Databricks releases, every cloud
| Release | Date | ||||
|---|---|---|---|---|---|
| Configurable retention for system tables is in Beta Retention period can be set from 30 to 3650 days. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Sep 9, 2026 |
| Partner-powered AI features can no longer be disabled in the settings UI Settings API still allows enable or disable until November 1, 2026. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Sep 8, 2026 |
| The partner-powered AI features setting will be removed Coming soon Settings will remain as is, but changes will require contacting the account team after removal. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Sep 8, 2026 |
| Private network gateway is in Beta Connects serverless compute to VNet and on-premises systems through a managed gateway. Enabled from account console Previews page. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Sep 3, 2026 |
| Private network gateway is in Private Preview Connects serverless compute to VPC and on-premises systems through a managed gateway, reusing existing network connectivity configuration. | On AWS, read it on their docs | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Aug 24, 2026 |
| Inbound Private Service Connect for performance-intensive services (Beta) Enables private connectivity to services like Zerobus Ingest and Lakebase Autoscaling on Google Cloud. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Aug 22, 2026 |
| Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs | |||||
| Cross-workspace access for serverless (Beta) Controls serverless network traffic between workspaces with ingress and egress rules. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 13, 2026 |
| Custom URL access to workspaces over inbound Private Link (Beta) Uses general_access private endpoint, serves workspaces and account-level resources across regions. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Aug 13, 2026 |
| Tags page in Governance Hub (Beta) Provides a centralized view of tag usage, summarizes governed tags, and offers recommendations for invalid values. Requires account admins to enable from Previews page. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 13, 2026 |
| Alert system tables are in Public Preview Contains alerts and alert_evaluation_history tables for auditing and monitoring. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Unknown on SAP | Aug 10, 2026 |
| Serverless outbound Private Service Connect to customer-managed resources (Public Preview) Keeps traffic off the public internet, adding network-layer defense against data exfiltration through customer-managed Google Cloud service attachment. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Aug 6, 2026 |
| Email notifications for expiring service principal tokens are now generally available Sends emails to workspace admins 7 days before token expiration for used tokens with lifetime over 7 days. No configuration is required. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | On SAP, read it on their docs | Jul 22, 2026 |
| Governance Hub is in Beta Enables monitoring of data health and AI usage, requires account admin enablement from Previews page. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Jul 22, 2026 |
| Networking charges for performance-intensive products Charges apply to cross-region and public-internet egress for Lakebase, OpenSharing SecureConnect, Zerobus, and Files API. | Not on AWS | On Azure, read it on their docs | Not on GCP | On SAP, read it on their docs | Jul 22, 2026 |
| Context-based ingress control for workspaces public access is now generally available Uses allow and deny rules to control access based on identities, network sources, and request types. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | On SAP, read it on their docs | Jul 21, 2026 |
| Allowlist partner platform IPs in context-based ingress control (Beta) Supports Power BI, Tableau Cloud, and dbt platform, with automatic IP list updates. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Jul 14, 2026 |
| Serverless compute is now available in the Azure UK West region Supports notebooks, jobs, pipelines, and SQL warehouses, with private connectivity. | Not on AWS | On Azure, read it on their docs | Not on GCP | On SAP, read it on their docs | Jul 14, 2026 |
| Block specific internet destinations in network policies (Public Preview) Blocks destinations regardless of network access mode, enforced through REST API. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Jun 23, 2026 |
| Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest | |||||
| Legacy compute_preview system schema deprecated Replaced by system.compute schema. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | On SAP, read it on their docs | Jun 22, 2026 |
| Private Link for account-level resources (Beta) Connects account console through VPC interface endpoint instead of public internet. Requires configuration. | On AWS, read it on their docs | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 15, 2026 |
| Email notifications for expiring service principal tokens (Beta) Sends emails to workspace admins when tokens expire in 7 days, requiring no configuration. | On AWS, read it on their docs | On Azure, read it on their docs | On GCP, read it on their docs | Not on SAP | Jun 12, 2026 |
| Managed disaster recovery is now in Public Preview Replicates metadata, table data, and workspace assets to a secondary region. Requires account team enablement. | On AWS, read it on their docs | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 12, 2026 |
