Databricks releases, every cloud
| Release | Date | ||||
|---|---|---|---|---|---|
| Unused OAuth client secrets are automatically deleted after 90 days Deletes unused secrets after 90 days, create new if still needed. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Sep 16, 2026 |
| Data Classification now scans Unity Catalog views (Beta) Scans Unity Catalog views in addition to tables, using the same detection engine, and is currently in Beta. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Sep 15, 2026 |
| External secrets in Unity Catalog (Beta) Connects Unity Catalog schema to AWS Secrets Manager, appearing as read-only objects. | On AWS, read it on their docs | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Sep 9, 2026 |
| Compliance security profile will enforce Azure Virtual Network encryption Coming soon Enforces Azure Virtual Network encryption on workspaces starting February 1, 2027. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Sep 3, 2026 |
| Restrict service principal OAuth secrets to specific API scopes Restricts OAuth secrets to specific API scopes like sql or jobs, limiting leaked secret impact. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 29, 2026 |
| Unity Catalog Skills (Beta) Publishes and governs agent skills, controlling access with Unity Catalog permissions. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 28, 2026 |
| Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs | |||||
| Inbound Private Service Connect for performance-intensive services (Beta) Enables private connectivity to services like Zerobus Ingest and Lakebase Autoscaling on Google Cloud. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Aug 22, 2026 |
| Context attributes in ABAC column mask and row filter policies (Beta) Targets request context, such as OAuth client ID and on-behalf-of status, in Unity Catalog policies. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 21, 2026 |
| Identity attributes in ABAC column mask policies (Beta) Targets users by attributes like department or country, using has_identity_attribute_value and has_identity_attribute_tag_match functions. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 17, 2026 |
| Block or redact sensitive data in requests and responses Detects SSNs, credit cards, and phone numbers using regex and checksums. Requires Enhanced Unity Gateway preview. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 13, 2026 |
| Cross-workspace access for serverless (Beta) Controls serverless network traffic between workspaces with ingress and egress rules. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 13, 2026 |
| Custom URL access to workspaces over inbound Private Link (Beta) Uses general_access private endpoint, serves workspaces and account-level resources across regions. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Aug 13, 2026 |
| Tags page in Governance Hub (Beta) Provides a centralized view of tag usage, summarizes governed tags, and offers recommendations for invalid values. Requires account admins to enable from Previews page. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 13, 2026 |
| Define business concepts with Pages (Beta) Gives business terms a single governed definition, part of Unity Catalog semantics. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 12, 2026 |
| ABAC GRANT policies now cover Unity Gateway resource types (Beta) Supports model services, model provider services, MCP services, and agent services, allowing tag-based access. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 11, 2026 |
| READ METADATA privilege is GA Provides read-only visibility into security-sensitive metadata, including privilege grants and ABAC policies. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 10, 2026 |
| Tag automations (Beta) Assigns or removes governed tags on Unity Catalog tables or volumes based on defined conditions. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 7, 2026 |
| Genie One is now available in Google Sheets Queries governed data in natural language, importing results as native rows and columns. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 5, 2026 |
| Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest | |||||
| Genie One is now available in Microsoft Excel Queries governed data in natural language, importing results as native rows and columns. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 5, 2026 |
| Refresh materialized views and streaming tables without exempting the pipeline owner from ABAC policies Pipeline owners are now subject to ABAC policies when refreshing views and tables. Policies are evaluated using the pipeline owner's identity. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 3, 2026 |
| Secrets in Unity Catalog is GA Stores secrets as securable objects with Unity Catalog privileges. Uses catalog.schema.secret namespace. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 3, 2026 |
| Upcoming general availability of Unity Gateway Coming soon Extends Unity Catalog governance to runtime interactions, controls AI service usage, and monitors traffic. Available by default for workspaces with compliance security profile in mid-September. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Jul 29, 2026 |
| Create a least-privilege Databricks workspace Grants Databricks a narrow set of custom IAM roles instead of broad permissions on Google Cloud. | Not on AWS | Not on Azure | On GCP, read it on their docs | Not on SAP | Jul 27, 2026 |
