Databricks releases, every cloud
| Release | Date | ||||
|---|---|---|---|---|---|
| Compliance security profile will enforce Azure Virtual Network encryption Coming soon Enforces Azure Virtual Network encryption on workspaces starting February 1, 2027. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Sep 3, 2026 |
| Lakebase now available in Azure Japan East region (japaneast) Available in japaneast region, requires Postgres database setup. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Sep 3, 2026 |
| Private network gateway is in Beta Connects serverless compute to VNet and on-premises systems through a managed gateway. Enabled from account console Previews page. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Sep 3, 2026 |
| HITRUST and IRAP compliance controls are now generally available Available through compliance security profile, required for HIPAA, HITRUST, and IRAP. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Sep 1, 2026 |
| Inbound Private Service Connect for performance-intensive services (Beta) Enables private connectivity to services like Zerobus Ingest and Lakebase Autoscaling on Google Cloud. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Aug 22, 2026 |
| Lakebase adds compliance security profile standards on Azure Supports ISMAP, IRAP, and UK Cyber Essentials Plus on Azure. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Aug 21, 2026 |
| Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs | |||||
| Lakebase available in four new Azure regions Added to North Central US, France Central, Germany West Central, and East Asia regions. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Aug 18, 2026 |
| Custom URL access to workspaces over inbound Private Link (Beta) Uses general_access private endpoint, serves workspaces and account-level resources across regions. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Aug 13, 2026 |
| Serverless outbound Private Service Connect to customer-managed resources (Public Preview) Keeps traffic off the public internet, adding network-layer defense against data exfiltration through customer-managed Google Cloud service attachment. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Aug 6, 2026 |
| Create a least-privilege Databricks workspace Grants Databricks a narrow set of custom IAM roles instead of broad permissions on Google Cloud. | Not on AWS | Not on Azure | On GCP, read it on their docs | Not on SAP | Jul 27, 2026 |
| Custom URLs for your Azure Databricks account (Public Preview) Replaces default Azure Databricks URL with a custom domain. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jul 15, 2026 |
| Configure serverless egress control in Azure China Available in China North 3 region, requires workspace in same region. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jul 7, 2026 |
| Classic workspace creation with a Azure Databricks-managed VNet will soon be deprecated Coming soon Replaced by serverless workspace or VNet injection. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 26, 2026 |
| Classic workspace creation with a Databricks-managed VPC will soon be deprecated Coming soon Replaced by customer-managed VPC for new workspaces. | Not on AWS | Not on Azure | On GCP, read it on their docs | Not on SAP | Jun 26, 2026 |
| Secure cluster connectivity will soon become mandatory for classic workspaces Coming soon Replaces enableNoPublicIp set to false, requires secure setup for all classic workspaces. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 26, 2026 |
| Arm-based instances are now supported with the compliance security profile Supports all compliance standards, previously unsupported. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 23, 2026 |
| Azure Databricks UI assets will be served from a new CDN domain Coming soon Replaces existing domain, requires firewall update to ui-assets.azuredatabricks.net. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 15, 2026 |
| Lakebase Postgres is now in Beta Available in us-east4, us-central1, and europe-west3 regions. | Not on AWS | Not on Azure | On GCP, read it on their docs | Not on SAP | Jun 15, 2026 |
| Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest | |||||
| Intra-VNet NSG rule hardening for Azure Databricks is now in Public Preview Restricts workspace traffic to host and worker subnet CIDRs. Applies to classic compute plane workspaces. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 1, 2026 |
| Compliance security profile required for HIPAA, HITRUST, and IRAP Coming soon Required starting September 1, 2026, for HIPAA, HITRUST, and IRAP data. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | May 30, 2026 |
| Azure Databricks Add-in for Excel support for all compliance security profile standards Supports all Azure Databricks compliance security profiles. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | May 19, 2026 |
| HIPAA support for the Azure Databricks Add-in for Excel Available for workspaces with HIPAA compliance across all supported regions. Requires a workspace with HIPAA compliance enabled. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | May 11, 2026 |
| Block identities from your Azure Databricks account with the account access denylist Prevents access when automatic identity management is enabled, blocking specific users, groups, or service principals. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | May 6, 2026 |
