An Apache Spark-based analytics platform optimized for Azure.
Hello Chamel Nadir Bouacha,
Absolutely! First, thank you to the original community member Sina Salam for their thorough answer—those are great baseline recommendations. Here’s an additional, detailed explanation to clarify the background, next steps, and important troubleshooting aspects about deny assignments in Azure Databricks resource groups:
When you use Azure Databricks, a "Managed Resource Group" is created. Azure Databricks applies a deny assignment at this group to protect the resources required for the workspace. This is why you see:
- access is denied because of the deny assignment...
- You can’t delete the resource group even if you're an Owner or have role-assignment delete permission.
This happens because:
- Deny assignments override all allow permissions.
- Only the Azure Databricks service (or the underlying Azure management system) can remove the deny assignment.
- Manual removal is restricted, even for Owners, as a security measure.
- The deny assignment is automatically deleted when you delete the Databricks workspace that controls the managed resource group.
What To Do: Step-by-Step
- Always Delete the Databricks Workspace First
- Go to the Azure Portal, find your Databricks Workspace, and delete it from there.
- This action will:
- Remove the Databricks workspace,
- Automatically remove the managed resource group and all associated deny assignments.
- Remove the Databricks workspace,
- How to delete a Databricks workspace
- If the Workspace Is Already Gone, but the Resource Group Remains
Sometimes, resource groups get "orphaned" due to a failed deletion or accidental removal of the workspace object before the group.
- Check Deny Assignments Go to "Access Control (IAM)" on the resource group → "Deny assignments" tab. Ensure the deny assignment is from Databricks. About deny assignments
- Check for Resource Locks or Policies In the resource group, check for any "Locks" or "Policies" that might prevent deletion. Resource locks
- Get Subscription Owner or Admin Help
- Only a Subscription Owner (or Service Admin) can delete a managed workspace if you lack access or can escalate the support case.
- If you are not the Owner, ask them to:
- Assign you Contributor access to the workspace and its managed resource group,
- Or delete the Databricks workspace on your behalf.
- Assign you Contributor access to the workspace and its managed resource group,
- Open an Azure Support Ticket if Stuck
If the workspace is gone and the managed resource group is stuck (with deny assignments you can't remove).
- Go to Help + Support in the Azure Portal.
- Open a new support request, describe the situation (Databricks deny assignment, resource group stuck, workspace already deleted).
I hope this response will also add some more insights around your issue.
Please "Accept as Answer" if the answer provided is useful, so that you can help others in the community looking for remediation for similar issues.
Thanks
Pratyush