Databricks releases, every cloud
| Release | Date | ||||
|---|---|---|---|---|---|
| Anthropic models will be removed from AWS GovCloud IL5 workspaces Coming soon Removal affects IL5 workspaces on AWS GovCloud. Endpoints must be migrated before September 19, 2026. | On AWS, read it on their docs | Not on Azure | Not on GCP | Unknown on SAP | Sep 16, 2026 |
| Inbound Private Service Connect for performance-intensive services (Beta) Enables private connectivity to services like Zerobus Ingest and Lakebase Autoscaling on Google Cloud. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Aug 22, 2026 |
| Serverless outbound Private Service Connect to customer-managed resources (Public Preview) Keeps traffic off the public internet, adding network-layer defense against data exfiltration through customer-managed Google Cloud service attachment. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Aug 6, 2026 |
| Create a least-privilege Databricks workspace Grants Databricks a narrow set of custom IAM roles instead of broad permissions on Google Cloud. | Not on AWS | Not on Azure | On GCP, read it on their docs | Not on SAP | Jul 27, 2026 |
| Custom URLs for your Databricks account (Public Preview) Replaces default URL, requires claim and enable process. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Not on SAP | Jul 15, 2026 |
| Classic workspace creation with a Databricks-managed VPC will soon be deprecated Coming soon Replaced by customer-managed VPC for new workspaces. | Not on AWS | Not on Azure | On GCP, read it on their docs | Not on SAP | Jun 26, 2026 |
| Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs | |||||
| Customer-managed VPC will soon be required for classic workspaces Coming soon New classic workspaces will require a customer-managed VPC, replacing Databricks-managed VPC. | On AWS, read it on their docs | Not on Azure | Not on GCP | Not on SAP | Jun 26, 2026 |
| Inbound Private Link for performance-intensive services is now generally available Supports Lakebase Autoscaling and Zerobus Ingest. | On AWS, read it on their docs | Not on Azure | Not on GCP | On SAP, read it on their docs | Jun 8, 2026 |
| AWS Graviton instances are now supported with the compliance security profile Supports all compliance standards in AWS commercial regions and GovCloud. | On AWS, read it on their docs | Not on Azure | Not on GCP | Not on SAP | Jun 5, 2026 |
| Automatic identity management with Microsoft Entra ID is now GA Replaces SCIM provisioning, syncs users and groups from Microsoft Entra ID. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | On SAP, read it on their docs | May 26, 2026 |
| Configure Microsoft Entra ID SSO for Power BI (Public Preview) Uses account-level federation policy, replacing manual config. | On AWS, read it on their docs | Not on Azure | Not on GCP | Not on SAP | May 20, 2026 |
| Databricks Add-in for Excel support for all compliance security profile standards Supports all Databricks compliance security profiles. Requires Public Preview. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Not on SAP | May 19, 2026 |
| HIPAA support for the Databricks Add-in for Excel Available for workspaces with HIPAA compliance across all supported regions. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Not on SAP | May 11, 2026 |
| Graviton instance types are available for the compliance security profile Graviton instances improve price-performance for many workloads on AWS Commercial workspaces with FedRAMP Moderate, IRAP, or CCCS Medium compliance standards. | On AWS, read it on their docs | Not on Azure | Not on GCP | Not on SAP | May 7, 2026 |
| Automatic identity management Syncs users and groups from identity providers like Microsoft Entra ID and Okta. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | On SAP, read it on their docs | May 5, 2026 |
| Connect Databricks to on-premises resources using an SSH reverse tunnel Uses proxy VMs in AWS, replacing inbound firewall access. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Not on SAP | Apr 28, 2026 |
| Customer-managed keys for Unity Catalog are generally available Encrypts data in Unity Catalog catalogs using cloud KMS keys. Requires default storage. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Not on SAP | Apr 1, 2026 |
| Databricks Documentation site table of contents tabs Replaces static sidebar with tabbed navigation, includes 6 context tabs. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Not on SAP | Mar 31, 2026 |
| Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest | |||||
| Customer-managed keys for Unity Catalog (Beta) Uses own encryption keys for Unity Catalog catalogs. Replaces automatic encryption. | Not on AWS | Not on Azure | On GCP, read it on their docs | Not on SAP | Mar 2, 2026 |
| Customer-managed keys for Unity Catalog (Public Preview) Protects data with user-owned encryption keys, replacing automatic encryption. | On AWS, read it on their docs | Not on Azure | Not on GCP | Not on SAP | Mar 2, 2026 |
| HITRUST compliance controls (Public Preview) Manages risk and demonstrates security and privacy compliance. Requires enabling in settings. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Feb 26, 2026 |
| Serverless outbound IPs available through public JSON endpoint (Public Preview) Replaces existing stable IPs, requires Public Preview enrollment. | On AWS, read it on their docs | Not on Azure | Not on GCP | Unknown on SAP | Feb 25, 2026 |
| Change to use_case field in VPC endpoint API responses Coming soon Changes from WORKSPACE_ACCESS to GENERAL_ACCESS, see API docs for details. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Feb 24, 2026 |
| Enhanced Security and Compliance add-on is now generally available includes compliance security profile and enhanced security monitoring. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Feb 19, 2026 |
| Serverless egress control is now generally available Manages outbound connections with restricted access and FQDN filtering. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Feb 9, 2026 |
| Automatically provision users (JIT) GA Creates accounts during SSO login if none exist. Requires single sign-on setup. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Feb 2, 2026 |
| Front-end PrivateLink for performance-intensive services (Beta) Supports private connectivity to Zerobus Ingest and Lakebase Autoscaling. | On AWS, read it on their docs | Not on Azure | Not on GCP | Unknown on SAP | Jan 22, 2026 |
| Expanded regional availability for C5 and TISAX compliance Now available in all regions and with serverless compute. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Dec 8, 2025 |
| List MCP servers in Databricks Marketplace (Public Preview) Lets users install MCP servers to connect AI agents to external data sources. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Nov 6, 2025 |
| GCP Private Service Connect generally available No account team request needed to enable. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Nov 3, 2025 |
| TISAX compliance controls Enhances workspace compliance based on ISO/IEC 27001 and VDA ISA. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Nov 3, 2025 |
- Anthropic models will be removed from AWS GovCloud IL5 workspaces Coming soon
Removal affects IL5 workspaces on AWS GovCloud. Endpoints must be migrated before September 19, 2026.
