Posted inDatabricks / LinkedIn

Upcoming behavior change: Choose entitlements when adding principals to workspaces

If you are deploying Databricks at scale then you should be aware of the following change. Databricks is changing the default entitlements for workspaces. This means that the user group will no longer have entitlements by default! I believe this is a good change, supporting the least privileged security model better. However, it has some impacts since:

โš ๏ธ No entitlements = No permissions = Not be able to work.

You can already opt in the 15th of June, and it will be enforced on September 14. So you should prepare for this.

After the change:
๐Ÿ’  The users group will have no entitlements. The admins group will have all workspace entitlements. Both groups’ entitlements are locked.
๐Ÿ’  New principals must be granted entitlements explicitly when added to a workspace.
๐Ÿ’  Users and admins cannot be nested as members of other groups.

According to Databricks the following actions are required:
๐Ÿ’  If you manage system group entitlements through automation (Terraform, Workspace SCIM APIs, or custom scripts), update your workflows to target standard account groups, not system groups. After the new behavior is enabled, attempts to modify system group entitlements will fail.
๐Ÿ’  If users or admins is nested as a member of another group, remove the nesting. Nesting is not permitted under the new behavior.
๐Ÿ’  If your SCIM sync deletes workspace groups it doesn’t recognize, update its configuration to preserve the migration clone group (users-clone-<TIMESTAMP>). If the sync removes the clone group, principals migrated to it lose their entitlements.

Timeline
๐Ÿ’  June 15, 2026 โ€“ Opt-in available in workspace settings under Advanced > Access control.
๐Ÿ’  July 27, 2026 โ€“ Auto-enabled for workspaces that haven’t opted in or out. Opt-out remains available.
๐Ÿ’  September 14, 2026 โ€“ New behavior enforced for all workspaces. Opt-out removed.

๐Ÿ”— Check the official message here: https://lnkd.in/evqkb86h

#databricks #security #leastprivileged #unitycatalog

View image

For the original LinkedIn post clickย here.

My name is Remco Hooijer, and Iโ€™m an Azure Cloud Solution Architect with over 15 years of experience in the IT industry. Iโ€™ve worked with a wide range of clients and projects, from small startups to large enterprises, helping them to design, implement, and optimize their cloud solutions.

As a Microsoft Certified Trainer, Iโ€™m passionate about sharing my knowledge and expertise with others. I believe that education and training are essential to staying up-to-date with the latest technologies and best practices, and I love helping others to develop their skills and achieve their goals.

Whether youโ€™re looking to migrate to the cloud, optimize your existing infrastructure, or develop new applications and services, Iโ€™m here to help. With my extensive experience in Azure and other cloud technologies, I can provide expert guidance and support to help you achieve your business objectives.

Leave a Reply

Your email address will not be published. Required fields are marked *