| Automated setup for S3 external locations Uses AWS IAM temporary delegation to configure external locations and provision required resources. | On AWS, read it on their docs | Not on Azure | Not on GCP | On SAP, read it on their docs | Jul 22, 2026 |
| Databricks-hosted sample datasets available in the samples catalog Available in Unity Catalog-enabled workspaces through OpenSharing as samples.databricks.datasets. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Jul 22, 2026 |
| Allowlist partner platform IPs in context-based ingress control (Beta) Supports Power BI, Tableau Cloud, and dbt platform, with automatic IP list updates. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Jul 14, 2026 |
| Change to default pipeline editor for workspaces with the compliance security profile enabled Coming soon Replaces legacy editor, removing it in August. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Jul 9, 2026 |
| Configure serverless egress control in Azure China Available in China North 3 region, requires workspace in same region. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jul 7, 2026 |
| Govern LLMs in Unity Catalog with model services (Beta) Represents a governed LLM endpoint, sharable across workspaces via Unity Catalog privileges. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Jun 29, 2026 |
| Customer-managed VPC will soon be required for classic workspaces Coming soon New classic workspaces will require a customer-managed VPC, replacing Databricks-managed VPC. | On AWS, read it on their docs | Not on Azure | Not on GCP | Not on SAP | Jun 26, 2026 |
| Secure cluster connectivity will soon become mandatory for classic workspaces Coming soon Replaces enableNoPublicIp set to false, requires secure setup for all classic workspaces. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 26, 2026 |
| Arm-based instances are now supported with the compliance security profile Supports all compliance standards, previously unsupported. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 23, 2026 |
| Comments on foreign tables (Beta) Syncs table and column comments from external data sources to Unity Catalog foreign tables. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Jun 17, 2026 |
| Azure Databricks UI assets will be served from a new CDN domain Coming soon Replaces existing domain, requires firewall update to ui-assets.azuredatabricks.net. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 15, 2026 |
| Private Link for account-level resources (Beta) Connects account console through VPC interface endpoint instead of public internet. Requires configuration. | On AWS, read it on their docs | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 15, 2026 |
| Email notifications for expiring service principal tokens (Beta) Sends emails to workspace admins when tokens expire in 7 days, requiring no configuration. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Jun 12, 2026 |
| ABAC GRANT policies for models (Beta) Grants EXECUTE privilege on models based on governed tags, supporting MLflow and foundation models. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Jun 11, 2026 |
| AWS Graviton instances are now supported with the compliance security profile Supports all compliance standards in AWS commercial regions and GovCloud. | On AWS, read it on their docs | Not on Azure | Not on GCP | Not on SAP | Jun 5, 2026 |
| Write data from Microsoft Excel back to Azure Databricks Writes to Unity Catalog tables, overwriting existing ones if needed. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 4, 2026 |
| Write data from Microsoft Excel back to Databricks Writes to Unity Catalog tables, overwriting existing ones if needed. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Not on SAP | Jun 4, 2026 |
- Unused OAuth client secrets are automatically deleted after 90 days
Deletes unused secrets after 90 days, create new if still needed.
- Data Classification now scans Unity Catalog views (Beta)
Scans Unity Catalog views in addition to tables, using the same detection engine, and is currently in Beta.
- External secrets in Unity Catalog (Beta)
Connects Unity Catalog schema to AWS Secrets Manager, appearing as read-only objects.
- Compliance security profile will enforce Azure Virtual Network encryption Coming soon
Enforces Azure Virtual Network encryption on workspaces starting February 1, 2027.
- Restrict service principal OAuth secrets to specific API scopes
Restricts OAuth secrets to specific API scopes like sql or jobs, limiting leaked secret impact.
- Unity Catalog Skills (Beta)
Publishes and governs agent skills, controlling access with Unity Catalog permissions.
- Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs
- Inbound Private Service Connect for performance-intensive services (Beta)
Enables private connectivity to services like Zerobus Ingest and Lakebase Autoscaling on Google Cloud.
- Context attributes in ABAC column mask and row filter policies (Beta)
Targets request context, such as OAuth client ID and on-behalf-of status, in Unity Catalog policies.
- Identity attributes in ABAC column mask policies (Beta)
Targets users by attributes like department or country, using has_identity_attribute_value and has_identity_attribute_tag_match functions.
- Block or redact sensitive data in requests and responses
Detects SSNs, credit cards, and phone numbers using regex and checksums. Requires Enhanced Unity Gateway preview.
