Databricks releases, every cloud
- Metastore-level ABAC policies are in Beta
Applies across every catalog in the metastore. Replaces per-catalog policy setup.
- ABAC DENY policies are in Beta
Explicitly deny MANAGE ACCESS CONTROL privilege, taking precedence over grants.
- The INSERT, UPDATE, and DELETE privileges are in Beta
Require Databricks Runtime 18.1 or above, alternative to MODIFY privilege.
- Serverless outbound Private Service Connect to customer-managed resources (Public Preview)
Keeps traffic off the public internet, adding network-layer defense against data exfiltration through customer-managed Google Cloud service attachment.
- Role-based access control (RBAC) is in Public Preview
Lets users assume a role with limited permissions. Requires account and workspace admin setup.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Custom URLs for your Databricks account (Public Preview)
Replaces default URL, requires claim and enable process.
- Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs
- Thinking Machine Labs Inkling now available as a Databricks-hosted model in Public Preview
Supports text and image inputs with a 1 million token context window. Access via Foundation Model APIs.
- Restrict access to AI Functions with Unity Catalog permissions (Public Preview)
Requires account team enablement, restricts access to task-specific AI Functions.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Block specific internet destinations in network policies (Public Preview)
Blocks destinations regardless of network access mode, enforced through REST API.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Omnigent coding agent meta-harness is now in Beta
Wraps coding agents like Claude Code and Codex with a common platform. Swap runtimes with one line of configuration.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - ai_classify and ai_extract now support v2 signatures (Public Preview)
Supports improved quality and performance with native composability with ai_parse_document.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - HITRUST compliance controls (Public Preview)
Manages risk and demonstrates security and privacy compliance. Requires enabling in settings.
- Qwen3-Embedding-0.6B now available in Public Preview as a Databricks-hosted model
Accessible via Foundation Model APIs on a pay-per-token basis.
- Managed MCP servers is now Public Preview
Allows AI agents to connect to Databricks resources and external APIs.
- Context based ingress control is now in Public Preview
Enables account admins to set allow and deny rules based on identity, request type, and network source.
- Automatic email notifications for expiring personal access tokens (Public Preview)
Sends emails 7 days before token expiration.
- AI agents: Authorize on-behalf-of-user Public Preview
Lets agents act as the Databricks user who runs the query for added security.
- Admins can now manage a workspace's serverless base environments (Public Preview)
Defines custom environment specs for serverless notebooks, allows setting a default for new notebooks.
- Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest
- External MCP servers are in Beta
Enables agent access to external tools, requires connecting to Model Context Protocol servers.
Headlines, dates and product areas are Databricks' own, from the release notes published for each cloud, and every item links to the note it came from. The one-line summaries are ours. Not a Databricks product and not affiliated with Databricks, Inc.