Databricks releases, every cloud
| Release | Date | ||||
|---|---|---|---|---|---|
| Block identities from your Azure Databricks account with the account access denylist Prevents access when automatic identity management is enabled, blocking specific users, groups, or service principals. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | May 6, 2026 |
| Automatic identity management Syncs users and groups from identity providers like Microsoft Entra ID and Okta. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | On SAP, read it on their docs | May 5, 2026 |
| Azure UK South now has a dedicated regional control plane New workspaces require firewall allowlist entries for SCC relay tunnel and other IPs. Existing workspaces use UK West control plane unless migrated. | Not on AWS | On Azure, read it on their docs | Not on GCP | On SAP, read it on their docs | May 1, 2026 |
| Configure private endpoints for serverless compute in Azure China Requires China North 3 region and network connectivity configuration. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Apr 29, 2026 |
| Connect Azure Databricks to on-premises resources using an SSH reverse tunnel Replaces inbound firewall access, works with classic and serverless compute. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Apr 28, 2026 |
| Connect Databricks to on-premises resources using an SSH reverse tunnel Uses proxy VMs in AWS, replacing inbound firewall access. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Not on SAP | Apr 28, 2026 |
| Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs | |||||
| Azure Databricks Excel Add-in requires workspace preview enablement Enabled from the Previews page by a workspace admin. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Apr 24, 2026 |
| Databricks Excel Add-in requires workspace preview enablement Enabled from the Previews page by a workspace admin. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Not on SAP | Apr 24, 2026 |
| Workspace object permissions will soon be inherited from all account groups Coming soon Inherited permissions include inactive grants from removed groups, potentially giving unexpected access. Users still need workspace assignment. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Apr 23, 2026 |
| Customer-managed keys now support model serving Encrypts model serving container images and model artifacts in Databricks managed registry. Applies to endpoint artifacts created after April 16, 2026. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Apr 16, 2026 |
| Connect Lovable apps to Azure Databricks Uses REST API and OAuth authentication. Requires machine-to-machine authentication setup. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Apr 13, 2026 |
| Connect Lovable apps to Databricks Uses REST API and OAuth machine-to-machine authentication. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Not on SAP | Apr 13, 2026 |
| C5, TISAX, and K-FSI compliance controls are now generally available Available on Azure, providing enhancements for workspace compliance requirements. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Apr 10, 2026 |
| Upcoming breaking change: default behavior when deleting a Unity Catalog pipeline Coming soon Deletes now retain associated tables by default, set cascade=true to remove them. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Apr 9, 2026 |
| Scoped personal access tokens are now generally available Restrict tokens to specific API operations with specified permissions. Coming soon to compliance security profile workspaces. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Apr 8, 2026 |
| Customer-managed keys for Unity Catalog are generally available Encrypts data in Unity Catalog catalogs using cloud KMS keys. Requires default storage. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Not on SAP | Apr 1, 2026 |
| Databricks Documentation site table of contents tabs Replaces static sidebar with tabbed navigation, includes 6 context tabs. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Not on SAP | Mar 31, 2026 |
| Databricks Connector for Google Sheets updates Longer query execution timeout and UI improvements added. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Mar 30, 2026 |
| Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest | |||||
| Databricks JDBC driver 2.8.0 is available Replaces Log4j with SLF4J 2.0.13, enables telemetry by default. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Mar 18, 2026 |
| Inbound Private Link for performance-intensive services (Public Preview) Enables private connectivity for Zerobus Ingest and Lakebase Autoscaling. | On AWS, read it on their docs | On Azure, read it on their docs | Not on GCP | Not on SAP | Mar 9, 2026 |
| Serverless compute now available for IRAP and Canada Protected B workloads on Azure Databricks Requires environment version 5 to be enabled. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Mar 6, 2026 |
| Connect to Azure Databricks from Microsoft Excel (Public Preview) Imports data from tables or Metric Views, executes SQL queries in Excel. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Mar 2, 2026 |
