Skip to main content

๐Ÿ›ก๏ธ Azure Databricks groups are not reviewed periodically๐ŸŸขโšช

  • Contextual name: ๐Ÿ›ก๏ธ Databricks groups are not reviewed periodically๐ŸŸขโšช
  • ID: /ce/ca/azure/databricks/groups-reviewed-periodically
  • Tags:
  • Policy Type: COMPLIANCE_POLICY
  • Policy Categories: SECURITY

Descriptionโ€‹

Open File

Descriptionโ€‹

Azure Databricks groups are used with role-based access control to assign permissions to users and service principals. These assignments should be reviewed periodically to confirm that access remains appropriate.

Rationaleโ€‹

Regular access reviews reduce the risk of stale or excessive permissions in Databricks workspaces. Reviewing group membership and role assignments helps ensure that users retain only the access required for their current responsibilities.

Impactโ€‹

Periodic reviews require administrative effort and coordination with workspace owners. Removing or changing assignments without validation may disrupt users, jobs, or integrations that depend on Databricks access.

Auditโ€‹

From Azure Portalโ€‹
  1. Open Azure Databricks.
  2. Select the Databricks workspace to audit.
  3. Select Access control (IAM).
  4. Select Role assignments.
  5. Review each role assignment and verify that assigned groups and users are still required.

Default Valueโ€‹

By default, Azure Databricks has the owner user and role assigned.

... see more

Remediationโ€‹

Open File

Remediationโ€‹

From Azure Portalโ€‹

  1. Open Azure Databricks.
  2. Select the Databricks workspace to remediate.
  3. Select Access control (IAM).
  4. Select Role assignments.
  5. Remove group or user assignments that are no longer required.
  6. To add an approved assignment, select Add role assignment.
  7. Select the required role, select the approved group members, and then select Review + assign.
  8. Repeat the review for each Databricks workspace.

Document the review outcome and repeat the process at the interval defined by the organization's access review policy.

policy.yamlโ€‹

Open File

Linked Framework Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
๐Ÿ’ผ CIS Azure v6.0.0 โ†’ ๐Ÿ’ผ 2.1.12 Ensure Azure Databricks groups are reviewed periodically (Manual)1no data
๐Ÿ’ผ Cloudaware Framework โ†’ ๐Ÿ’ผ Role-Based Access Control (RBAC) Management29no data