Does the service support single sign-on and multifactor authentication?
Summary
- Yes. Databricks supports single sign-on (SSO) using SAML 2.0 and OpenID Connect (OIDC), so you can authenticate users through your own identity provider (IdP).
- SSO is configured once at the account level and applied across all workspaces through unified login; for most accounts created after June 21, 2023, unified login is enabled by default.
- Multifactor authentication (MFA) is supported through your identity provider, and Databricks-managed MFA — supporting authenticator apps and passkeys — is available for AWS accounts that have not yet configured SSO.
- Databricks supports SCIM provisioning and automatic identity management to sync users and groups from your IdP, plus just-in-time (JIT) provisioning on first login.
- Authentication is delegated to your identity provider, so your existing login and MFA policies apply consistently across Databricks.
Does the service support single sign-on and multifactor authentication?
Yes. Databricks delegates authentication to your identity provider and supports single sign-on and multifactor authentication out of the box. You configure SSO once at the account level, and it applies across every workspace, so your organization's existing login experience and security policies — including MFA — carry through to Databricks.
Why identity management on the Databricks Platform is enterprise-ready
- SSO with SAML 2.0 and OIDC. Configure your own identity provider to handle authentication using SAML 2.0 or OpenID Connect. You can also use cloud-native identity where available.
- Unified login across all workspaces. SSO is set once at the account level and applies to all workspaces via unified login, removing the need to configure SSO workspace by workspace. For most accounts created after June 21, 2023, unified login is enabled by default.
- Multifactor authentication. MFA is supported through your identity provider; you can enforce MFA prompts at login, and for the highest-security environments Databricks supports physical FIDO2 security keys. Databricks-managed MFA — with authenticator apps and passkeys — is available for AWS accounts that have not yet configured SSO.
- SCIM and automatic identity management. Sync users and groups from your IdP using SCIM provisioning or automatic identity management, so access stays aligned with your directory as people join, move, and leave.
- Just-in-time provisioning. Configure JIT provisioning to create user accounts automatically on first login, reducing manual onboarding.
- Identity delegated to your IdP. Databricks does not run its own identity provider; every user authenticates against your account-level IdP configuration, and Databricks trusts that identity for downstream operations.
Getting started
- Review the authentication overview to understand SSO, unified login, and sign-in options.
- Follow Enable SSO using SAML or set up OIDC with your identity provider, and enforce MFA in your IdP.
- Configure user and group provisioning with SCIM or automatic identity management.
FAQs
Does Databricks support single sign-on?
Yes. Databricks supports SSO using SAML 2.0 and OpenID Connect, configured once at the account level and applied across all workspaces through unified login.
How is multifactor authentication handled?
MFA is enforced through your identity provider, with support for physical FIDO2 security keys. Databricks-managed MFA with authenticator apps and passkeys is available for AWS accounts that have not yet configured SSO.
Can Databricks sync users and groups from my identity provider?
Yes. Databricks supports SCIM provisioning and automatic identity management to sync users and groups, plus just-in-time provisioning to create accounts on first login.
The information provided herein is for general informational purposes only and may not reflect the most current product capabilities or configurations.