| Connect to Databricks from Microsoft Excel (Public Preview) Imports data from tables or Metric Views, executes SQL queries in Excel. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Not on SAP | Mar 2, 2026 |
| Customer-managed keys for Unity Catalog Uses own encryption keys for Unity Catalog data. Replaces automatic encryption. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Mar 2, 2026 |
| Customer-managed keys for Unity Catalog (Beta) Uses own encryption keys for Unity Catalog catalogs. Replaces automatic encryption. | Not on AWS | Not on Azure | On GCP, read it on their docs | Not on SAP | Mar 2, 2026 |
| Customer-managed keys for Unity Catalog (Public Preview) Protects data with user-owned encryption keys, replacing automatic encryption. | On AWS, read it on their docs | Not on Azure | Not on GCP | Not on SAP | Mar 2, 2026 |
| Schedule data refreshes in Google Sheets (Public Preview) Refreshes occur hourly, daily, or weekly. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Mar 2, 2026 |
| Update workspace network configuration to VNet injection is now GA Migrates from Databricks-managed VNet to customer-owned VNet. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Mar 2, 2026 |
| HITRUST compliance controls (Public Preview) Manages risk and demonstrates security and privacy compliance. Requires enabling in settings. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Feb 26, 2026 |
| ISMAP compliance support Supports Japanese government cloud certification, requires configuration changes. | On AWS, read it on their docs | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Feb 26, 2026 |
| Serverless outbound IPs available through public JSON endpoint (Public Preview) Replaces existing stable IPs, requires Public Preview enrollment. | On AWS, read it on their docs | Not on Azure | Not on GCP | Unknown on SAP | Feb 25, 2026 |
| Change to use_case field in VPC endpoint API responses Coming soon Changes from WORKSPACE_ACCESS to GENERAL_ACCESS, see API docs for details. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Feb 24, 2026 |
| Azure virtual network service endpoint policies are now generally available Apply to classic compute for outbound storage access filtering. Requires configuration. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Feb 23, 2026 |
| Personal access tokens preserved when CAN USE permission is revoked Tokens become unusable but not deleted when permission is revoked, and reactivate if restored. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Feb 23, 2026 |
| Enhanced Security and Compliance add-on is now generally available includes compliance security profile and enhanced security monitoring. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Feb 19, 2026 |
| Inbound Private Link for performance-intensive services (Beta) Enables private connectivity to Zerobus Ingest and Lakebase Autoscaling. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Feb 18, 2026 |
| Scoped personal access tokens (Beta) Limits permissions by selecting token type and API scopes, replacing legacy tokens. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Feb 18, 2026 |
| Automatic identity management deactivates deleted Entra ID users Replaces "Active: Removed From EntraID" status with Deactivated. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Feb 16, 2026 |
| Serverless egress control is now generally available Manages outbound connections with restricted access and FQDN filtering. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Feb 9, 2026 |
| Select tables and create pivot tables in Google Sheets Imports data via Databricks Connector, selecting from Catalog Explorer. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Feb 3, 2026 |
- Block identities from your Azure Databricks account with the account access denylist
Prevents access when automatic identity management is enabled, blocking specific users, groups, or service principals.
- Automatic identity management
Syncs users and groups from identity providers like Microsoft Entra ID and Okta.
AWS, read it on their docsAzure(not on this cloud)GCP, read it on their docsSAP, read it on their docs - Azure UK South now has a dedicated regional control plane
New workspaces require firewall allowlist entries for SCC relay tunnel and other IPs. Existing workspaces use UK West control plane unless migrated.
- Configure private endpoints for serverless compute in Azure China
Requires China North 3 region and network connectivity configuration.
- Connect Azure Databricks to on-premises resources using an SSH reverse tunnel
Replaces inbound firewall access, works with classic and serverless compute.
- Connect Databricks to on-premises resources using an SSH reverse tunnel
Uses proxy VMs in AWS, replacing inbound firewall access.
- Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs
- Azure Databricks Excel Add-in requires workspace preview enablement
Enabled from the Previews page by a workspace admin.
- Databricks Excel Add-in requires workspace preview enablement
Enabled from the Previews page by a workspace admin.
