Wraps a long-lived credential, often an Access Connector's managed identity, that external locations use to reach ADLS. It is a Unity Catalog securable, and CREATE STORAGE CREDENTIAL is needed to make one.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Storage credential in context, with comparison tables and the common traps.
Terms in this definition
- Managed identity
Identity in Microsoft Entra given to an Azure resource so that no secret has to be stored. It comes in two kinds: user-assigned and system-assigned.
- External
API Management virtual network mode in which the gateway stays public but can call private back ends inside the VNet.
- ADLS
Paths beginning
abfss://point into this: Azure Storage with the hierarchical namespace switched on. In Unity Catalog it is typically the object store under both external locations and managed storage. - Unity Catalog
Azure Databricks' governance solution covering both data and AI in one place, with centralised permissions, auditing, data discovery and lineage.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
Related terms
- External location
A securable object in Unity Catalog that combines a storage credential with a particular path in cloud object storage, so that who may read or write under that path is controlled centrally. Volumes, external tables and managed storage locations all depend on it.
- READ FILES
Granted on a storage credential or external location, this Unity Catalog permission lets tools like Auto Loader or
COPY INTOpull files directly from cloud storage.WRITE FILEScan't be used without it. - Service credential
Stores a long-lived credential so code can call cloud services that aren't storage, like Key Vault or Azure Event Hubs. It is a Unity Catalog securable used through the
ACCESSprivilege; for storage paths, use a storage credential.