<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unauthorized network access to workspace in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169266#M5624</link>
    <description>&lt;DIV&gt;We're setting up a new workspace on AWS commercial cloud (customer-managed VPC, back-end PrivateLink) and are blocked from using Unity Catalog due to an account-level network policy restriction.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Issue:&lt;/DIV&gt;&lt;DIV&gt;Notebook calls to Unity Catalog fail with:&lt;/DIV&gt;&lt;DIV&gt;Error Code: UNEXPECTED_HTTP_ERROR&lt;/DIV&gt;&lt;DIV&gt;Message: HTTP request failed with status: HTTP/1.1 403 Forbidden, original HTTP response body: Unauthorized network access to workspace&lt;/DIV&gt;</description>
    <pubDate>Mon, 21 Sep 2026 05:18:45 GMT</pubDate>
    <dc:creator>nsingh_tl</dc:creator>
    <dc:date>2026-09-21T05:18:45Z</dc:date>
    <item>
      <title>Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169266#M5624</link>
      <description>&lt;DIV&gt;We're setting up a new workspace on AWS commercial cloud (customer-managed VPC, back-end PrivateLink) and are blocked from using Unity Catalog due to an account-level network policy restriction.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Issue:&lt;/DIV&gt;&lt;DIV&gt;Notebook calls to Unity Catalog fail with:&lt;/DIV&gt;&lt;DIV&gt;Error Code: UNEXPECTED_HTTP_ERROR&lt;/DIV&gt;&lt;DIV&gt;Message: HTTP request failed with status: HTTP/1.1 403 Forbidden, original HTTP response body: Unauthorized network access to workspace&lt;/DIV&gt;</description>
      <pubDate>Mon, 21 Sep 2026 05:18:45 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169266#M5624</guid>
      <dc:creator>nsingh_tl</dc:creator>
      <dc:date>2026-09-21T05:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169271#M5625</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/259239"&gt;@nsingh_tl&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;Unauthorized network access to workspace 403 error is generally a network layer block, not an IAM or permissions issue. When you are running a customer-managed VPC with back end PrivateLink, Unity Catalog needs to connect to the Databricks regional hostname rather than the specific workspace URL. The underlying issue here is likely that the VPC endpoint's Private DNS names option isn't enabled on the AWS side. When that is disabled, the regional hostname resolves to a public IP instead of routing through the private VPC endpoint. If the VPC is fully private and lacks a NAT gateway, that connection drops and throws 403 error. To isolate and fix this, you can check the AWS Console under VPC - Endpoints, open the Databricks workspace VPC endpoint, and verify that Private DNS names enabled is set to Yes. VPC must have both enableDnsSupport and enableDnsHostnames set to true.&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;If its already configured, confirm the account-level network policy in Databricks. If it is set to Restricted Access mode, it governs serverless compute egress and denies all outbound traffic by default except for Unity Catalog external locations and explicitly allow listed FQDNs or S3 buckets. Ask the account admin to check it in the Security - Networking - Context-based ingress &amp;amp; egress control. You can switch the policy to Full Access or manually add the required destinations in the allowed list.&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;Ensure that the Unity Catalog metastore is attached to this specific workspace (Account Console - Workspaces - check the Metastore). Ensure the workspace has the UC mapped and attached.&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;The pipelines rely on Unity Catalog for governance, and you won't be able to ingest your Oracle data or build out that silver layer until this is resolved. You can check the AWS-side &lt;STRONG&gt;VPC endpoint Private DNS&lt;/STRONG&gt;, followed by the Databricks-side &lt;STRONG&gt;network policy&lt;/STRONG&gt; and &lt;STRONG&gt;metastore attachment&lt;/STRONG&gt;. If the 403 persists after fixing all sides, you can check with databricks support.&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 21 Sep 2026 05:39:35 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169271#M5625</guid>
      <dc:creator>balajij8</dc:creator>
