Skip to main content

Configure authentication to Microsoft 365

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Microsoft 365 Unified Audit Logs from the Previews page. See Manage Databricks previews.

Configure Microsoft 365 to enable authentication from Databricks for the Microsoft 365 Unified Audit Logs connector. Use the application credentials from these steps to create a Unity Catalog connection.

Prerequisites​

  • Enable Office 365 unified auditing for your organization.
  • Have permission to register an application in Microsoft Entra ID.
  • Have permission to grant tenant-wide admin consent for Office 365 Management APIs.

Register an Azure application for OAuth​

In this step, you register an application in the Azure portal to enable authentication from Databricks.

Register the application​

  1. Go to the Azure portal and search for Microsoft Entra ID.
  2. In the left pane, go to Manage > App registrations, and click New registration.
  3. On the Register an application page:
    1. Enter a user-facing display name for your application.
    2. In Supported account types, select Single tenant only - <your tenant name>.
    3. Leave Redirect URI blank.
    4. Click Register.

Create a client secret​

  1. In the left pane of the registered application page, go to Manage > Certificates & secrets, and click New client secret.
  2. In the pane that opens, enter a description for the secret, select 24 months for Expires, and click Add.
  3. Note the credential Value, not the Secret ID. You use this value in the next step.

Configure API permissions​

  1. Add delegated permissions:
    1. In the left pane, go to Manage > API permissions, and click Add a permission.
    2. In the Request API permissions pane, click Office 365 Management APIs.
    3. Click Delegated permissions.
    4. Select ActivityFeed.Read, ActivityFeed.ReadDlp, and ServiceHealth.Read.
    5. Click Add permissions.
  2. Repeat the permission steps for application permissions:
    1. Click Add a permission.
    2. In the Request API permissions pane, click Office 365 Management APIs.
    3. Click Application permissions.
    4. Select ActivityFeed.Read, ActivityFeed.ReadDlp, and ServiceHealth.Read.
    5. Click Add permissions.
  3. On the API permissions page, click Grant admin consent for <your organization>, next to Add a permission, and click Yes in the confirmation popup.

Copy the application IDs​

  1. In the left pane, go to Overview.
  2. Note down the Application (client) ID and Directory (tenant) ID; you'll use these in the next step.

Next steps​

Create a Microsoft 365 Unified Audit Logs connection in Databricks. See Create a Microsoft 365 Unified Audit Logs connection.