| Azure UK South now has a dedicated regional control plane New workspaces require firewall allowlist entries for SCC relay tunnel and other IPs. Existing workspaces use UK West control plane unless migrated. | Not on AWS | On Azure, read it on their docs | Not on GCP | On SAP, read it on their docs | May 1, 2026 |
| Configure private endpoints for serverless compute in Azure China Requires China North 3 region and network connectivity configuration. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Apr 29, 2026 |
| Connect Azure Databricks to on-premises resources using an SSH reverse tunnel Replaces inbound firewall access, works with classic and serverless compute. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Apr 28, 2026 |
| C5, TISAX, and K-FSI compliance controls are now generally available Available on Azure, providing enhancements for workspace compliance requirements. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Apr 10, 2026 |
| Lakebase updates: OAuth role management and budget policies and tags Creates OAuth roles via UI or REST API, and adds budget policies and custom tags to projects. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Mar 12, 2026 |
| Serverless compute now available for IRAP and Canada Protected B workloads on Azure Databricks Requires environment version 5 to be enabled. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Mar 6, 2026 |
| Customer-managed keys for Unity Catalog Uses own encryption keys for Unity Catalog data. Replaces automatic encryption. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Mar 2, 2026 |
| Customer-managed keys for Unity Catalog (Beta) Uses own encryption keys for Unity Catalog catalogs. Replaces automatic encryption. | Not on AWS | Not on Azure | On GCP, read it on their docs | Not on SAP | Mar 2, 2026 |
| Lakebase is now generally available on Azure Adds autoscaling compute and scale-to-zero to 11 new Azure regions. | Not on AWS | On Azure, read it on their docs | Not on GCP | On SAP, read it on their docs | Mar 2, 2026 |
| Update workspace network configuration to VNet injection is now GA Migrates from Databricks-managed VNet to customer-owned VNet. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Mar 2, 2026 |
| Azure virtual network service endpoint policies are now generally available Apply to classic compute for outbound storage access filtering. Requires configuration. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Feb 23, 2026 |
| Enhanced Security and Compliance add-on is now generally available includes compliance security profile and enhanced security monitoring. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Feb 19, 2026 |
| Inbound Private Link for performance-intensive services (Beta) Enables private connectivity to Zerobus Ingest and Lakebase Autoscaling. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Feb 18, 2026 |
| Automatic identity management deactivates deleted Entra ID users Replaces "Active: Removed From EntraID" status with Deactivated. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Feb 16, 2026 |
| Serverless compute now available for compliance standards Adds HITRUST, PCI-DSS, TISAX, and UK Cyber Essentials Plus support. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Feb 11, 2026 |
| Serverless egress control is now generally available Manages outbound connections with restricted access and FQDN filtering. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Feb 9, 2026 |
| Lakebase now available on Azure (Beta) Lakebase on Azure offers autoscaling compute and scale-to-zero. Supported regions include eastus2, westeurope, and westus. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Feb 4, 2026 |
- Compliance security profile will enforce Azure Virtual Network encryption Coming soon
Enforces Azure Virtual Network encryption on workspaces starting February 1, 2027.
- Lakebase now available in Azure Japan East region (japaneast)
Available in japaneast region, requires Postgres database setup.
- Private network gateway is in Beta
Connects serverless compute to VNet and on-premises systems through a managed gateway. Enabled from account console Previews page.
- HITRUST and IRAP compliance controls are now generally available
Available through compliance security profile, required for HIPAA, HITRUST, and IRAP.
- Inbound Private Service Connect for performance-intensive services (Beta)
Enables private connectivity to services like Zerobus Ingest and Lakebase Autoscaling on Google Cloud.
- Lakebase adds compliance security profile standards on Azure
Supports ISMAP, IRAP, and UK Cyber Essentials Plus on Azure.
- Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs
- Lakebase available in four new Azure regions
Added to North Central US, France Central, Germany West Central, and East Asia regions.
- Custom URL access to workspaces over inbound Private Link (Beta)
Uses general_access private endpoint, serves workspaces and account-level resources across regions.
- Serverless outbound Private Service Connect to customer-managed resources (Public Preview)
Keeps traffic off the public internet, adding network-layer defense against data exfiltration through customer-managed Google Cloud service attachment.
- Create a least-privilege Databricks workspace
Grants Databricks a narrow set of custom IAM roles instead of broad permissions on Google Cloud.
