Databricks releases, every cloud
- Lakeflow Designer will soon be available by default for workspaces with the compliance security profile enabled Coming soon
Replaces manual coding for data preparation and transformation. Available late July 2026.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Email notifications for expiring service principal tokens (Beta)
Sends emails to workspace admins when tokens expire in 7 days, requiring no configuration.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Identity federation enabled by default for all new workspaces
Does not affect existing workspaces.
- Reorganized Spark Declarative Pipelines on Lakeflow documentation
Conceptual topics are now under Concepts.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Upcoming behavior change: Choose entitlements when adding principals to workspaces Coming soon
Grants entitlements explicitly when adding principals, replacing inheritance from users system group.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Write data from Microsoft Excel back to Databricks
Writes to Unity Catalog tables, overwriting existing ones if needed.
- Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs
- Automatic identity management with Microsoft Entra ID is now GA
Replaces SCIM provisioning, syncs users and groups from Microsoft Entra ID.
AWS, read it on their docsAzure(not on this cloud)GCP, read it on their docsSAP, read it on their docs - Customer-managed keys now support MLflow managed evaluation features
Supports MLflow 3 scorers and requires non-CMK encrypted catalog.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Databricks Add-in for Excel support for all compliance security profile standards
Supports all Databricks compliance security profiles. Requires Public Preview.
- View run history for scheduled refreshes in Google Sheets
Shows Run ID, start time, and success status for each run.
- HIPAA support for the Databricks Add-in for Excel
Available for workspaces with HIPAA compliance across all supported regions.
- Automatic identity management
Syncs users and groups from identity providers like Microsoft Entra ID and Okta.
AWS, read it on their docsAzure(not on this cloud)GCP, read it on their docsSAP, read it on their docs - Connect Databricks to on-premises resources using an SSH reverse tunnel
Uses proxy VMs in AWS, replacing inbound firewall access.
- Databricks Excel Add-in requires workspace preview enablement
Enabled from the Previews page by a workspace admin.
- Workspace object permissions will soon be inherited from all account groups Coming soon
Inherited permissions include inactive grants from removed groups, potentially giving unexpected access. Users still need workspace assignment.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Customer-managed keys now support model serving
Encrypts model serving container images and model artifacts in Databricks managed registry. Applies to endpoint artifacts created after April 16, 2026.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Connect Lovable apps to Databricks
Uses REST API and OAuth machine-to-machine authentication.
- Upcoming breaking change: default behavior when deleting a Unity Catalog pipeline Coming soon
Deletes now retain associated tables by default, set cascade=true to remove them.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest
- Scoped personal access tokens are now generally available
Restrict tokens to specific API operations with specified permissions. Coming soon to compliance security profile workspaces.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Customer-managed keys for Unity Catalog are generally available
Encrypts data in Unity Catalog catalogs using cloud KMS keys. Requires default storage.
- Databricks Documentation site table of contents tabs
Replaces static sidebar with tabbed navigation, includes 6 context tabs.
- Databricks Connector for Google Sheets updates
Longer query execution timeout and UI improvements added.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Databricks JDBC driver 2.8.0 is available
Replaces Log4j with SLF4J 2.0.13, enables telemetry by default.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Connect to Databricks from Microsoft Excel (Public Preview)
Imports data from tables or Metric Views, executes SQL queries in Excel.
- Customer-managed keys for Unity Catalog (Beta)
Uses own encryption keys for Unity Catalog catalogs. Replaces automatic encryption.
- Schedule data refreshes in Google Sheets (Public Preview)
Refreshes occur hourly, daily, or weekly.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - HITRUST compliance controls (Public Preview)
Manages risk and demonstrates security and privacy compliance. Requires enabling in settings.
- Change to use_case field in VPC endpoint API responses Coming soon
Changes from WORKSPACE_ACCESS to GENERAL_ACCESS, see API docs for details.
- Personal access tokens preserved when CAN USE permission is revoked
Tokens become unusable but not deleted when permission is revoked, and reactivate if restored.
- Enhanced Security and Compliance add-on is now generally available
includes compliance security profile and enhanced security monitoring.
- Scoped personal access tokens (Beta)
Limits permissions by selecting token type and API scopes, replacing legacy tokens.
- Serverless egress control is now generally available
Manages outbound connections with restricted access and FQDN filtering.
- Select tables and create pivot tables in Google Sheets
Imports data via Databricks Connector, selecting from Catalog Explorer.
- Automatically provision users (JIT) GA
Creates accounts during SSO login if none exist. Requires single sign-on setup.
- Automatic email notifications for expiring personal access tokens (GA)
Sends emails 14 days before token expiration, requires token lifetime to be set.
- Context based ingress control is now in Public Preview
Enables account admins to set allow and deny rules based on identity, request type, and network source.
- Login required to download ODBC driver
Requires login and license acceptance, except for AWS GovCloud which needs account team access.
- Expanded regional availability for C5 and TISAX compliance
Now available in all regions and with serverless compute.
- Automatic email notifications for expiring personal access tokens (Public Preview)
Sends emails 7 days before token expiration.
- Delta Sharing views automatically permitted in serverless network policies
Permitted regardless of storage location alignment between shared tables and view dependencies. Simplifies network policy configuration.
Headlines, dates and product areas are Databricks' own, and every item links to the note it came from. The one-line summaries are ours.