Skip to content

Databricks releases, every cloud

124 releases of 1321

Last updated

  1. Block identities from your Azure Databricks account with the account access denylist

    Prevents access when automatic identity management is enabled, blocking specific users, groups, or service principals.

    AWS(not on this cloud)Azure, read it on their docsGCP(not on this cloud)SAP(not on this cloud)
  2. Automatic identity management

    Syncs users and groups from identity providers like Microsoft Entra ID and Okta.

  3. Azure UK South now has a dedicated regional control plane

    New workspaces require firewall allowlist entries for SCC relay tunnel and other IPs. Existing workspaces use UK West control plane unless migrated.

    AWS(not on this cloud)Azure, read it on their docsGCP(not on this cloud)SAP, read it on their docs
  4. Configure private endpoints for serverless compute in Azure China

    Requires China North 3 region and network connectivity configuration.

    AWS(not on this cloud)Azure, read it on their docsGCP(not on this cloud)SAP(not on this cloud)
  5. Connect Azure Databricks to on-premises resources using an SSH reverse tunnel

    Replaces inbound firewall access, works with classic and serverless compute.

    AWS(not on this cloud)Azure, read it on their docsGCP(not on this cloud)SAP(not on this cloud)
  6. Connect Databricks to on-premises resources using an SSH reverse tunnel

    Uses proxy VMs in AWS, replacing inbound firewall access.

    AWS, read it on their docsAzure(not on this cloud)GCP, read it on their docsSAP(not on this cloud)
  7. Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs
  8. Workspace object permissions will soon be inherited from all account groups Coming soon

    Inherited permissions include inactive grants from removed groups, potentially giving unexpected access. Users still need workspace assignment.

  9. Compute log delivery to volumes is now GA

    Delivers Spark driver, worker, and event logs to Unity Catalog volumes, recommended for log storage.

  10. Customer-managed keys now support model serving

    Encrypts model serving container images and model artifacts in Databricks managed registry. Applies to endpoint artifacts created after April 16, 2026.

  11. C5, TISAX, and K-FSI compliance controls are now generally available

    Available on Azure, providing enhancements for workspace compliance requirements.

    AWS(not on this cloud)Azure, read it on their docsGCP(not on this cloud)SAP(not on this cloud)
  12. Scoped personal access tokens are now generally available

    Restrict tokens to specific API operations with specified permissions. Coming soon to compliance security profile workspaces.

  13. Customer-managed keys for Unity Catalog are generally available

    Encrypts data in Unity Catalog catalogs using cloud KMS keys. Requires default storage.

    AWS, read it on their docsAzure(not on this cloud)GCP, read it on their docsSAP(not on this cloud)
  14. Serverless compute is enabled by default

    Eligible Google Cloud workspaces are affected, account admins no longer need to manually enable it.

    AWS(not on this cloud)Azure(not on this cloud)GCP, read it on their docsSAP(not on this cloud)
  15. Inbound Private Link for performance-intensive services (Public Preview)

    Enables private connectivity for Zerobus Ingest and Lakebase Autoscaling.

    AWS, read it on their docsAzure, read it on their docsGCP(not on this cloud)SAP(not on this cloud)
  16. Serverless compute now available for IRAP and Canada Protected B workloads on Azure Databricks

    Requires environment version 5 to be enabled.

    AWS(not on this cloud)Azure, read it on their docsGCP(not on this cloud)SAP(not on this cloud)
  17. Customer-managed keys for Unity Catalog

    Uses own encryption keys for Unity Catalog data. Replaces automatic encryption.

    AWS(not on this cloud)Azure, read it on their docsGCP(not on this cloud)SAP(not on this cloud)
  18. Customer-managed keys for Unity Catalog (Beta)

    Uses own encryption keys for Unity Catalog catalogs. Replaces automatic encryption.

    AWS(not on this cloud)Azure(not on this cloud)GCP, read it on their docsSAP(not on this cloud)
  19. Customer-managed keys for Unity Catalog (Public Preview)

    Protects data with user-owned encryption keys, replacing automatic encryption.

    AWS, read it on their docsAzure(not on this cloud)GCP(not on this cloud)SAP(not on this cloud)
  20. Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest
  21. Update workspace network configuration to VNet injection is now GA

    Migrates from Databricks-managed VNet to customer-owned VNet.