      <dc:date>2026-09-21T05:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169348#M5628</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/210897"&gt;@balajij8&lt;/a&gt;&amp;nbsp;for your input. The metastore is attached to the workspace, I am able to create schemas from the control plane ( workspace), but when I use notebook and compute to create a table or schema, I am getting "&lt;SPAN&gt;Unauthorized network access to workspace". This is a new account created using AWS Marketplace, I do not have support contract with Databricks and no available from them,&amp;nbsp;&amp;nbsp;&lt;BR /&gt;VPC endpoint have private DNS enable.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Relay is point to:&amp;nbsp;tunnel.privatelink.cloud.databricks.com (com.amazonaws.vpce.us-west-1.vpce-svc-04cb91f9372b792fe)&lt;BR /&gt;Dataplane is point to:&amp;nbsp;ncalifornia.privatelink.cloud.databricks.com (com.amazonaws.vpce.us-west-1.vpce-svc-09bb6ca26208063f2)&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2026 15:24:44 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169348#M5628</guid>
      <dc:creator>nsingh_tl</dc:creator>
      <dc:date>2026-09-21T15:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169350#M5629</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/259239"&gt;@nsingh_tl&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your back end PrivateLink only serves classic compute - clusters running inside your customer-managed VPC. Serverless compute generally runs in Databricks managed infrastructure outside VPC and reaches the workspace control plane API via public IP addresses, bypassing the Private Link. This is an ingress rejection (the workspace actively blocks the connection).&lt;/P&gt;&lt;P data-unlink="true"&gt;You can add the &lt;STRONG&gt;serverless&lt;/STRONG&gt; compute outbound IPs to the workspace's allowed list.&amp;nbsp;More details &lt;A href="https://www.databricks.com/networking/v1/ip-ranges.json" target="_self"&gt;here&lt;/A&gt;. &lt;STRONG&gt;Download&lt;/STRONG&gt; it and &lt;STRONG&gt;filter&lt;/STRONG&gt; for entries where service = "Databricks", type = "outbound", platform = "aws", and region = "us-west-1". &lt;STRONG&gt;Add&lt;/STRONG&gt; the resulting CIDR blocks to the workspace's &lt;STRONG&gt;IP access list&lt;/STRONG&gt; (Admin Settings - IP Access Lists) or to the context-based ingress rules in account-level network policy (Account Console - Security - Networking - Ingress tab). You can setup periodic refresh on the allowlist regularly.&lt;/P&gt;&lt;P&gt;You can alternatively use &lt;STRONG&gt;classic compute&lt;/STRONG&gt; - create a cluster that deploys into the customer-managed VPC subnets. Classic compute uses existing back end Private Link to reach the control plane privately and generally never hits the IP access list.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2026 15:52:11 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169350#M5629</guid>
      <dc:creator>balajij8</dc:creator>
      <dc:date>2026-09-21T15:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169358#M5630</link>
      <description>&lt;P&gt;Serverless compute is disabled on my account for some reason, and it won't let me turn it on.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My compute is getting provisioned in the same VPC, private subnet, and SG is also associated with VPC as well.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nsingh_tl_0-1790012455163.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/31360i8EB1EF176D7018DC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nsingh_tl_0-1790012455163.png" alt="nsingh_tl_0-1790012455163.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I am not able to this option to add IP CIDR, `&lt;STRONG&gt;Add&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;the resulting CIDR blocks to the workspace's&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;IP access list`,&amp;nbsp;&lt;/STRONG&gt;only IP access list is restrict the IP from workspace acces, currently that option is disabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2026 17:49:41 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169358#M5630</guid>
      <dc:creator>nsingh_tl</dc:creator>
