Databricks releases, every cloud
| Release | Date | ||||
|---|---|---|---|---|---|
| Compliance security profile will enforce Azure Virtual Network encryption Coming soon Enforces Azure Virtual Network encryption on workspaces starting February 1, 2027. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Sep 3, 2026 |
| Inbound Private Service Connect for performance-intensive services (Beta) Enables private connectivity to services like Zerobus Ingest and Lakebase Autoscaling on Google Cloud. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Aug 22, 2026 |
| Custom URL access to workspaces over inbound Private Link (Beta) Uses general_access private endpoint, serves workspaces and account-level resources across regions. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Aug 13, 2026 |
| Create a least-privilege Databricks workspace Grants Databricks a narrow set of custom IAM roles instead of broad permissions on Google Cloud. | Not on AWS | Not on Azure | On GCP, read it on their docs | Not on SAP | Jul 27, 2026 |
| Configure serverless egress control in Azure China Available in China North 3 region, requires workspace in same region. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jul 7, 2026 |
| Secure cluster connectivity will soon become mandatory for classic workspaces Coming soon Replaces enableNoPublicIp set to false, requires secure setup for all classic workspaces. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 26, 2026 |
| Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs | |||||
| Arm-based instances are now supported with the compliance security profile Supports all compliance standards, previously unsupported. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 23, 2026 |
| Azure Databricks UI assets will be served from a new CDN domain Coming soon Replaces existing domain, requires firewall update to ui-assets.azuredatabricks.net. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 15, 2026 |
| Compliance security profile required for HIPAA, HITRUST, and IRAP Coming soon Required starting September 1, 2026, for HIPAA, HITRUST, and IRAP data. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | May 30, 2026 |
| Azure Databricks Add-in for Excel support for all compliance security profile standards Supports all Azure Databricks compliance security profiles. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | May 19, 2026 |
| HIPAA support for the Azure Databricks Add-in for Excel Available for workspaces with HIPAA compliance across all supported regions. Requires a workspace with HIPAA compliance enabled. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | May 11, 2026 |
| Block identities from your Azure Databricks account with the account access denylist Prevents access when automatic identity management is enabled, blocking specific users, groups, or service principals. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | May 6, 2026 |
| Azure UK South now has a dedicated regional control plane New workspaces require firewall allowlist entries for SCC relay tunnel and other IPs. Existing workspaces use UK West control plane unless migrated. | Not on AWS | On Azure, read it on their docs | Not on GCP | On SAP, read it on their docs | May 1, 2026 |
| Configure private endpoints for serverless compute in Azure China Requires China North 3 region and network connectivity configuration. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Apr 29, 2026 |
| Connect Azure Databricks to on-premises resources using an SSH reverse tunnel Replaces inbound firewall access, works with classic and serverless compute. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Apr 28, 2026 |
| Serverless compute now available for IRAP and Canada Protected B workloads on Azure Databricks Requires environment version 5 to be enabled. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Mar 6, 2026 |
| Customer-managed keys for Unity Catalog Uses own encryption keys for Unity Catalog data. Replaces automatic encryption. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Mar 2, 2026 |
| Customer-managed keys for Unity Catalog (Beta) Uses own encryption keys for Unity Catalog catalogs. Replaces automatic encryption. | Not on AWS | Not on Azure | On GCP, read it on their docs | Not on SAP | Mar 2, 2026 |
| Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest | |||||
| Inbound Private Link for performance-intensive services (Beta) Enables private connectivity to Zerobus Ingest and Lakebase Autoscaling. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Feb 18, 2026 |
| Automatic identity management deactivates deleted Entra ID users Replaces "Active: Removed From EntraID" status with Deactivated. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Feb 16, 2026 |
| Automatically provision users (JIT) GA Creates accounts during SSO login if none exist. Requires single sign-on setup. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Feb 2, 2026 |
| Improved group sharing for automatic identity management Shares account-level assets with Microsoft Entra ID groups. Requires automatic identity management. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Jan 24, 2026 |
| Simplified serverless network security with Azure Network Security Perimeter Uses AzureDatabricksServerless service tag, replacing subnet-based rules. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Jan 7, 2026 |
- Compliance security profile will enforce Azure Virtual Network encryption Coming soon
Enforces Azure Virtual Network encryption on workspaces starting February 1, 2027.
- Inbound Private Service Connect for performance-intensive services (Beta)
Enables private connectivity to services like Zerobus Ingest and Lakebase Autoscaling on Google Cloud.
- Custom URL access to workspaces over inbound Private Link (Beta)
Uses general_access private endpoint, serves workspaces and account-level resources across regions.
- Create a least-privilege Databricks workspace
Grants Databricks a narrow set of custom IAM roles instead of broad permissions on Google Cloud.
- Configure serverless egress control in Azure China
Available in China North 3 region, requires workspace in same region.
- Secure cluster connectivity will soon become mandatory for classic workspaces Coming soon
Replaces enableNoPublicIp set to false, requires secure setup for all classic workspaces.
- Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs
- Arm-based instances are now supported with the compliance security profile
Supports all compliance standards, previously unsupported.
- Azure Databricks UI assets will be served from a new CDN domain Coming soon
Replaces existing domain, requires firewall update to ui-assets.azuredatabricks.net.
- Compliance security profile required for HIPAA, HITRUST, and IRAP Coming soon
Required starting September 1, 2026, for HIPAA, HITRUST, and IRAP data.
- Azure Databricks Add-in for Excel support for all compliance security profile standards
Supports all Azure Databricks compliance security profiles.
- HIPAA support for the Azure Databricks Add-in for Excel
Available for workspaces with HIPAA compliance across all supported regions. Requires a workspace with HIPAA compliance enabled.
- Block identities from your Azure Databricks account with the account access denylist
Prevents access when automatic identity management is enabled, blocking specific users, groups, or service principals.
- Azure UK South now has a dedicated regional control plane
New workspaces require firewall allowlist entries for SCC relay tunnel and other IPs. Existing workspaces use UK West control plane unless migrated.
- Configure private endpoints for serverless compute in Azure China
Requires China North 3 region and network connectivity configuration.
- Connect Azure Databricks to on-premises resources using an SSH reverse tunnel
Replaces inbound firewall access, works with classic and serverless compute.
- Serverless compute now available for IRAP and Canada Protected B workloads on Azure Databricks
Requires environment version 5 to be enabled.
- Customer-managed keys for Unity Catalog
Uses own encryption keys for Unity Catalog data. Replaces automatic encryption.
- Customer-managed keys for Unity Catalog (Beta)
Uses own encryption keys for Unity Catalog catalogs. Replaces automatic encryption.
- Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest
- Inbound Private Link for performance-intensive services (Beta)
Enables private connectivity to Zerobus Ingest and Lakebase Autoscaling.
- Automatic identity management deactivates deleted Entra ID users
Replaces "Active: Removed From EntraID" status with Deactivated.
- Automatically provision users (JIT) GA
Creates accounts during SSO login if none exist. Requires single sign-on setup.
- Improved group sharing for automatic identity management
Shares account-level assets with Microsoft Entra ID groups. Requires automatic identity management.
- Simplified serverless network security with Azure Network Security Perimeter
Uses AzureDatabricksServerless service tag, replacing subnet-based rules.
Headlines, dates and product areas are Databricks' own, and every item links to the note it came from. The one-line summaries are ours.