Security and Compliance
Understand the authentication methods and audit features supported by the Databricks Unity Catalog integration to ensure you are meeting your organization's security and compliance needs
Authentication methods
Registering the connection
The Databricks Unity Catalog integration supports the following authentication methods to register a connection. The credentials provided must be for an account with the permissions listed in the Register a Databricks Unity Catalog connection guide.
Personal access token (PAT)
OAuth machine-to-machine (M2M)
Identity providers for user authentication
The built-in Immuta IAM can be used as a complete solution for authentication and user entitlement. However, you can connect your existing identity management provider to Immuta to use that system for authentication and user entitlement instead.
Each of the supported identity providers includes a specific set of configuration options that enable Immuta to communicate with the IAM system and map the users, permissions, groups, and attributes into Immuta.
See the Identity managers guide for a list of supported providers and details.
See the Databricks Unity Catalog integration reference guide for details about user provisioning and mapping user accounts to Immuta.
Auditing and compliance
Immuta provides auditing features and governance reports so that data owners and governors can monitor users' access to data and detect anomalies in behavior.
You can view the information in these audit logs on dashboards or export the full audit logs to S3 and ADLS for long-term backup and processing with log data processors and tools. This capability fosters convenient integrations with log monitoring services and data pipelines.
See the Audit documentation for details about these capabilities and how they work with the Databricks Unity Catalog integration.
Databricks Unity Catalog query audit
Immuta uses Databricks tables from the system catalog to understand the queries users make and present them in the query audit logs.
The audit ingest is set when registering the connection and can be scoped to only ingest specific workspaces if needed. The default ingest frequency is every 24 hours, but this can be configured to a different frequency on the Immuta app settings page. Additionally, audit ingestion can be manually requested at any time from the Immuta audit page. When manually requested, it will only search for new queries that were created since the last query that had been audited. The job is run in the background, so the new queries will not be immediately available.
See the Databricks Unity Catalog audit page for details about the contents of the logs and an example of the resulting audit record.
Governance reports
Immuta governance reports allow users with the GOVERNANCE Immuta permission to use a natural language builder to instantly create reports that delineate user activity across Immuta. These reports can be based on various entity types, including users, groups, projects, data sources, purposes, policy types, or connection types.
See the Governance report types page for a list of report types and guidance.
Last updated
Was this helpful?