      <dc:date>2026-09-21T17:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169372#M5631</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/259239"&gt;@nsingh_tl&lt;/a&gt;&amp;nbsp;given the latest useful details, I'd check the classic-compute PrivateLink path first.&lt;/P&gt;&lt;P&gt;From the affected cluster, run %sh nslookup &amp;lt;workspace-url&amp;gt; and confirm that the workspace hostname resolves to the private IP for the registered workspace REST API endpoint. Also check the workspace network configuration has both required VPC endpoints registered: the SCC relay and workspace REST API endpoints.&lt;/P&gt;&lt;P&gt;If DNS already resolves privately, check Private Access Settings next. With access level ENDPOINT, the relevant REST API VPC endpoint must be allowed.&lt;/P&gt;&lt;P&gt;If context-based ingress is also configured, it has to allow the same endpoint. system.access.inbound_network can help confirm an ingress-policy denial.&lt;/P&gt;&lt;P&gt;That should narrow this down before looking at UC permissions. Please, let us know the resukts.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2026 22:18:19 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169372#M5631</guid>
      <dc:creator>ivanvyd</dc:creator>
      <dc:date>2026-09-21T22:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169375#M5632</link>
      <description>&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Here is output:&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;%sh&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;SPAN&gt;nslookup dbc-xxxxxxxxx-xxxx.cloud.databricks.com&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Output:&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Server: 10.10.0.2&lt;BR /&gt;Address: 10.10.0.2#53&lt;BR /&gt;Non-authoritative answer:&lt;BR /&gt;dbc-xxxxxxxxx-xxxx.cloud.databricks.com canonical name = ncalifornia.privatelink.cloud.databricks.com.&lt;BR /&gt;Name: ncalifornia.privatelink.cloud.databricks.com&lt;BR /&gt;Address: 10.10.x.x&lt;BR /&gt;Name: ncalifornia.privatelink.cloud.databricks.com&lt;BR /&gt;Address: 10.10.x.y&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;SPAN&gt;%sql&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;`select&lt;/SPAN&gt; &lt;SPAN&gt;*&lt;/SPAN&gt; &lt;SPAN&gt;from&lt;/SPAN&gt; &lt;SPAN&gt;system&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;access&lt;/SPAN&gt;&lt;SPAN&gt;.inbound_network` give below error:&lt;BR /&gt;"[&lt;A class="" href="https://docs.databricks.com/error-messages/error-classes.html#uc_uncaught_client_exception" target="_blank" rel="noopener noreferrer"&gt;UC_UNCAUGHT_CLIENT_EXCEPTION&lt;/A&gt;] Encountered an unexpected HTTP error while communicating with the Databricks Unity Catalog backend. Error Code: UNEXPECTED_HTTP_ERROR. Message: HTTP request failed with status: HTTP/1.1 403 Forbidden, original HTTP response body: Unauthorized network access to workspace:"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;My settings:&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV class=""&gt;Private Access Level&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Specifies which VPC endpoints can connect to the attached workspace&lt;/SPAN&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Account -&lt;/SPAN&gt;&amp;nbsp;Limit connections to those VPC endpoints that are registered in your Databricks account.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 21 Sep 2026 23:53:31 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169375#M5632</guid>
      <dc:creator>nsingh_tl</dc:creator>
      <dc:date>2026-09-21T23:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169385#M5633</link>
      <description>&lt;P&gt;Additionally, I have used&amp;nbsp;&lt;A href="https://github.com/databricks/terraform-databricks-sra/tree/main/aws" target="_self"&gt;SRA&lt;/A&gt;&amp;nbsp;to deploy with custom networking option&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 03:48:30 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169385#M5633</guid>
      <dc:creator>nsingh_tl</dc:creator>
      <dc:date>2026-09-22T03:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169386#M5634</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/259239"&gt;@nsingh_tl&lt;/a&gt;&amp;nbsp;thanks, that confirms &lt;STRONG&gt;private DNS resolution for the workspace hostname&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;1) Could you compare both returned addresses with the network-interface IPs of your &lt;STRONG&gt;workspace REST API VPC endpoint&lt;/STRONG&gt;&amp;nbsp;in AWS? They should match. Private addresses alone do not confirm that the intended endpoint is being used.