Databricks releases, every cloud
| Release | Date | ||||
|---|---|---|---|---|---|
| Metastore-level ABAC policies are in Beta Applies across every catalog in the metastore. Replaces per-catalog policy setup. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Sep 17, 2026 |
| ABAC DENY policies are in Beta Explicitly deny MANAGE ACCESS CONTROL privilege, taking precedence over grants. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Sep 8, 2026 |
| Private network gateway is in Beta Connects serverless compute to VNet and on-premises systems through a managed gateway. Enabled from account console Previews page. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Sep 3, 2026 |
| Genie Code for AI Runtime (Public Preview) Generates distributed training code and resolves environment issues. Requires AI Runtime. | On AWS, read it on their docs | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Aug 27, 2026 |
| Private network gateway is in Private Preview Connects serverless compute to VPC and on-premises systems through a managed gateway, reusing existing network connectivity configuration. | On AWS, read it on their docs | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Aug 24, 2026 |
| The INSERT, UPDATE, and DELETE privileges are in Beta Require Databricks Runtime 18.1 or above, alternative to MODIFY privilege. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 24, 2026 |
| Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs | |||||
| Serverless outbound Private Service Connect to customer-managed resources (Public Preview) Keeps traffic off the public internet, adding network-layer defense against data exfiltration through customer-managed Google Cloud service attachment. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Aug 6, 2026 |
| Web terminal on serverless GPU compute (AI Runtime) is in Public Preview Runs shell commands, monitors GPU usage, and manages files on serverless GPU compute. Requires environment version 5 or above. | On AWS, read it on their docs | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Jul 31, 2026 |
| Role-based access control (RBAC) is in Public Preview Lets users assume a role with limited permissions. Requires account and workspace admin setup. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Jul 22, 2026 |
| Custom URLs for your Azure Databricks account (Public Preview) Replaces default Azure Databricks URL with a custom domain. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jul 15, 2026 |
| Custom URLs for your Databricks account (Public Preview) Replaces default URL, requires claim and enable process. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Not on SAP | Jul 15, 2026 |
| Protobuf tensor input for custom model serving endpoints (Public Preview) Replaces JSON with serialized KServe v2 ModelInferRequest. Requires endpoints deployed after July 9, 2026. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Jul 9, 2026 |
| Block specific internet destinations in network policies (Public Preview) Blocks destinations regardless of network access mode, enforced through REST API. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Jun 23, 2026 |
| Intra-VNet NSG rule hardening for Azure Databricks is now in Public Preview Restricts workspace traffic to host and worker subnet CIDRs. Applies to classic compute plane workspaces. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 1, 2026 |
| Configure Microsoft Entra ID SSO for Power BI (Public Preview) Uses account-level federation policy, replacing manual config. | On AWS, read it on their docs | Not on Azure | Not on GCP | Not on SAP | May 20, 2026 |
| AI Runtime is now in Public Preview Adds GPU support to serverless compute for deep learning workloads. | On AWS, read it on their docs | On Azure, read it on their docs | Not on GCP | Not on SAP | Mar 19, 2026 |
| Inbound Private Link for performance-intensive services (Public Preview) Enables private connectivity for Zerobus Ingest and Lakebase Autoscaling. | On AWS, read it on their docs | On Azure, read it on their docs | Not on GCP | Not on SAP | Mar 9, 2026 |
| Customer-managed keys for Unity Catalog (Public Preview) Protects data with user-owned encryption keys, replacing automatic encryption. | On AWS, read it on their docs | Not on Azure | Not on GCP | Not on SAP | Mar 2, 2026 |
| Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest | |||||
| HITRUST compliance controls (Public Preview) Manages risk and demonstrates security and privacy compliance. Requires enabling in settings. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Feb 26, 2026 |
| Serverless outbound IPs available through public JSON endpoint (Public Preview) Replaces existing stable IPs, requires Public Preview enrollment. | On AWS, read it on their docs | Not on Azure | Not on GCP | Unknown on SAP | Feb 25, 2026 |
| Context based ingress control is now in Public Preview Enables account admins to set allow and deny rules based on identity, request type, and network source. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Dec 17, 2025 |
| Automatic email notifications for expiring personal access tokens (Public Preview) Sends emails 7 days before token expiration. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Nov 20, 2025 |
| TISAX compliance controls (Public Preview) Enhances workspace compliance based on ISO/IEC 27001 and VDA ISA requirements. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Nov 13, 2025 |
| C5 and K-FSI compliance standards (Public Preview) Adds German and Korean financial regulations compliance. Requires public preview setup. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Nov 6, 2025 |
| Configure Azure virtual network service policies for storage access (Public Preview) Filters outbound traffic from classic compute to specific Azure Storage accounts. Requires Azure virtual network service endpoint policies. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Oct 1, 2025 |
| Updates for customer-managed VPC workspaces (Public Preview) Adds Private Service Connect conversion and network config changes. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Aug 22, 2025 |
| Updating workspace virtual network configurations is now in Public Preview Allows migration to custom VNet or changes to existing VNet injection setups. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Aug 22, 2025 |
- Metastore-level ABAC policies are in Beta
Applies across every catalog in the metastore. Replaces per-catalog policy setup.