- Workspace object permissions will soon be inherited from all account groups Coming soon
Inherited permissions include inactive grants from removed groups, potentially giving unexpected access. Users still need workspace assignment.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Customer-managed keys now support model serving
Encrypts model serving container images and model artifacts in Databricks managed registry. Applies to endpoint artifacts created after April 16, 2026.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Connect Lovable apps to Azure Databricks
Uses REST API and OAuth authentication. Requires machine-to-machine authentication setup.
- Connect Lovable apps to Databricks
Uses REST API and OAuth machine-to-machine authentication.
- C5, TISAX, and K-FSI compliance controls are now generally available
Available on Azure, providing enhancements for workspace compliance requirements.
- Upcoming breaking change: default behavior when deleting a Unity Catalog pipeline Coming soon
Deletes now retain associated tables by default, set cascade=true to remove them.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Scoped personal access tokens are now generally available
Restrict tokens to specific API operations with specified permissions. Coming soon to compliance security profile workspaces.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Customer-managed keys for Unity Catalog are generally available
Encrypts data in Unity Catalog catalogs using cloud KMS keys. Requires default storage.
- Databricks Documentation site table of contents tabs
Replaces static sidebar with tabbed navigation, includes 6 context tabs.
- Databricks Connector for Google Sheets updates
Longer query execution timeout and UI improvements added.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest
- Databricks JDBC driver 2.8.0 is available
Replaces Log4j with SLF4J 2.0.13, enables telemetry by default.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Inbound Private Link for performance-intensive services (Public Preview)
Enables private connectivity for Zerobus Ingest and Lakebase Autoscaling.
- Serverless compute now available for IRAP and Canada Protected B workloads on Azure Databricks
Requires environment version 5 to be enabled.
- Connect to Azure Databricks from Microsoft Excel (Public Preview)
Imports data from tables or Metric Views, executes SQL queries in Excel.
- Connect to Databricks from Microsoft Excel (Public Preview)
Imports data from tables or Metric Views, executes SQL queries in Excel.
- Customer-managed keys for Unity Catalog
Uses own encryption keys for Unity Catalog data. Replaces automatic encryption.
- Customer-managed keys for Unity Catalog (Beta)
Uses own encryption keys for Unity Catalog catalogs. Replaces automatic encryption.
- Customer-managed keys for Unity Catalog (Public Preview)
Protects data with user-owned encryption keys, replacing automatic encryption.
- Schedule data refreshes in Google Sheets (Public Preview)
Refreshes occur hourly, daily, or weekly.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Update workspace network configuration to VNet injection is now GA
Migrates from Databricks-managed VNet to customer-owned VNet.
- HITRUST compliance controls (Public Preview)
Manages risk and demonstrates security and privacy compliance. Requires enabling in settings.
- ISMAP compliance support
Supports Japanese government cloud certification, requires configuration changes.
- Serverless outbound IPs available through public JSON endpoint (Public Preview)
Replaces existing stable IPs, requires Public Preview enrollment.
- Change to use_case field in VPC endpoint API responses Coming soon
Changes from WORKSPACE_ACCESS to GENERAL_ACCESS, see API docs for details.
- Azure virtual network service endpoint policies are now generally available
Apply to classic compute for outbound storage access filtering. Requires configuration.
- Personal access tokens preserved when CAN USE permission is revoked
Tokens become unusable but not deleted when permission is revoked, and reactivate if restored.
- Enhanced Security and Compliance add-on is now generally available
includes compliance security profile and enhanced security monitoring.
- Inbound Private Link for performance-intensive services (Beta)
Enables private connectivity to Zerobus Ingest and Lakebase Autoscaling.
- Scoped personal access tokens (Beta)
Limits permissions by selecting token type and API scopes, replacing legacy tokens.
- Automatic identity management deactivates deleted Entra ID users
Replaces "Active: Removed From EntraID" status with Deactivated.
- Serverless egress control is now generally available
Manages outbound connections with restricted access and FQDN filtering.
- Select tables and create pivot tables in Google Sheets
Imports data via Databricks Connector, selecting from Catalog Explorer.
Headlines, dates and product areas are Databricks' own, and every item links to the note it came from. The one-line summaries are ours.