| Mission Critical add-on is now in Public Preview Unlocks managed disaster recovery and ESC for a single compute rate, enabled per workspace. | On AWS, read it on their docs | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 12, 2026 |
| Inbound Private Link for performance-intensive services is now generally available Supports Lakebase Autoscaling and Zerobus Ingest. | On AWS, read it on their docs | Not on Azure | Not on GCP | On SAP, read it on their docs | Jun 8, 2026 |
| Intra-VNet NSG rule hardening for Azure Databricks is now in Public Preview Restricts workspace traffic to host and worker subnet CIDRs. Applies to classic compute plane workspaces. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Jun 1, 2026 |
| Configure an additional recipient for workspace operational emails Receives operational updates like breaking changes and incident communications, use a distribution-list alias for multiple people. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | On SAP, read it on their docs | May 14, 2026 |
| Azure UK South now has a dedicated regional control plane New workspaces require firewall allowlist entries for SCC relay tunnel and other IPs. Existing workspaces use UK West control plane unless migrated. | Not on AWS | On Azure, read it on their docs | Not on GCP | On SAP, read it on their docs | May 1, 2026 |
| Connect Azure Databricks to on-premises resources using an SSH reverse tunnel Replaces inbound firewall access, works with classic and serverless compute. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Apr 28, 2026 |
| Connect Databricks to on-premises resources using an SSH reverse tunnel Uses proxy VMs in AWS, replacing inbound firewall access. | On AWS, read it on their docs | Not on Azure | On GCP, read it on their docs | Not on SAP | Apr 28, 2026 |
| Updated AWS tag character restrictions Tag keys and values now cannot contain spaces or /. Tag keys also cannot be just . , .. , or _index. | On AWS, read it on their docs | Not on Azure | Not on GCP | Not on SAP | Apr 15, 2026 |
| Inbound Private Link for performance-intensive services (Public Preview) Enables private connectivity for Zerobus Ingest and Lakebase Autoscaling. | On AWS, read it on their docs | On Azure, read it on their docs | Not on GCP | Not on SAP | Mar 9, 2026 |
| Update workspace network configuration to VNet injection is now GA Migrates from Databricks-managed VNet to customer-owned VNet. | Not on AWS | On Azure, read it on their docs | Not on GCP | Not on SAP | Mar 2, 2026 |
| Serverless outbound IPs available through public JSON endpoint (Public Preview) Replaces existing stable IPs, requires Public Preview enrollment. | On AWS, read it on their docs | Not on Azure | Not on GCP | Unknown on SAP | Feb 25, 2026 |
| Azure virtual network service endpoint policies are now generally available Apply to classic compute for outbound storage access filtering. Requires configuration. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Feb 23, 2026 |
| Inbound Private Link for performance-intensive services (Beta) Enables private connectivity to Zerobus Ingest and Lakebase Autoscaling. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Feb 18, 2026 |
| Serverless egress control is now generally available Manages outbound connections with restricted access and FQDN filtering. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Feb 9, 2026 |
| Front-end PrivateLink for performance-intensive services (Beta) Supports private connectivity to Zerobus Ingest and Lakebase Autoscaling. | On AWS, read it on their docs | Not on Azure | Not on GCP | Unknown on SAP | Jan 22, 2026 |
| GCP Private Service Connect generally available No account team request needed to enable. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Nov 3, 2025 |
| Configure Azure virtual network service policies for storage access (Public Preview) Filters outbound traffic from classic compute to specific Azure Storage accounts. Requires Azure virtual network service endpoint policies. | Not on AWS | On Azure, read it on their docs | Not on GCP | Unknown on SAP | Oct 1, 2025 |
| Updates for customer-managed VPC workspaces (Public Preview) Adds Private Service Connect conversion and network config changes. | Not on AWS | Not on Azure | On GCP, read it on their docs | Unknown on SAP | Aug 22, 2025 |
- Configurable retention for system tables is in Beta
Retention period can be set from 30 to 3650 days.
- Partner-powered AI features can no longer be disabled in the settings UI
Settings API still allows enable or disable until November 1, 2026.
- The partner-powered AI features setting will be removed Coming soon
Settings will remain as is, but changes will require contacting the account team after removal.
- Private network gateway is in Beta
Connects serverless compute to VNet and on-premises systems through a managed gateway. Enabled from account console Previews page.
- Private network gateway is in Private Preview
Connects serverless compute to VPC and on-premises systems through a managed gateway, reusing existing network connectivity configuration.
- Inbound Private Service Connect for performance-intensive services (Beta)
Enables private connectivity to services like Zerobus Ingest and Lakebase Autoscaling on Google Cloud.
- Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs
- Cross-workspace access for serverless (Beta)
Controls serverless network traffic between workspaces with ingress and egress rules.
- Custom URL access to workspaces over inbound Private Link (Beta)
Uses general_access private endpoint, serves workspaces and account-level resources across regions.
