Held at metastore level, it records which JAR files, Maven libraries and init scripts may run on compute using the standard access mode. It begins with no entries, and only holders of MANAGE ALLOWLIST may change it.
Also called artifact allowlist.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Allowlist in context, with comparison tables and the common traps.
Terms in this definition
- Metastore
The highest-level Unity Catalog container, holding metadata and permissions for a single cloud region. Each region has only one, which every workspace in that region shares, and it is not meant to be the usual boundary for isolating data.
- JAR
Java or Scala code, compiled and packaged as a single archive. In Lakeflow Jobs, a JAR task invokes the archive's main class; on standard access mode compute the JAR must first be allowlisted.
- Maven
Java's build tool and packaging format. GitHub Packages accepts both Gradle and Maven, while Azure Artifacts feeds store these packages for Gradle clients too.
- Init scripts
Learn suggests steering clear of these where possible: shell scripts that execute on every classic compute node during boot, before Spark comes up. If you do need one, keep it cluster-scoped and store it in a volume; DBFS-hosted scripts are end-of-life.
- Standard access mode
An access mode for classic compute in which multiple users can share a cluster and run work at once, kept apart by Lakeguard and governed by Unity Catalog. It is the recommended mode unless a needed feature isn't supported.
- MANAGE
A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of
ALL PRIVILEGES.
Related terms
- Monitor mode
Restricts the Azure Connected Machine agent to security or monitoring extensions only; it also switches off machine configuration and remote connectivity, and stops anyone editing the extension allowlist.
- Restrict personal access token creation
An Azure DevOps organisation policy, for organisations backed by Microsoft Entra, that allows only people on an allowlist to create PATs, with an option to permit PATs limited to packaging. PATs that already exist carry on working until they expire.