&lt;/P&gt;&lt;P&gt;With &lt;A href="https://docs.databricks.com/aws/en/security/network/classic/private-access-settings" target="_blank" rel="noopener"&gt;Private Access Level = Account&lt;/A&gt;, the endpoint must be &lt;STRONG&gt;registered in your Databricks account&lt;/STRONG&gt;, not just exist in your AWS account. You do not need an explicit ENDPOINT allowlist with that setting.&lt;/P&gt;&lt;P&gt;In the Databricks account console (like Account Console &amp;gt; Security &amp;gt; Networking &amp;gt; VPC endpoints) , check that the actual workspace and SCC endpoint IDs (vpce-...) are registered in us-west-1. The vpce-svc-... values you shared identify the services, not your individual endpoints. Also check that the workspace’s attached network configuration references those registrations in the correct workspace and SCC fields. The &lt;A href="https://docs.databricks.com/aws/en/security/network/classic/vpc-endpoints" target="_blank" rel="noopener"&gt;endpoint registration documentation&lt;/A&gt; covers this distinction.&lt;/P&gt;&lt;P&gt;2) Next, try &lt;STRONG&gt;a workspace REST API request from the affected cluster&lt;/STRONG&gt;. This uses the same API as &lt;A href="https://docs.databricks.com/aws/en/security/network/classic/privatelink#verify-classic-compute-plane-connectivity" target="_blank" rel="noopener"&gt;Databricks' documented connectivity test&lt;/A&gt;&amp;nbsp;. Run it in a Python cell, replacing the hostname and existing secret scope/key. Use a PAT already authorized to list tokens, rather than granting additional permissions just for this test.&lt;/P&gt;&lt;LI-CODE lang="python"&gt;import requests

token = dbutils.secrets.get(
scope="&amp;lt;secret-scope&amp;gt;",
key="&amp;lt;pat-key&amp;gt;",
)

response = requests.get(
"https://&amp;lt;workspace-hostname&amp;gt;/api/2.0/token/list",
headers={"Authorization": f"Bearer {token}"},
timeout=20,
)

print("HTTP", response.status_code)

if response.status_code &amp;gt;= 400:
print(response.text)&lt;/LI-CODE&gt;&lt;UL&gt;&lt;LI&gt;The same 403 "Unauthorized network access to workspace": the rejection also affects a non-UC workspace API. I'd continue checking endpoint registration and workspace network controls, including any attached context-based ingress policy.&lt;/LI&gt;&lt;LI&gt;HTTP 200: this particular request works. That narrows the investigation but does not prove that every UC request is permitted.&lt;/LI&gt;&lt;LI&gt;An authentication or scope error: resolve that before using this test to draw conclusions about the original network restriction.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The system.access.inbound_network query also depends on Unity Catalog, since &lt;A href="https://docs.databricks.com/aws/en/admin/system-tables" target="_blank" rel="noopener"&gt;system tables are UC-governed&lt;/A&gt;. My earlier suggestion therefore cannot provide the denial logs from this cluster while UC access is failing.&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Please share only the HTTP status and redacted error, not the token or successful token-list output.&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 03:52:59 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169386#M5634</guid>
      <dc:creator>ivanvyd</dc:creator>
      <dc:date>2026-09-22T03:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169393#M5635</link>
      <description>&lt;P&gt;Here is the output of the screenshot. The response is 200 for a non-UC call from compute. One more thing: this workspace and account are set up for a HIPAA-compliant workload.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nsingh_tl_0-1790053321792.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/31370iA7D29DDEF56BCB22/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nsingh_tl_0-1790053321792.png" alt="nsingh_tl_0-1790053321792.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 05:04:21 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169393#M5635</guid>
      <dc:creator>nsingh_tl</dc:creator>
      <dc:date>2026-09-22T05:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169398#M5636</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/259239"&gt;@nsingh_tl&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The HTTP 200 from the workspace REST API call confirms the basic Classic compute → workspace PrivateLink path is working.&lt;/P&gt;&lt;P&gt;One additional thing to check is the regional hostname used by UC, since UC can use that path directly rather than the workspace URL.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;%sh