- Tags page in Governance Hub (Beta)
Provides a centralized view of tag usage, summarizes governed tags, and offers recommendations for invalid values. Requires account admins to enable from Previews page.
- Alert system tables are in Public Preview
Contains alerts and alert_evaluation_history tables for auditing and monitoring.
- Serverless outbound Private Service Connect to customer-managed resources (Public Preview)
Keeps traffic off the public internet, adding network-layer defense against data exfiltration through customer-managed Google Cloud service attachment.
- Email notifications for expiring service principal tokens are now generally available
Sends emails to workspace admins 7 days before token expiration for used tokens with lifetime over 7 days. No configuration is required.
- Governance Hub is in Beta
Enables monitoring of data health and AI usage, requires account admin enablement from Previews page.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Networking charges for performance-intensive products
Charges apply to cross-region and public-internet egress for Lakebase, OpenSharing SecureConnect, Zerobus, and Files API.
- Context-based ingress control for workspaces public access is now generally available
Uses allow and deny rules to control access based on identities, network sources, and request types.
- Allowlist partner platform IPs in context-based ingress control (Beta)
Supports Power BI, Tableau Cloud, and dbt platform, with automatic IP list updates.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Serverless compute is now available in the Azure UK West region
Supports notebooks, jobs, pipelines, and SQL warehouses, with private connectivity.
- Block specific internet destinations in network policies (Public Preview)
Blocks destinations regardless of network access mode, enforced through REST API.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest
- Legacy compute_preview system schema deprecated
Replaced by system.compute schema.
- Private Link for account-level resources (Beta)
Connects account console through VPC interface endpoint instead of public internet. Requires configuration.
- Email notifications for expiring service principal tokens (Beta)
Sends emails to workspace admins when tokens expire in 7 days, requiring no configuration.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Managed disaster recovery is now in Public Preview
Replicates metadata, table data, and workspace assets to a secondary region. Requires account team enablement.
- Mission Critical add-on is now in Public Preview
Unlocks managed disaster recovery and ESC for a single compute rate, enabled per workspace.
- Inbound Private Link for performance-intensive services is now generally available
Supports Lakebase Autoscaling and Zerobus Ingest.
- Intra-VNet NSG rule hardening for Azure Databricks is now in Public Preview
Restricts workspace traffic to host and worker subnet CIDRs. Applies to classic compute plane workspaces.
- Configure an additional recipient for workspace operational emails
Receives operational updates like breaking changes and incident communications, use a distribution-list alias for multiple people.
AWS, read it on their docsAzure(not on this cloud)GCP, read it on their docsSAP, read it on their docs - Azure UK South now has a dedicated regional control plane
New workspaces require firewall allowlist entries for SCC relay tunnel and other IPs. Existing workspaces use UK West control plane unless migrated.
- Connect Azure Databricks to on-premises resources using an SSH reverse tunnel
Replaces inbound firewall access, works with classic and serverless compute.
- Connect Databricks to on-premises resources using an SSH reverse tunnel
Uses proxy VMs in AWS, replacing inbound firewall access.
- Updated AWS tag character restrictions
Tag keys and values now cannot contain spaces or /. Tag keys also cannot be just . , .. , or _index.
- Inbound Private Link for performance-intensive services (Public Preview)
Enables private connectivity for Zerobus Ingest and Lakebase Autoscaling.
- Update workspace network configuration to VNet injection is now GA
Migrates from Databricks-managed VNet to customer-owned VNet.
- Serverless outbound IPs available through public JSON endpoint (Public Preview)
Replaces existing stable IPs, requires Public Preview enrollment.
- Azure virtual network service endpoint policies are now generally available
Apply to classic compute for outbound storage access filtering. Requires configuration.
- Inbound Private Link for performance-intensive services (Beta)
Enables private connectivity to Zerobus Ingest and Lakebase Autoscaling.
- Serverless egress control is now generally available
Manages outbound connections with restricted access and FQDN filtering.
- Front-end PrivateLink for performance-intensive services (Beta)
Supports private connectivity to Zerobus Ingest and Lakebase Autoscaling.
- GCP Private Service Connect generally available
No account team request needed to enable.
- Configure Azure virtual network service policies for storage access (Public Preview)
Filters outbound traffic from classic compute to specific Azure Storage accounts. Requires Azure virtual network service endpoint policies.
- Updates for customer-managed VPC workspaces (Public Preview)
Adds Private Service Connect conversion and network config changes.
Headlines, dates and product areas are Databricks' own, from the release notes published for each cloud, and every item links to the note it came from. The one-line summaries are ours. Not a Databricks product and not affiliated with Databricks, Inc.