<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Databricks Network Policies in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/databricks-network-policies/m-p/111913#M3091</link>
    <description>&lt;P&gt;I am not support, just a regular customer like you, but here is what I know:&lt;/P&gt;&lt;P&gt;1. Yes, serverless egress only applies to serverless.&amp;nbsp; There is another upcoming change you'll need to make for your classic compute, announced by Microsoft at&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/azure/virtual-network/ip-services/default-outbound-access" target="_blank"&gt;Default outbound access in Azure - Azure Virtual Network | Microsoft Learn&lt;/A&gt;&amp;nbsp;and mentioned by Databricks in&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/network/classic/secure-cluster-connectivity#egress-with-vnet-injection" target="_blank"&gt;Enable secure cluster connectivity - Azure Databricks | Microsoft Learn&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;2. Not sure.&amp;nbsp; If the storage accounts are in Unity Catalog they will be automatically allowed.&amp;nbsp; Likewise, if you're running classic compute this policy won't be applied.&amp;nbsp; How did you try to resolve the domain--just a ping, or call an API?&lt;/P&gt;</description>
    <pubDate>Thu, 06 Mar 2025 13:56:39 GMT</pubDate>
    <dc:creator>Rjdudley</dc:creator>
    <dc:date>2025-03-06T13:56:39Z</dc:date>
    <item>
      <title>Databricks Network Policies</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-network-policies/m-p/111384#M3063</link>
      <description>&lt;P&gt;Hi Databricks community. I have 2 questions that I'd appreciate if you can shed some lights on:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Is the new Network Policies in Databricks account, only applicable to serverless compute or are these workspace-wide policies which apply to all other compute types? The databricks documentation&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-gb/azure/databricks/security/network/serverless-network-security/manage-network-policies" target="_blank"&gt;Managing network policies for serverless egress control&lt;/A&gt;&amp;nbsp;talks about the serverless egress control but it's not clear if this applies to other computes or not. Also nothing in the network policy menu hints at this being a feature for serverless compute.&lt;/LI&gt;&lt;LI&gt;Also I have created a new policy and assigned a workspace to this policy. As you can see no domains is allowed and the policy is being enforced to the workspaces (I've redacted them). But I can still run any query from these workspaces to storage accounts. Also I can resolve any domain from notebooks. What am I misconfiguring here?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mohsendbx_0-1740670036975.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/15152i4C2470D1188255B5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mohsendbx_0-1740670036975.png" alt="mohsendbx_0-1740670036975.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 15:27:32 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-network-policies/m-p/111384#M3063</guid>
      <dc:creator>mohsen-dbx</dc:creator>
      <dc:date>2025-02-27T15:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks Network Policies</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-network-policies/m-p/111636#M3079</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/84948"&gt;@support&lt;/a&gt;&amp;nbsp;can you share your thoughts on the above please as no one else have responded.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 21:41:22 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-network-policies/m-p/111636#M3079</guid>
      <dc:creator>mohsen-dbx</dc:creator>
      <dc:date>2025-03-03T21:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks Network Policies</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-network-policies/m-p/111913#M3091</link>
      <description>&lt;P&gt;I am not support, just a regular customer like you, but here is what I know:&lt;/P&gt;&lt;P&gt;1. Yes, serverless egress only applies to serverless.&amp;nbsp; There is another upcoming change you'll need to make for your classic compute, announced by Microsoft at&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/azure/virtual-network/ip-services/default-outbound-access" target="_blank"&gt;Default outbound access in Azure - Azure Virtual Network | Microsoft Learn&lt;/A&gt;&amp;nbsp;and mentioned by Databricks in&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/network/classic/secure-cluster-connectivity#egress-with-vnet-injection" target="_blank"&gt;Enable secure cluster connectivity - Azure Databricks | Microsoft Learn&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;2. Not sure.&amp;nbsp; If the storage accounts are in Unity Catalog they will be automatically allowed.&amp;nbsp; Likewise, if you're running classic compute this policy won't be applied.&amp;nbsp; How did you try to resolve the domain--just a ping, or call an API?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 13:56:39 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-network-policies/m-p/111913#M3091</guid>
      <dc:creator>Rjdudley</dc:creator>
      <dc:date>2025-03-06T13:56:39Z</dc:date>
    </item>
  </channel>
</rss>