nslookup ncalifornia.cloud.databricks.com&lt;/LI-CODE&gt;&lt;P&gt;Check if that also resolves to private IPs. Databricks &lt;A href="https://docs.databricks.com/aws/en/ingestion/lakeflow-connect/uc-initialization-troubleshoot#privatelink-or-customer-managed-vpc-dns-misconfiguration" target="_self"&gt;documents&lt;/A&gt; that if Private DNS is not enabled on the workspace VPC endpoint, the regional hostname can resolve publicly even though the workspace URL resolves correctly.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 07:07:11 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169398#M5636</guid>
      <dc:creator>data_pulse</dc:creator>
      <dc:date>2026-09-22T07:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169404#M5637</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/259239"&gt;@nsingh_tl&lt;/a&gt;&amp;nbsp;the 200 is for the token API. I'd compare &lt;STRONG&gt;a UC REST request with notebook SQL&lt;/STRONG&gt; before changing any network settings.&lt;/P&gt;&lt;P&gt;From the same cluster, run this read-only &lt;A href="https://docs.databricks.com/api/workspace/catalogs/list" target="_blank" rel="noopener"&gt;List catalogs request&lt;/A&gt;. Reuse your existing token variable, provided the token belongs to the user running the notebook. If the token is scoped, it must allow the &lt;STRONG&gt;unity-catalog&lt;/STRONG&gt; API scope.&lt;/P&gt;&lt;PRE&gt;import requests

response = requests.get(
    "https://&amp;lt;workspace-hostname&amp;gt;/api/2.1/unity-catalog/catalogs",
    headers={"Authorization": f"Bearer {token}"},
    params={"max_results": 1},
    timeout=20,
    allow_redirects=False,
)

print("HTTP", response.status_code)

if response.status_code &amp;gt;= 400:
    print(response.text[:1000])&lt;/PRE&gt;&lt;P&gt;Then run &lt;A href="https://docs.databricks.com/aws/en/sql/language-manual/sql-ref-syntax-aux-show-catalogs" target="_blank" rel="noopener"&gt;SHOW CATALOGS&lt;/A&gt; in a SQL cell attached to &lt;STRONG&gt;that same cluster&lt;/STRONG&gt;:&lt;/P&gt;&lt;PRE&gt;SHOW CATALOGS;&lt;/PRE&gt;&lt;P&gt;&lt;STRONG&gt;If REST returns 200 but SQL returns the original network-access 403&lt;/STRONG&gt;, check &lt;STRONG&gt;Compute &amp;gt; your cluster &amp;gt; Driver logs&lt;/STRONG&gt; around the SQL failure. Please include the &lt;STRONG&gt;runtime version, access mode and redacted exception&lt;/STRONG&gt;, with any destination hostname, port or request ID that appears. The &lt;A href="https://docs.databricks.com/aws/en/compute/clusters-manage#compute-driver-and-worker-logs" target="_blank" rel="noopener"&gt;driver-log documentation&lt;/A&gt; explains where to find those logs.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;If REST also fails&lt;/STRONG&gt;, please share its http status and redacted error. A token-scope or privilege error is different from the original "Unauthorized network access to workspace" response.&lt;/P&gt;&lt;P&gt;The results so far do not establish HIPAA settings, SRA or a blocked port as the cause.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 07:27:57 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169404#M5637</guid>
      <dc:creator>ivanvyd</dc:creator>
      <dc:date>2026-09-22T07:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169432#M5641</link>
      <description>&lt;P&gt;I am getting return code of 200 from api call&amp;nbsp; `show the catalog api`, but show catalogs failed again&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nsingh_tl_0-1790082202863.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/31383iA19CDEE329C61FEF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nsingh_tl_0-1790082202863.png" alt="nsingh_tl_0-1790082202863.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 13:06:07 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169432#M5641</guid>
      <dc:creator>nsingh_tl</dc:creator>
      <dc:date>2026-09-22T13:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169435#M5642</link>
      <description>&lt;P&gt;The nslookup resolves to a public IP. Is this an issue? it seems AWS did not create a private route for it.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;%sh
nslookup ncalifornia.cloud.databricks.com

Server:		10.10.0.2
Address:	10.10.0.2#53

Non-authoritative answer:
ncalifornia.cloud.databricks.com	canonical name = public-ingress-a84df8d06aede39e.elb.us-west-2.amazonaws.com.
