50Z</dc:date>
    </item>
  </channel>
</rss>

