datalake-ADLS-access-patterns-with-Databricks icon indicating copy to clipboard operation
datalake-ADLS-access-patterns-with-Databricks copied to clipboard

Clarification on AD Groups

Open ashfondu opened this issue 2 years ago • 1 comments

Hi can you provide clarification on what the 'Read-only Group/Read-write Group' means, seems like SP is part of the AD group. ADLS will be accessed via SP hence i am unclear how the rest of the group can leverage the mount setup by the SP.

image

ashfondu avatar Oct 19 '21 17:10 ashfondu

Hello, sorry for the delay. Yes typically you will have AAD security groups created one for reading and one for writing. In the pattern where you use multiple workspaces to separate users that have read permissions vs those who have write permissions, you will use a service principal which belongs to a security group and create a workspace mount or use direct path using that service principal. Only those users belonging to the workspace will have access to use that mount or service principal (for example where you put the service principal client ID and secret in a secret scope that everyone in that workspace can access). Hope that helps?

hurtn avatar Dec 14 '21 13:12 hurtn