    AWS(not on this cloud)Azure, read it on their docsGCP(not on this cloud)SAP(not on this cloud)
  22. HITRUST compliance controls (Public Preview)

    Manages risk and demonstrates security and privacy compliance. Requires enabling in settings.

    AWS, read it on their docsAzure(not on this cloud)GCP, read it on their docsSAP(unknown)
  23. ISMAP compliance support

    Supports Japanese government cloud certification, requires configuration changes.

    AWS, read it on their docsAzure, read it on their docsGCP(not on this cloud)SAP(unknown)
  24. Serverless outbound IPs available through public JSON endpoint (Public Preview)

    Replaces existing stable IPs, requires Public Preview enrollment.

    AWS, read it on their docsAzure(not on this cloud)GCP(not on this cloud)SAP(unknown)
  25. Azure virtual network service endpoint policies are now generally available

    Apply to classic compute for outbound storage access filtering. Requires configuration.

    AWS(not on this cloud)Azure, read it on their docsGCP(not on this cloud)SAP(unknown)
  26. Personal access tokens preserved when CAN USE permission is revoked

    Tokens become unusable but not deleted when permission is revoked, and reactivate if restored.

  27. Enhanced Security and Compliance add-on is now generally available

    includes compliance security profile and enhanced security monitoring.

    AWS(not on this cloud)Azure(not on this cloud)GCP, read it on their docsSAP(unknown)
  28. Inbound Private Link for performance-intensive services (Beta)

    Enables private connectivity to Zerobus Ingest and Lakebase Autoscaling.

    AWS(not on this cloud)Azure, read it on their docsGCP(not on this cloud)SAP(unknown)
  29. Scoped personal access tokens (Beta)

    Limits permissions by selecting token type and API scopes, replacing legacy tokens.

  30. Automatic identity management deactivates deleted Entra ID users

    Replaces "Active: Removed From EntraID" status with Deactivated.

    AWS(not on this cloud)Azure, read it on their docsGCP(not on this cloud)SAP(unknown)
  31. Serverless egress control is now generally available

    Manages outbound connections with restricted access and FQDN filtering.

    AWS(not on this cloud)Azure(not on this cloud)GCP, read it on their docsSAP(unknown)
  32. Automatically provision users (JIT) GA

    Creates accounts during SSO login if none exist. Requires single sign-on setup.

    AWS(not on this cloud)Azure(not on this cloud)GCP, read it on their docsSAP(unknown)
  33. Improved group sharing for automatic identity management

    Shares account-level assets with Microsoft Entra ID groups. Requires automatic identity management.

    AWS(not on this cloud)Azure, read it on their docsGCP(not on this cloud)SAP(unknown)
  34. Front-end PrivateLink for performance-intensive services (Beta)

    Supports private connectivity to Zerobus Ingest and Lakebase Autoscaling.

    AWS, read it on their docsAzure(not on this cloud)GCP(not on this cloud)SAP(unknown)
  35. Simplified serverless network security with Azure Network Security Perimeter

    Uses AzureDatabricksServerless service tag, replacing subnet-based rules.

    AWS(not on this cloud)Azure, read it on their docsGCP(not on this cloud)SAP(unknown)
  36. Automatic email notifications for expiring personal access tokens (GA)

    Sends emails 14 days before token expiration, requires token lifetime to be set.

  37. Context based ingress control is now in Public Preview

    Enables account admins to set allow and deny rules based on identity, request type, and network source.

  38. Flexible node types are now generally available

    Falls back to alternative instance types when specified type is unavailable, improving launch reliability.

  39. Expanded regional availability for C5 and TISAX compliance

    Now available in all regions and with serverless compute.

    AWS, read it on their docsAzure(not on this cloud)GCP, read it on their docsSAP(unknown)
  40. Automatic email notifications for expiring personal access tokens (Public Preview)

    Sends emails 7 days before token expiration.

  41. Delta Sharing views automatically permitted in serverless network policies

    Permitted regardless of storage location alignment between shared tables and view dependencies. Simplifies network policy configuration.

  42. TISAX compliance controls (Public Preview)

    Enhances workspace compliance based on ISO/IEC 27001 and VDA ISA requirements.

    AWS(not on this cloud)Azure, read it on their docsGCP(not on this cloud)SAP(unknown)

Headlines, dates and product areas are Databricks' own, from the release notes published for each cloud, and every item links to the note it came from. The one-line summaries are ours. Not a Databricks product and not affiliated with Databricks, Inc.