An Apache Spark-based analytics platform optimized for Azure.
Hello Ryan De Four,
Thank you again for your posting your query on Microsoft QnA! . I also thank our community member Vinodh247 for the spot on response. I would like to add the following important context and details:
While it’s true that Azure Databricks on Azure Government (Gov) Cloud does not have the Account Console UI found in the commercial cloud, and that account admin assignments are initiated from the commercial Account Console by an Entra ID Global Admin, there are a few extra points to keep in mind:
- In Gov regions, admin assignments at the account level require initial setup by an Entra (Azure AD) Global Admin outside Gov. This admin can then delegate account admin roles to other users (including service principals). Reference: https://learn.microsoft.com/en-us/azure/databricks/admin/#establish-your-first-account-admin
- Once an account admin is assigned, they can delegate workspace admin rights within your Databricks workspaces. Workspace admins manage daily permissions and workspace-level access, but do not have access to account-wide configuration unless given the higher privilege. Reference: https://learn.microsoft.com/en-us/azure/databricks/admin/
- Feature Limitations Specific to Gov Cloud: Not all Unity Catalog or account-level features available in commercial cloud are supported in Gov. The lack of the Account Console UI and some APIs can change how admin assignments and configuration are handled. Microsoft maintains an up-to-date list of support and limitations for Azure Government: Unity Catalog feature limitations and region support
- If there are roadblocks or you cannot find a currently assigned account admin, Microsoft and Databricks support teams are prepared to help, given the governance limitations. You may need to file a support request for admin changes in Gov regions. Unity Catalog volumes – not available in Azure Government regions
Please also consider:
Confirming with your internal Azure administrators if any existing account admin (user or service principal) can make the required changes via API or CLI.
- Keeping security/compliance stakeholders aware that account-level admin assignments may take additional time in Gov Cloud and may need to involve central cloud identity teams or official support tickets.
If you encounter any errors or further restrictions when using the CLI after admin rights are established, please share any specific error message or operation that did not succeed. We can help troubleshoot API or permission details if you provide that context.
References:
https://learn.microsoft.com/en-us/azure/databricks/admin/#establish-your-first-account-admin
https://learn.microsoft.com/en-us/azure/databricks/admin/
Please "Accept as Answer" if the answer provided is useful, so that you can help others in the community looking for remediation for similar issues.
Thanks
Pratyush