Azure Purview无法启动Azure Synapse Analytics无服务器池扫描的权限问题排查
Alright, let's dig into the possible permission issues you're facing with scanning your Synapse Serverless pool's mango database in Purview. You've already checked off several key steps, but here are some often-overlooked causes to investigate:
You didn't assign the
db_ownerrole toOrange-accountin themangodatabase itself
You created the external user forOrange-accountinmango, but only added them todb_ownerin themasterdatabase. Purview needs explicit permissions on the target database it's trying to scan. Run this command directly in themangodatabase:EXEC sp_addrolemember 'db_owner', [Orange-account];You might be targeting the wrong identity for permissions
If you're using Purview's Managed Identity (MI) to run the scan (this is the default setting for most Purview scans), you need to grant permissions to the Purview MI—not the Purview account nameOrange-account. The MI has a unique name (usually matching your Purview account, but confirm it in the Azure Portal under your Purview account's "Managed Identity" tab). You'll need to:- Create the MI as an external user in both
masterandmangodatabases. - Add the MI to the
db_ownerrole in both databases. - Make sure the MI has
Synapse Administrator(or at leastSynapse SQL Administrator) rights on your Synapse workspace.
- Create the MI as an external user in both
Synapse workspace firewall is blocking Purview's access
Serverless pools in Synapse respect network firewall rules. Double-check:- In your Synapse workspace's "Firewalls and virtual networks" settings, ensure the toggle for "Allow Azure services and resources to access this workspace" is turned on. This lets Purview's service connect to your Synapse instance.
- If you're using private endpoints for Synapse, you'll need to set up a private link connection between Purview and Synapse to enable access over your private network.
Permissions haven't finished syncing across Azure services
Azure AD and Synapse don't always apply permission changes instantly—it can take 5-15 minutes for updates to propagate across services. If you tested right after configuring permissions, wait a bit, refresh Purview Studio, and try again. Sometimes re-registering the Synapse source in Purview can help kick off the sync.Your Synapse source registration in Purview has a narrow scope
When you registered your Synapse instance in Purview, make sure the registration includes the serverless pool and its databases. If you only selected dedicated pools during registration, the serverless databases won't show up in the dropdown. Edit the source registration to expand the scope to include all pools and databases.You need higher server-level permissions in Synapse
WhileSynapse Administratorshould give broad access, serverless pools sometimes require explicitCONTROL SERVERpermissions on themasterdatabase to list all available databases. If nothing else works, try running this in themasterdatabase (note: this is a high-level permission, use cautiously):GRANT CONTROL SERVER TO [Orange-account];
内容的提问来源于stack exchange,提问作者Aravind

