Your Databricks Access Policies Have Gaps. Here Is Where That Bites.


Your Databricks Access Policies Have Gaps: What the Docs Actually Say

Two groups of documented limits. Manual table-level filters and masks do not support views, time travel, clones, OpenSharing, Iceberg REST or Unity REST APIs, or path-based file access. ABAC policies do not support clones or metric views, do not apply to AI Search indexes, and allow only one distinct row filter per table and user - Databricks access policies
The two mechanisms stop in different places, so check which one protects a table before you assume a limit does or does not apply.

Gap 1: Views and Time Travel With Manual Filters and Masks

Gap 2: Copies, Shares and Side Doors (Clones, OpenSharing, REST APIs, Paths)

Route to the table Manual filters and masks ABAC policies
Deep or shallow clone Not supported Not supported
OpenSharing share Not supported Not covered in this post
Iceberg REST catalog or Unity REST API Not supported Not covered in this post
Direct file path Not supported Not covered in this post
SQL query Subject to the runtime floors in Gap 3 Subject to the runtime floors in Gap 3

Gap 3: Runtime Version Floors That Differ by Mechanism

Mechanism Runtime limit What the docs say happens
Manual filters and masks Below 12.2 LTS Not supported (fails securely, no data)
Manual filters and masks Dedicated compute on 15.3 or below Cannot read the table
ABAC policies Standard or dedicated compute below 16.4 Cannot access ABAC-secured tables

Gap 4: ABAC Edge Cases, Plus Nested MERGE (AI Search Indexes, One Row Filter)

What a Team Should Check This Week

  1. List every cluster and job runtime. Anything below 12.2 LTS cannot use row filters or column masks, dedicated compute on 15.3 or below cannot read manually protected tables, and ABAC needs 16.4 or later.
  2. Search your jobs for deep and shallow clones of any table that carries a policy.
  3. List the OpenSharing shares and check whether any includes a table with a table-level row filter or column mask.
  4. List every AI Search index built from a table with ABAC policies, and test what an index query returns.

September’s Four ABAC Additions, All Beta

A four-step timeline of September 2026 ABAC releases, all in Beta. Sep 8 DENY policies, which deny only MANAGE ACCESS CONTROL. Sep 17 metastore-level policies, about coverage. Sep 23 time travel enforcing ABAC, and Sep 29 ABAC on views, each partly addressing Gap 1 for ABAC only - Databricks access policies
All four additions are Beta, and only the last two touch a gap from this post, and only on the ABAC side.

Conclusion

+ There are no comments

Add yours