Unable to access Azure Databricks Account as an admin

In the Azure portal, assign global admin rights to a secondary user and elevate their access.

Written by aishwarya.sood

Last published at: December 2nd, 2024

Problem

You need to access the Databricks account console, but there are no active Azure Databricks account admins in your organization. This can happen when there is only one admin user for the account and they have left the organization.

Actions such as changing the metastore owner, managing the account subscriptions, creation and management of workspaces, etc. can only be done by account admins.

You tried to work around the issue by granting a user the Microsoft Entra Global Administrator role, but that user is unable to access the account console. When they try to log in to the account console, they are redirected to the workspace selector.

The Azure Databricks workspace selector. The text "Choose a workspace" is at the top, with a list of available workspaces below.

Cause

A Microsoft Entra Global Administrator can only access the Databricks account console as an Azure Databricks account admin when you are establishing your first account admin. After you have created the first Azure Databricks account admin, users who have the Microsoft Entra Global Administrator role don’t automatically get Azure Databricks account admin access.

Solution

You can log into the Azure portal as a Microsoft Entra Global Administrator and enable Access management for Azure resources. This allows the Microsoft Entra Global Administrator to access the Databricks account console where they can assign themselves the Azure Databricks account admin role.

For more information, review the Elevate access to manage all Azure subscriptions and management groups Azure documentation.

An image of the Default Directory "Properties" page in the Azure portal with the toggle for Access management for Azure resources highlighted.

After you have made the change, attempt to log in to the Databricks account console again. Verify that your account has the Azure Databricks account admin role. You can also assign the account admin role to additional users as needed.

As a best practice you should minimize the number of account admins, however you should always have more than one account admin to ensure your organization can manage the account as needed.

Info

Once you have confirmed an Azure Databricks account admin, make sure you disable Access Management for Azure resources. Changing this setting does not remove the Azure Databricks account admin role.