- Custom URLs for your Azure Databricks account (Public Preview)
Replaces default Azure Databricks URL with a custom domain.
- Configure serverless egress control in Azure China
Available in China North 3 region, requires workspace in same region.
- Classic workspace creation with a Azure Databricks-managed VNet will soon be deprecated Coming soon
Replaced by serverless workspace or VNet injection.
- Classic workspace creation with a Databricks-managed VPC will soon be deprecated Coming soon
Replaced by customer-managed VPC for new workspaces.
- Secure cluster connectivity will soon become mandatory for classic workspaces Coming soon
Replaces enableNoPublicIp set to false, requires secure setup for all classic workspaces.
- Arm-based instances are now supported with the compliance security profile
Supports all compliance standards, previously unsupported.
- Azure Databricks UI assets will be served from a new CDN domain Coming soon
Replaces existing domain, requires firewall update to ui-assets.azuredatabricks.net.
- Lakebase Postgres is now in Beta
Available in us-east4, us-central1, and europe-west3 regions.
- Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest
- Intra-VNet NSG rule hardening for Azure Databricks is now in Public Preview
Restricts workspace traffic to host and worker subnet CIDRs. Applies to classic compute plane workspaces.
- Compliance security profile required for HIPAA, HITRUST, and IRAP Coming soon
Required starting September 1, 2026, for HIPAA, HITRUST, and IRAP data.
- Azure Databricks Add-in for Excel support for all compliance security profile standards
Supports all Azure Databricks compliance security profiles.
- HIPAA support for the Azure Databricks Add-in for Excel
Available for workspaces with HIPAA compliance across all supported regions. Requires a workspace with HIPAA compliance enabled.
- Block identities from your Azure Databricks account with the account access denylist
Prevents access when automatic identity management is enabled, blocking specific users, groups, or service principals.
- Azure UK South now has a dedicated regional control plane
New workspaces require firewall allowlist entries for SCC relay tunnel and other IPs. Existing workspaces use UK West control plane unless migrated.
- Configure private endpoints for serverless compute in Azure China
Requires China North 3 region and network connectivity configuration.
- Connect Azure Databricks to on-premises resources using an SSH reverse tunnel
Replaces inbound firewall access, works with classic and serverless compute.
- C5, TISAX, and K-FSI compliance controls are now generally available
Available on Azure, providing enhancements for workspace compliance requirements.
- Lakebase updates: OAuth role management and budget policies and tags
Creates OAuth roles via UI or REST API, and adds budget policies and custom tags to projects.
- Serverless compute now available for IRAP and Canada Protected B workloads on Azure Databricks
Requires environment version 5 to be enabled.
- Customer-managed keys for Unity Catalog
Uses own encryption keys for Unity Catalog data. Replaces automatic encryption.
- Customer-managed keys for Unity Catalog (Beta)
Uses own encryption keys for Unity Catalog catalogs. Replaces automatic encryption.
- Lakebase is now generally available on Azure
Adds autoscaling compute and scale-to-zero to 11 new Azure regions.
- Update workspace network configuration to VNet injection is now GA
Migrates from Databricks-managed VNet to customer-owned VNet.
- Azure virtual network service endpoint policies are now generally available
Apply to classic compute for outbound storage access filtering. Requires configuration.
- Enhanced Security and Compliance add-on is now generally available
includes compliance security profile and enhanced security monitoring.
- Inbound Private Link for performance-intensive services (Beta)
Enables private connectivity to Zerobus Ingest and Lakebase Autoscaling.
- Automatic identity management deactivates deleted Entra ID users
Replaces "Active: Removed From EntraID" status with Deactivated.
- Serverless compute now available for compliance standards
Adds HITRUST, PCI-DSS, TISAX, and UK Cyber Essentials Plus support.
- Serverless egress control is now generally available
Manages outbound connections with restricted access and FQDN filtering.
- Lakebase now available on Azure (Beta)
Lakebase on Azure offers autoscaling compute and scale-to-zero. Supported regions include eastus2, westeurope, and westus.
Headlines, dates and product areas are Databricks' own, from the release notes published for each cloud, and every item links to the note it came from. The one-line summaries are ours. Not a Databricks product and not affiliated with Databricks, Inc.