Databricks releases, every cloud
- Metastore-level ABAC policies are in Beta
Applies across every catalog in the metastore. Replaces per-catalog policy setup.
- ABAC DENY policies are in Beta
Explicitly deny MANAGE ACCESS CONTROL privilege, taking precedence over grants.
- Private network gateway is in Beta
Connects serverless compute to VNet and on-premises systems through a managed gateway. Enabled from account console Previews page.
- Private network gateway is in Private Preview
Connects serverless compute to VPC and on-premises systems through a managed gateway, reusing existing network connectivity configuration.
- The INSERT, UPDATE, and DELETE privileges are in Beta
Require Databricks Runtime 18.1 or above, alternative to MODIFY privilege.
- Unity Catalog ABAC GRANT policies support more securable types in Beta
Now supports model services, model provider services, MCP services, and agent services, in addition to models.
- Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs
- Alert system tables are in Public Preview
Contains alerts and alert_evaluation_history tables for auditing and monitoring.
- Serverless outbound Private Service Connect to customer-managed resources (Public Preview)
Keeps traffic off the public internet, adding network-layer defense against data exfiltration through customer-managed Google Cloud service attachment.
- Governed tags system table is in Beta
Contains records for each governed tag key, including customer-created and system-generated tags.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Role-based access control (RBAC) is in Public Preview
Lets users assume a role with limited permissions. Requires account and workspace admin setup.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Custom URLs for your Azure Databricks account (Public Preview)
Replaces default Azure Databricks URL with a custom domain.
- Custom URLs for your Databricks account (Public Preview)
Replaces default URL, requires claim and enable process.
- Secrets in Unity Catalog (Public Preview)
Uses three-level namespace and Unity Catalog privileges for access control.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Restrict access to AI Functions with Unity Catalog permissions (Public Preview)
Requires account team enablement, restricts access to task-specific AI Functions.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - MATCH_RECOGNIZE is now in Beta
Requires enabling Match Recognize preview in workspace settings.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Metric view parameters are now in Public Preview
binds values at query time, replacing separate views per variant.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Block specific internet destinations in network policies (Public Preview)
Blocks destinations regardless of network access mode, enforced through REST API.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Enable access requests across your Unity Catalog metastore (Public Preview)
Enables requests at metastore level, inherited by all catalogs and schemas.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest
- The Discover page is now in Public Preview
Helps find Unity Catalog data assets without requiring catalog hierarchy knowledge. Organizes tables and dashboards by business area.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Configure the recovery period for dropped managed tables (Public Preview)
Sets recovery period to 0 hours or 7-30 days, requires Databricks Runtime 17.3.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Databricks-to-Databricks Delta Sharing across regulatory domains is now available (Public Preview)
Supports sharing with AWS GovCloud, AWS GovCloud DoD, and Azure China.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - UNIQUE constraint support is now in Public Preview
Enables join elimination and DISTINCT simplification on Photon-enabled compute. Applies to Unity Catalog Delta Lake tables.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Intra-VNet NSG rule hardening for Azure Databricks is now in Public Preview
Restricts workspace traffic to host and worker subnet CIDRs. Applies to classic compute plane workspaces.
- Configure Microsoft Entra ID SSO for Power BI (Public Preview)
Uses account-level federation policy, replacing manual config.
- MLflow trace storage in Unity Catalog is now in Public Preview
Stores OpenTelemetry traces, governed by Unity Catalog permissions, queryable from Databricks SQL or MLflow Python SDK.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - 5X-Large SQL warehouse size (Public Preview)
Provides 512 workers, available in all regions, controlled from Previews page.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Health indicators for tables in Catalog Explorer (Public Preview)
Shows freshness and completeness status based on anomaly detection.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Inbound Private Link for performance-intensive services (Public Preview)
Enables private connectivity for Zerobus Ingest and Lakebase Autoscaling.
- Customer-managed keys for Unity Catalog (Public Preview)
Protects data with user-owned encryption keys, replacing automatic encryption.
- HITRUST compliance controls (Public Preview)
Manages risk and demonstrates security and privacy compliance. Requires enabling in settings.
- Serverless outbound IPs available through public JSON endpoint (Public Preview)
Replaces existing stable IPs, requires Public Preview enrollment.
- Tag Databricks Apps (Public Preview)
Organize and categorize apps, but search is not supported.
- Context based ingress control is now in Public Preview
Enables account admins to set allow and deny rules based on identity, request type, and network source.
- Automatic email notifications for expiring personal access tokens (Public Preview)
Sends emails 7 days before token expiration.
- ABAC-secured assets shared using Delta Sharing is in Public Preview
Applies to tables and schemas, but not streaming tables or materialized views.
- Databricks SQL alerts are now in Public Preview
Offers a new editing experience, replacing the previous version.
- Convert foreign tables to Unity Catalog managed or external tables (Public Preview)
Requires Databricks Runtime 17.0 LTS or above. Uses ALTER TABLE SET MANAGED or SET EXTERNAL.
- JDBC Unity Catalog connection in Beta
Requires Databricks Runtime 17.3 or above. Available on standard, dedicated, or serverless compute.
- TISAX compliance controls (Public Preview)
Enhances workspace compliance based on ISO/IEC 27001 and VDA ISA requirements.
- C5 and K-FSI compliance standards (Public Preview)
Adds German and Korean financial regulations compliance. Requires public preview setup.
Headlines, dates and product areas are Databricks' own, from the release notes published for each cloud, and every item links to the note it came from. The one-line summaries are ours. Not a Databricks product and not affiliated with Databricks, Inc.