Databricks releases, every cloud
- Metastore-level ABAC policies are in Beta
Applies across every catalog in the metastore. Replaces per-catalog policy setup.
- ABAC DENY policies are in Beta
Explicitly deny MANAGE ACCESS CONTROL privilege, taking precedence over grants.
- Private network gateway is in Beta
Connects serverless compute to VNet and on-premises systems through a managed gateway. Enabled from account console Previews page.
- Private network gateway is in Private Preview
Connects serverless compute to VPC and on-premises systems through a managed gateway, reusing existing network connectivity configuration.
- The INSERT, UPDATE, and DELETE privileges are in Beta
Require Databricks Runtime 18.1 or above, alternative to MODIFY privilege.
- Role-based access control (RBAC) is in Public Preview
Lets users assume a role with limited permissions. Requires account and workspace admin setup.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs
- Custom URLs for your Azure Databricks account (Public Preview)
Replaces default Azure Databricks URL with a custom domain.
- Block specific internet destinations in network policies (Public Preview)
Blocks destinations regardless of network access mode, enforced through REST API.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Intra-VNet NSG rule hardening for Azure Databricks is now in Public Preview
Restricts workspace traffic to host and worker subnet CIDRs. Applies to classic compute plane workspaces.
- Lakebase Change Data Feed (CDF) is now in Public Preview
Captures row-level changes from Postgres tables as Delta tables, requiring no external CDC stack.
- Inbound Private Link for performance-intensive services (Public Preview)
Enables private connectivity for Zerobus Ingest and Lakebase Autoscaling.
- Context based ingress control is now in Public Preview
Enables account admins to set allow and deny rules based on identity, request type, and network source.
- Automatic email notifications for expiring personal access tokens (Public Preview)
Sends emails 7 days before token expiration.
- TISAX compliance controls (Public Preview)
Enhances workspace compliance based on ISO/IEC 27001 and VDA ISA requirements.
- C5 and K-FSI compliance standards (Public Preview)
Adds German and Korean financial regulations compliance. Requires public preview setup.
- List MCP servers in Azure Databricks Marketplace (Public Preview)
Allows distribution of AI tools and connection to external data sources, requires provider listing.
- Budget policy support for Lakebase database instances and synced tables (Public Preview)
Tags database instances and synced tables for billing attribution, also supports custom tags for compute usage.
- Lakebase Public Preview enabled by default
No admin enablement required, can be disabled by admins.
- Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest
Headlines, dates and product areas are Databricks' own, and every item links to the note it came from. The one-line summaries are ours.