Databricks releases, every cloud
- HITRUST and IRAP compliance controls are now generally available
Available through compliance security profile, required for HIPAA, HITRUST, and IRAP.
- ABAC GRANT policies are generally available for models and services
Replaces individual privilege grants with governed tag matching.
- Consumer access to query Unity Gateway services will become generally available Coming soon
Requires account admins to set budgets and rate limits beforehand to control model traffic.
- Role-based access control (RBAC) is generally available
Requires account and workspace admin setup. Enables exclusive access to sensitive data.
- Schema-level HTTP connections in Unity Catalog are now generally available
Creates connections inside a schema, inheriting its privileges, instead of only at metastore level.
- Python UDTFs in Unity Catalog are now generally available
Runs on serverless compute, classic compute, and SQL warehouses. Requires Databricks Runtime 18.
- Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs
- Email notifications for expiring service principal tokens are now generally available
Sends emails to workspace admins 7 days before token expiration for used tokens with lifetime over 7 days. No configuration is required.
- Context-based ingress control for workspaces public access is now generally available
Uses allow and deny rules to control access based on identities, network sources, and request types.
- MLflow trace storage in Unity Catalog is now generally available
Stores traces in OpenTelemetry format with unlimited storage and SQL query access.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - OneLake catalog federation is generally available
Allows reading OneLake data without copying, with read-only access and direct queries against file storage.
- External lineage is now generally available
Registers external assets like Salesforce or MySQL sources and Tableau dashboards. Automatically records source lineage for Lakeflow Connect pipelines.
- Inbound Private Link for performance-intensive services is now generally available
Supports Lakebase Autoscaling and Zerobus Ingest.
- Automatic identity management with Microsoft Entra ID is now GA
Replaces SCIM provisioning, syncs users and groups from Microsoft Entra ID.
AWS, read it on their docsAzure(not on this cloud)GCP, read it on their docsSAP, read it on their docs - Unity Catalog managed Apache Iceberg tables, foreign Apache Iceberg tables, and Apache Iceberg v3 features are generally available
Supports liquid clustering, predictive optimization, and materialized views. Requires Databricks Runtime or external Iceberg-compatible engines.
- Catalog commits are now generally available
Enables multi-statement transactions on Unity Catalog managed Delta tables, supported by products like MLflow and Delta Sharing.
- Attribute-based access control (ABAC) is now generally available
Uses governed tags to enforce row filter and column mask policies. Replaces per-table configuration with automatic application at catalog, schema, or table level.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Databricks Data Classification is now GA
Automatically classifies and tags sensitive data in Unity Catalog using AI.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Altering a catalog or schema's managed storage location is now GA
Modifies default cloud storage location for new managed tables and volumes.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest
- C5, TISAX, and K-FSI compliance controls are now generally available
Available on Azure, providing enhancements for workspace compliance requirements.
- Scoped personal access tokens are now generally available
Restrict tokens to specific API operations with specified permissions. Coming soon to compliance security profile workspaces.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Governed tags are generally available
Allow administrators to define controlled tags for Unity Catalog and workspace objects, enforcing consistent metadata tagging.
- Customer-managed keys for Unity Catalog are generally available
Encrypts data in Unity Catalog catalogs using cloud KMS keys. Requires default storage.
- Update workspace network configuration to VNet injection is now GA
Migrates from Databricks-managed VNet to customer-owned VNet.
- Azure virtual network service endpoint policies are now generally available
Apply to classic compute for outbound storage access filtering. Requires configuration.
- Enhanced Security and Compliance add-on is now generally available
includes compliance security profile and enhanced security monitoring.
- Serverless egress control is now generally available
Manages outbound connections with restricted access and FQDN filtering.
- GCP Private Service Connect generally available
No account team request needed to enable.
Headlines, dates and product areas are Databricks' own, from the release notes published for each cloud, and every item links to the note it came from. The one-line summaries are ours. Not a Databricks product and not affiliated with Databricks, Inc.