Name:	public-ingress-a84df8d06aede39e.elb.us-west-2.amazonaws.com
Address: 44.234.192.46
Name:	public-ingress-a84df8d06aede39e.elb.us-west-2.amazonaws.com
Address: 44.234.192.47
Name:	public-ingress-a84df8d06aede39e.elb.us-west-2.amazonaws.com
Address: 44.234.192.45&lt;/LI-CODE&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 22 Sep 2026 13:14:13 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169435#M5642</guid>
      <dc:creator>nsingh_tl</dc:creator>
      <dc:date>2026-09-22T13:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169448#M5643</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/259239"&gt;@nsingh_tl&lt;/a&gt;&amp;nbsp;these results support the regional-DNS explanation&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/250262"&gt;@data_pulse&lt;/a&gt;&amp;nbsp;raised. Your logs&lt;STRONG&gt;&amp;nbsp;show public DNS resolution, not a missing route-table entry.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Databricks &lt;A href="https://docs.databricks.com/aws/en/ingestion/lakeflow-connect/uc-initialization-troubleshoot#privatelink-or-customer-managed-vpc-dns-misconfiguration" target="_blank" rel="noopener"&gt;documents UC initialization contacting a regional hostname directly&lt;/A&gt;, bypassing the workspace URL’s PrivateLink CNAME chain. If the failing UC request uses that hostname, this could explain the difference between your REST and SQL results.&lt;/P&gt;&lt;P&gt;Since you already reported private DNS enabled, I’d check the &lt;STRONG&gt;actual workspace REST API endpoint’s DNS configuration&lt;/STRONG&gt;, rather than repeat the workspace lookup. Run this read-only &lt;A href="https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpc-endpoints.html" target="_blank" rel="noopener"&gt;AWS CLI command&lt;/A&gt; from an authorized AWS terminal, replacing the endpoint ID:&lt;/P&gt;&lt;PRE&gt;aws ec2 describe-vpc-endpoints \
  --region us-west-1 \
  --vpc-endpoint-ids "&amp;lt;workspace-rest-vpce-id&amp;gt;" \
  --query 'VpcEndpoints[0].{PrivateDNS:PrivateDnsEnabled,DNSNames:DnsEntries[].DnsName}' \
  --output json&lt;/PRE&gt;&lt;P&gt;&lt;STRONG&gt;If PrivateDNS is false&lt;/STRONG&gt;, enable it on that workspace endpoint through &lt;STRONG&gt;VPC &amp;gt; Endpoints &amp;gt; Actions &amp;gt; Modify private DNS name&lt;/STRONG&gt;. Both VPC DNS resolution and DNS hostnames must be enabled. &lt;A href="https://docs.aws.amazon.com/vpc/latest/privatelink/interface-endpoints.html#modify-private-dns" target="_blank" rel="noopener"&gt;AWS documents these requirements here&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;If it is already true&lt;/STRONG&gt;, check whether the private DNS configuration covers the hostname UC actually uses, and inspect Route 53 Resolver rules associated with the VPC. A forwarding rule for the same domain can take precedence over a private hosted zone, so an enabled endpoint setting alone does not establish which DNS answer the cluster receives. &lt;A href="https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/hosted-zone-private-considerations.html#private-hosted-zones-resolver-rules" target="_blank" rel="noopener"&gt;AWS explains that precedence here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 14:05:25 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169448#M5643</guid>
      <dc:creator>ivanvyd</dc:creator>
      <dc:date>2026-09-22T14:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169449#M5644</link>
      <description>&lt;P&gt;Before creating a manual DNS override, confirm the destination hostname in the failing UC request. The &lt;A href="https://docs.databricks.com/aws/en/resources/ip-domain-region" target="_blank"&gt;current regional reference&lt;/A&gt; lists &lt;STRONG&gt;oregon.cloud.databricks.com for us-west-1&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;The correction to test is &lt;STRONG&gt;private resolution of that actual UC hostname to the intended workspace endpoint&lt;/STRONG&gt;, followed by another &lt;STRONG&gt;SHOW CATALOGS&lt;/STRONG&gt; attempt. I would leave the ingress restrictions unchanged while checking this.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 14:03:41 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169449#M5644</guid>
      <dc:creator>ivanvyd</dc:creator>
      <dc:date>2026-09-22T14:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169452#M5646</link>
      <description>&lt;P&gt;Here is output; private DNS is enabled.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;~ $ aws  ec2 describe-vpc-endpoints \
