Kostavo is built from the ground up for Azure Databricks. Deep Azure integration, native authentication, and governance that speaks your cloud language.
Microsoft Entra SSO. Service principal authentication. No separate identity system to manage.
Use your existing Azure resource tags for policy assignment. No duplicate tagging required.
Connect securely to workspaces behind Azure Private Link. Your data stays on your network.
SSO with your existing Microsoft Entra tenant. No separate passwords or identity system to manage.
Assign policies based on Azure resource tags. Environment, cost-center, team: any tag becomes a policy selector.
Securely connect to Databricks workspaces behind Azure Private Link. Works with your network security setup.
Azure Databricks workspaces connected via a service principal: hosts, regions, and tags in one place.
Authenticate with your existing Microsoft Entra tenant
Custom role with only the Azure permissions Kostavo needs. Workspace admin is granted inside Databricks, not at the Azure level.
Policy assignment based on Azure resource tags
Connect to workspaces behind Azure Private Link
Tag rules match on your Azure resource tags: here everything not tagged environment=production gets cost guardrails, with a live preview of the workspaces covered.
Register an app in Microsoft Entra and assign it a minimal custom role. Kostavo will elevate itself to workspace admin inside Databricks to manage resources on your behalf.
Enter your tenant ID and service principal credentials. We'll discover your workspaces.
Apply policies immediately. Auto-discovery finds all resources automatically.
Connect your first Azure Databricks workspace in 5 minutes.