Share via

How to modify a system defined deny assignment

Mark H. Swanson 0 Reputation points
2025-05-08T17:16:58.29+00:00

Error message trying to access Databricks resource group

Failed to add Darktrace Flow Analysis as Reader for databricks-rg-EDAP_FRED-xj4ij3nvcx6ua

however, the access is denied because of the deny assignment with name 'System deny assignment created by Azure Databricks /subscriptions/

Is there any way to modify this system deny assignment?

Azure Databricks
Azure Databricks

An Apache Spark-based analytics platform optimized for Azure.


1 answer

Sort by: Most helpful
  1. Chandra Boorla 15,475 Reputation points Microsoft External Staff Moderator
    2025-05-08T18:16:27.4166667+00:00

    @Mark H. Swanson

    The error you’re seeing is due to a system-defined deny assignment created by Azure Databricks. These deny assignments are automatically generated by Azure services (like Databricks) to protect their managed resources and ensure their security.

    Why This Happens

    System-Defined Deny Assignment - These are created and managed by Azure services (like Azure Databricks) and cannot be modified, deleted, or overridden by users, even with Owner permissions.

    Security Control - They prevent changes to critical resources managed by the service.

    User's image For additional information, please refer: List Azure deny assignments

    What You Can Do

    Assign Permissions at the Workspace Level - Instead of assigning Reader access to the Databricks resource group, assign it directly to the Databricks workspace resource.

    I hope this information helps. Please do let us know if you have any further queries.

    Kindly consider upvoting the comment if the information provided is helpful. This can assist other community members in resolving similar issues.

    Thank you.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.