- Cross-workspace access for serverless (Beta)
Controls serverless network traffic between workspaces with ingress and egress rules.
- Custom URL access to workspaces over inbound Private Link (Beta)
Uses general_access private endpoint, serves workspaces and account-level resources across regions.
- Tags page in Governance Hub (Beta)
Provides a centralized view of tag usage, summarizes governed tags, and offers recommendations for invalid values. Requires account admins to enable from Previews page.
- Define business concepts with Pages (Beta)
Gives business terms a single governed definition, part of Unity Catalog semantics.
- ABAC GRANT policies now cover Unity Gateway resource types (Beta)
Supports model services, model provider services, MCP services, and agent services, allowing tag-based access.
- READ METADATA privilege is GA
Provides read-only visibility into security-sensitive metadata, including privilege grants and ABAC policies.
- Tag automations (Beta)
Assigns or removes governed tags on Unity Catalog tables or volumes based on defined conditions.
- Genie One is now available in Google Sheets
Queries governed data in natural language, importing results as native rows and columns.
- Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest
- Genie One is now available in Microsoft Excel
Queries governed data in natural language, importing results as native rows and columns.
- Refresh materialized views and streaming tables without exempting the pipeline owner from ABAC policies
Pipeline owners are now subject to ABAC policies when refreshing views and tables. Policies are evaluated using the pipeline owner's identity.
- Secrets in Unity Catalog is GA
Stores secrets as securable objects with Unity Catalog privileges. Uses catalog.schema.secret namespace.
- Upcoming general availability of Unity Gateway Coming soon
Extends Unity Catalog governance to runtime interactions, controls AI service usage, and monitors traffic. Available by default for workspaces with compliance security profile in mid-September.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Create a least-privilege Databricks workspace
Grants Databricks a narrow set of custom IAM roles instead of broad permissions on Google Cloud.
- Automated setup for S3 external locations
Uses AWS IAM temporary delegation to configure external locations and provision required resources.
- Databricks-hosted sample datasets available in the samples catalog
Available in Unity Catalog-enabled workspaces through OpenSharing as samples.databricks.datasets.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Allowlist partner platform IPs in context-based ingress control (Beta)
Supports Power BI, Tableau Cloud, and dbt platform, with automatic IP list updates.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Change to default pipeline editor for workspaces with the compliance security profile enabled Coming soon
Replaces legacy editor, removing it in August.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Configure serverless egress control in Azure China
Available in China North 3 region, requires workspace in same region.
- Govern LLMs in Unity Catalog with model services (Beta)
Represents a governed LLM endpoint, sharable across workspaces via Unity Catalog privileges.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Customer-managed VPC will soon be required for classic workspaces Coming soon
New classic workspaces will require a customer-managed VPC, replacing Databricks-managed VPC.
- Secure cluster connectivity will soon become mandatory for classic workspaces Coming soon
Replaces enableNoPublicIp set to false, requires secure setup for all classic workspaces.
- Arm-based instances are now supported with the compliance security profile
Supports all compliance standards, previously unsupported.
- Comments on foreign tables (Beta)
Syncs table and column comments from external data sources to Unity Catalog foreign tables.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Azure Databricks UI assets will be served from a new CDN domain Coming soon
Replaces existing domain, requires firewall update to ui-assets.azuredatabricks.net.
- Private Link for account-level resources (Beta)
Connects account console through VPC interface endpoint instead of public internet. Requires configuration.
- Email notifications for expiring service principal tokens (Beta)
Sends emails to workspace admins when tokens expire in 7 days, requiring no configuration.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - ABAC GRANT policies for models (Beta)
Grants EXECUTE privilege on models based on governed tags, supporting MLflow and foundation models.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - AWS Graviton instances are now supported with the compliance security profile
Supports all compliance standards in AWS commercial regions and GovCloud.
- Write data from Microsoft Excel back to Azure Databricks
Writes to Unity Catalog tables, overwriting existing ones if needed.
- Write data from Microsoft Excel back to Databricks
Writes to Unity Catalog tables, overwriting existing ones if needed.
Headlines, dates and product areas are Databricks' own, from the release notes published for each cloud, and every item links to the note it came from. The one-line summaries are ours. Not a Databricks product and not affiliated with Databricks, Inc.