หมายเหตุ
การเข้าถึงหน้านี้ต้องได้รับการอนุญาต คุณสามารถลอง ลงชื่อเข้าใช้หรือเปลี่ยนไดเรกทอรีได้
การเข้าถึงหน้านี้ต้องได้รับการอนุญาต คุณสามารถลองเปลี่ยนไดเรกทอรีได้
Important
Foundation model Unity Catalog permissions no longer accepts new enrollments. To restrict access to Azure Databricks-hosted models, use Unity Gateway model APIs instead. See Discover and govern access to model services and Migrate to Unity Gateway.
This page applies only to accounts already enrolled in foundation model Unity Catalog permissions.
This page describes when and how account admins use foundation model Unity Catalog permissions to restrict which Databricks-hosted foundation models your organization can access. Admins can block specific models account-wide or grant model access to specific groups or users. The enforcement applies consistently across pay-per-token, provisioned throughput, and batch inference (AI Functions) workloads.
When to use foundation model Unity Catalog permissions
Use this feature only when legally required to restrict which specific models are open, such as:
- Export-controlled model families
- Vendor-restricted or region-restricted models
- Corporate policies prohibiting specific foundation models
For day-to-day governance, use:
system.billingfor cost tracking and attribution- Unity Gateway for rate limits and request-level usage tracking
- Private Link or private networking for secure connectivity
- Egress and network controls for restricting outbound traffic
How foundation model Unity Catalog permissions work
Foundation model Unity Catalog permissions use Unity Catalog permissions on the system.ai schema and individual model objects. By default, all users have EXECUTE permission on the system.ai schema, which opens all Databricks-hosted foundation models to users.
To restrict which models are open to users, admins remove the default EXECUTE permission from the schema and then selectively grant it on approved individual models. The system enforces permissions consistently across:
- Pay-per-token endpoints — automatically enforced
- Batch inference (AI Functions) — automatically enforced
- Provisioned throughput endpoints — require manual deletion of disallowed endpoints
The following sections provide step-by-step instructions for how to enforce model restrictions.
Requirements
- Unity Catalog must be enabled for your account.
- Account admin or metastore admin privileges. A metastore admin can grant and revoke
system.aischema permissions without an account admin. - Your account must already be enrolled in foundation model Unity Catalog permissions.
Step 1: Remove EXECUTE permission from the schema
Removing EXECUTE from the system.ai schema clears all default access to models. No user can invoke any model until permissions are explicitly re-granted.
- Go to Catalog. Select the system catalog, then the ai schema. Click the Permissions tab.
- Revoke
EXECUTEfrom All Users (or from all groups).
Important
After you remove EXECUTE from the schema, pay-per-token and batch inference (AI Functions) calls to all models stop immediately. Provisioned throughput endpoints continue serving until manually deleted.
Step 2: Grant EXECUTE on approved models
For each model your organization approves, selectively grant EXECUTE privilege.
- In Catalog Explorer, under the system catalog, select ai > models, then your target model.
- Click the Permissions tab.
- Grant
EXECUTEto All Users, or to specific groups.
Repeat for each approved model. This creates an allow-list of permitted models.
Step 3: Remove disallowed provisioned throughput endpoints
Delete all provisioned throughput endpoints that serve a disallowed model. Active endpoints continue serving until removed.
Pay-per-token and batch inference (AI Functions) endpoints automatically enforce the new permissions. Provisioned throughput endpoints do not, so you must manually delete the disallowed endpoints.
Limitations
- Custom agents deployed to Model Serving using automatic authentication passthrough are not compatible with this feature. Deploy the agent to a Databricks App instead.
- Knowledge Assistant does not support foundation model Unity Catalog permissions. If you actively use Knowledge Assistant, contact your Databricks account team before you remove
EXECUTEfrom thesystem.aischema.