- Inbound Private Service Connect for performance-intensive services (Beta)
Enables private connectivity to services like Zerobus Ingest and Lakebase Autoscaling on Google Cloud.
- Serverless outbound Private Service Connect to customer-managed resources (Public Preview)
Keeps traffic off the public internet, adding network-layer defense against data exfiltration through customer-managed Google Cloud service attachment.
- Create a least-privilege Databricks workspace
Grants Databricks a narrow set of custom IAM roles instead of broad permissions on Google Cloud.
- Custom URLs for your Databricks account (Public Preview)
Replaces default URL, requires claim and enable process.
- Classic workspace creation with a Databricks-managed VPC will soon be deprecated Coming soon
Replaced by customer-managed VPC for new workspaces.
- Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs
- Customer-managed VPC will soon be required for classic workspaces Coming soon
New classic workspaces will require a customer-managed VPC, replacing Databricks-managed VPC.
- Inbound Private Link for performance-intensive services is now generally available
Supports Lakebase Autoscaling and Zerobus Ingest.
- AWS Graviton instances are now supported with the compliance security profile
Supports all compliance standards in AWS commercial regions and GovCloud.
- Automatic identity management with Microsoft Entra ID is now GA
Replaces SCIM provisioning, syncs users and groups from Microsoft Entra ID.
AWS, read it on their docsAzure(not on this cloud)GCP, read it on their docsSAP, read it on their docs - Configure Microsoft Entra ID SSO for Power BI (Public Preview)
Uses account-level federation policy, replacing manual config.
- Databricks Add-in for Excel support for all compliance security profile standards
Supports all Databricks compliance security profiles. Requires Public Preview.
- HIPAA support for the Databricks Add-in for Excel
Available for workspaces with HIPAA compliance across all supported regions.
- Graviton instance types are available for the compliance security profile
Graviton instances improve price-performance for many workloads on AWS Commercial workspaces with FedRAMP Moderate, IRAP, or CCCS Medium compliance standards.
- Automatic identity management
Syncs users and groups from identity providers like Microsoft Entra ID and Okta.
AWS, read it on their docsAzure(not on this cloud)GCP, read it on their docsSAP, read it on their docs - Connect Databricks to on-premises resources using an SSH reverse tunnel
Uses proxy VMs in AWS, replacing inbound firewall access.
- Customer-managed keys for Unity Catalog are generally available
Encrypts data in Unity Catalog catalogs using cloud KMS keys. Requires default storage.
- Databricks Documentation site table of contents tabs
Replaces static sidebar with tabbed navigation, includes 6 context tabs.
- Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest
- Customer-managed keys for Unity Catalog (Beta)
Uses own encryption keys for Unity Catalog catalogs. Replaces automatic encryption.
- Customer-managed keys for Unity Catalog (Public Preview)
Protects data with user-owned encryption keys, replacing automatic encryption.
- HITRUST compliance controls (Public Preview)
Manages risk and demonstrates security and privacy compliance. Requires enabling in settings.
- Serverless outbound IPs available through public JSON endpoint (Public Preview)
Replaces existing stable IPs, requires Public Preview enrollment.
- Change to use_case field in VPC endpoint API responses Coming soon
Changes from WORKSPACE_ACCESS to GENERAL_ACCESS, see API docs for details.
- Enhanced Security and Compliance add-on is now generally available
includes compliance security profile and enhanced security monitoring.
- Serverless egress control is now generally available
Manages outbound connections with restricted access and FQDN filtering.
- Automatically provision users (JIT) GA
Creates accounts during SSO login if none exist. Requires single sign-on setup.
- Front-end PrivateLink for performance-intensive services (Beta)
Supports private connectivity to Zerobus Ingest and Lakebase Autoscaling.
- Expanded regional availability for C5 and TISAX compliance
Now available in all regions and with serverless compute.
- List MCP servers in Databricks Marketplace (Public Preview)
Lets users install MCP servers to connect AI agents to external data sources.
- GCP Private Service Connect generally available
No account team request needed to enable.
- TISAX compliance controls
Enhances workspace compliance based on ISO/IEC 27001 and VDA ISA.
Headlines, dates and product areas are Databricks' own, and every item links to the note it came from. The one-line summaries are ours.