- ABAC DENY policies are in Beta
Explicitly deny MANAGE ACCESS CONTROL privilege, taking precedence over grants.
- Private network gateway is in Beta
Connects serverless compute to VNet and on-premises systems through a managed gateway. Enabled from account console Previews page.
- Genie Code for AI Runtime (Public Preview)
Generates distributed training code and resolves environment issues. Requires AI Runtime.
- Private network gateway is in Private Preview
Connects serverless compute to VPC and on-premises systems through a managed gateway, reusing existing network connectivity configuration.
- The INSERT, UPDATE, and DELETE privileges are in Beta
Require Databricks Runtime 18.1 or above, alternative to MODIFY privilege.
- Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs
- Serverless outbound Private Service Connect to customer-managed resources (Public Preview)
Keeps traffic off the public internet, adding network-layer defense against data exfiltration through customer-managed Google Cloud service attachment.
- Web terminal on serverless GPU compute (AI Runtime) is in Public Preview
Runs shell commands, monitors GPU usage, and manages files on serverless GPU compute. Requires environment version 5 or above.
- Role-based access control (RBAC) is in Public Preview
Lets users assume a role with limited permissions. Requires account and workspace admin setup.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Custom URLs for your Azure Databricks account (Public Preview)
Replaces default Azure Databricks URL with a custom domain.
- Custom URLs for your Databricks account (Public Preview)
Replaces default URL, requires claim and enable process.
- Protobuf tensor input for custom model serving endpoints (Public Preview)
Replaces JSON with serialized KServe v2 ModelInferRequest. Requires endpoints deployed after July 9, 2026.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Block specific internet destinations in network policies (Public Preview)
Blocks destinations regardless of network access mode, enforced through REST API.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Intra-VNet NSG rule hardening for Azure Databricks is now in Public Preview
Restricts workspace traffic to host and worker subnet CIDRs. Applies to classic compute plane workspaces.
- Configure Microsoft Entra ID SSO for Power BI (Public Preview)
Uses account-level federation policy, replacing manual config.
- AI Runtime is now in Public Preview
Adds GPU support to serverless compute for deep learning workloads.
- Inbound Private Link for performance-intensive services (Public Preview)
Enables private connectivity for Zerobus Ingest and Lakebase Autoscaling.
- Customer-managed keys for Unity Catalog (Public Preview)
Protects data with user-owned encryption keys, replacing automatic encryption.
- Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest
- HITRUST compliance controls (Public Preview)
Manages risk and demonstrates security and privacy compliance. Requires enabling in settings.
- Serverless outbound IPs available through public JSON endpoint (Public Preview)
Replaces existing stable IPs, requires Public Preview enrollment.
- Context based ingress control is now in Public Preview
Enables account admins to set allow and deny rules based on identity, request type, and network source.
- Automatic email notifications for expiring personal access tokens (Public Preview)
Sends emails 7 days before token expiration.
- TISAX compliance controls (Public Preview)
Enhances workspace compliance based on ISO/IEC 27001 and VDA ISA requirements.
- C5 and K-FSI compliance standards (Public Preview)
Adds German and Korean financial regulations compliance. Requires public preview setup.
- Configure Azure virtual network service policies for storage access (Public Preview)
Filters outbound traffic from classic compute to specific Azure Storage accounts. Requires Azure virtual network service endpoint policies.
- Updates for customer-managed VPC workspaces (Public Preview)
Adds Private Service Connect conversion and network config changes.
- Updating workspace virtual network configurations is now in Public Preview
Allows migration to custom VNet or changes to existing VNet injection setups.
Headlines, dates and product areas are Databricks' own, from the release notes published for each cloud, and every item links to the note it came from. The one-line summaries are ours. Not a Databricks product and not affiliated with Databricks, Inc.