&amp;gt;   --region us-west-1 \
&amp;gt;   --vpc-endpoint-ids "vpce-005a4903xxxxxxx" \
&amp;gt;   --query 'VpcEndpoints[0].{PrivateDNS:PrivateDnsEnabled,DNSNames:DnsEntries[].DnsName}' \
~ $ aws  ec2 describe-vpc-endpoints \
&amp;gt;   --region us-west-1 \
&amp;gt;   --vpc-endpoint-ids "vpce-005a4903xxxxxxx" \
&amp;gt;   --query 'VpcEndpoints[0].{PrivateDNS:PrivateDnsEnabled,DNSNames:DnsEntries[].DnsName}' \
&amp;gt;   --output json
{
    "PrivateDNS": true,
    "DNSNames": [
        "vpce-005a4903xxxxxxx-k5bwn2b7.vpce-svc-09bb6ca26208063f2.us-west-1.vpce.amazonaws.com",
        "vpce-005a4903xxxxxxx-k5bwn2b7-us-west-1a.vpce-svc-09bb6ca26208063f2.us-west-1.vpce.amazonaws.com",
        "vpce-005a4903xxxxxxx-k5bwn2b7-us-west-1c.vpce-svc-09bb6ca26208063f2.us-west-1.vpce.amazonaws.com",
        "ncalifornia.privatelink.cloud.databricks.com"
    ]
}
~ $ &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 14:22:58 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169452#M5646</guid>
      <dc:creator>nsingh_tl</dc:creator>
      <dc:date>2026-09-22T14:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169460#M5648</link>
      <description>&lt;P class=""&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/259239"&gt;@nsingh_tl&lt;/a&gt;&amp;nbsp;good, I would leave that setting enabled.&lt;/P&gt;&lt;P&gt;&lt;A class="" href="https://docs.aws.amazon.com/vpc/latest/privatelink/manage-dns-names.html" target="_blank" rel="noopener"&gt;AWS private DNS&lt;/A&gt; maps the endpoint service’s configured DNS name. This output does not establish which destination the failing SQL request reaches, so it does not yet confirm or rule out the regional-DNS explanation.&lt;/P&gt;&lt;P&gt;Could you reproduce &lt;STRONG&gt;SHOW CATALOGS&lt;/STRONG&gt;, note the failure timestamp, and check &lt;STRONG&gt;Compute &amp;gt; your cluster &amp;gt; Driver logs&lt;/STRONG&gt;, particularly Log4j and stderr? &lt;A target="_blank" rel="noopener"&gt;Databricks documents those logs here&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Please share the &lt;STRONG&gt;Runtime version, access mode and a redacted exception excerpt&lt;/STRONG&gt;, including its nested causes. Include any hostname, port or request ID &lt;STRONG&gt;if present&lt;/STRONG&gt;; those details may not be logged.&lt;/P&gt;&lt;P&gt;I would hold off on manual DNS overrides or changes to ingress restrictions until we have evidence from the failing request. Please remove credentials and sensitive workload data from the excerpt.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 15:19:37 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169460#M5648</guid>
      <dc:creator>ivanvyd</dc:creator>
      <dc:date>2026-09-22T15:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169479#M5649</link>
      <description>&lt;P&gt;I couldn't appreciate it more, thank you for your help, below are additional information&lt;BR /&gt;&lt;BR /&gt;Runtime&lt;STRONG&gt; version: 18 LTS&lt;BR /&gt;Access mode: Standard&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[UC_UNCAUGHT_CLIENT_EXCEPTION] Encountered an unexpected HTTP error while communicating with the Databricks Unity Catalog backend. Error Code: UNEXPECTED_HTTP_ERROR. Message: HTTP request failed with status: HTTP/1.1 403 Forbidden, original HTTP response body: Unauthorized network access to workspace: 4444444444444 SQLSTATE: KCUC4
File &amp;lt;command-8700090828854269&amp;gt;, line 2
----&amp;gt; 2 spark.sql("show catalogs")
File /databricks/spark/python/pyspark/sql/connect/session.py:920, in SparkSession.sql(self, sqlQuery, args, **kwargs)
    917         _views.append(SubqueryAlias(df._plan, name))
    919 cmd = SQL(sqlQuery, _args, _named_args, _views)
--&amp;gt; 920 data, properties, ei = self.client.execute_command(cmd.command(self._client))
    921 if "sql_command_result" in properties:
    922     df = DataFrame(CachedRelation(properties["sql_command_result"]), self)
File /databricks/spark/python/pyspark/sql/connect/client/core.py:1618, in SparkConnectClient.execute_command(self, command, observations, extra_request_metadata)
   1616     req.user_context.user_id = self._user_id
   1617 self._set_command_in_plan(req.plan, command)
-&amp;gt; 1618 data, _, metrics, observed_metrics, properties = self._execute_and_fetch(
   1619     req, observations or {}, extra_request_metadata
   1620 )
   1621 # Create a query execution object.
