Skip to main content

πŸ“ Azure Databricks Unity Catalog is not configured 🟒

  • Contextual name: πŸ“ Databricks Unity Catalog is not configured 🟒
  • ID: /ce/ca/azure/databricks/unity-catalog
  • Located in: πŸ“ Azure Databricks

Flags​

Our Metadata​

  • Policy Type: COMPLIANCE_POLICY
  • Policy Category:
    • SECURITY

Description​

Open File

Description​

Unity Catalog is a centralized governance model for managing and securing data in Azure Databricks. It provides fine-grained access control to databases, tables, and views using Microsoft Entra ID identities. Unity Catalog also enhances data lineage, audit logging, and compliance monitoring, making it a critical component for security and governance.

Rationale​

  • Enforces centralized access control policies and reduces data security risks.
  • Enables identity-based authentication via Microsoft Entra ID.
  • Improves compliance with industry regulations (e.g. GDPR, HIPAA, SOC 2) by providing audit logs and access visibility.
  • Prevents unauthorized data access through table-, row-, and column-level security (RLS & CLS).

Impact​

  • Improperly configured permissions may lead to data exfiltration or unauthorized access.
  • Unity Catalog requires structured governance policies to be effective and prevent overly permissive access.

Audit​

Method 1: Verify unity catalog deployment:

  1. As an Azure Databricks account admin, log into the account console.

... see more

Remediation​

Open File

Remediation​

Use the remediation procedure written in this article: https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/get-started.

policy.yaml​

Open File

Linked Framework Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CIS Azure v4.0.0 β†’ πŸ’Ό 3.1.5 Ensure that Unity Catalog is configured for Azure Databricks (Manual)1
πŸ’Ό Cloudaware Framework β†’ πŸ’Ό Data Protection and Recovery15