   1622 ei = ExecutionInfo(metrics, observed_metrics)
File /databricks/spark/python/pyspark/sql/connect/client/core.py:2188, in SparkConnectClient._execute_and_fetch(self, req, observations, extra_request_metadata, self_destruct)
   2185 properties: Dict[str, Any] = {}
   2187 with Progress(handlers=self._progress_handlers, operation_id=req.operation_id) as progress:
-&amp;gt; 2188     for response in self._execute_and_fetch_as_iterator(
   2189         req, observations, extra_request_metadata or [], progress=progress
   2190     ):
   2191         if isinstance(response, StructType):
   2192             schema = response
File /databricks/spark/python/pyspark/sql/connect/client/core.py:2164, in SparkConnectClient._execute_and_fetch_as_iterator(self, req, observations, extra_request_metadata, progress)
   2162     raise kb
   2163 except Exception as error:
-&amp;gt; 2164     self._handle_error(error)
File /databricks/spark/python/pyspark/sql/connect/client/core.py:2537, in SparkConnectClient._handle_error(self, error)
   2535     self.thread_local.inside_error_handling = True
   2536     if isinstance(error, grpc.RpcError):
-&amp;gt; 2537         self._handle_rpc_error(error)
   2538     raise error
   2539 finally:
File /databricks/spark/python/pyspark/sql/connect/client/core.py:2615, in SparkConnectClient._handle_rpc_error(self, rpc_error)
   2611             logger.debug(f"Received ErrorInfo: {info}")
   2613             self._handle_rpc_error_with_error_info(info, status.message, status_code)  # EDGE
-&amp;gt; 2615             raise convert_exception(
   2616                 info,
   2617                 status.message,
   2618                 self._fetch_enriched_error(info),
   2619                 self._display_server_stack_trace(),
   2620                 status_code,
   2621             ) from None
   2623     raise SparkConnectGrpcException(
   2624         message=status.message,
   2625         sql_state=ErrorCode.CLIENT_UNEXPECTED_MISSING_SQL_STATE,  # EDGE
   2626         grpc_status_code=status_code,
   2627     ) from None
   2628 else:&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 17:00:30 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169479#M5649</guid>
      <dc:creator>nsingh_tl</dc:creator>
      <dc:date>2026-09-22T17:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized network access to workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169485#M5650</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/249473"&gt;@ivanvyd&lt;/a&gt;,&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/250262"&gt;@data_pulse&lt;/a&gt;&amp;nbsp;, and&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/210897"&gt;@balajij8&lt;/a&gt;. The issue was resolved after I added wild card private zone to Route 53,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 18:25:38 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/unauthorized-network-access-to-workspace/m-p/169485#M5650</guid>
      <dc:creator>nsingh_tl</dc:creator>
      <dc:date>2026-09-22T18:25:38Z</dc:date>
    </item>
  </channel>
</rss>

