08-17-2026 07:16 AM
We are using Azure Databricks Serverless Compute to connect to Azure SQL Managed Instance (SQL MI) through Network Connectivity Configuration (NCC) with Private Endpoint Rules. Connectivity works successfully when using the primary SQL MI FQDN. However, connectivity fails when the SQL Managed Instance is configured behind a Failover Group and the connection is attempted using the Failover Group listener FQDN. As a result, Databricks Serverless Compute is currently unable to establish a connection to Azure SQL MI via the Failover Group FQDN, while direct connections to the primary SQL MI endpoint continue to work as expected.
08-17-2026 07:40 AM
Hi Lokesh,
Its likely tied to how Azure Databricks Network Connectivity Configurations handle DNS resolution and Private Endpoint routing relative to Azure SQL Managed Instance Failover Groups.
4 weeks ago
Hi @LokeshChikuru in your scenario, the private endpoint registered within the NCC is mapped to a single instance not the failover cluster, hence it fails. Currently Databricks serverless does not support DNS chasing or DNS redirects for resources accessed, this has been documented clearly under Microsoft own documentation here
It states that:
There is a potential workaround:
Databricks Serverless -> NCC Private Endpoint -> Private Link Service -> Internal Standard load balancer -> proxy VM/ VM scale set -> SQL MI failover-group cluster
Register a customer FQDN such as sqlmi-fg.contoso.com in the NCC and point it directly at the load-balancer/Private Link path. Do not use a CNAME chain to the SQL MI listener, and avoid private-use suffixes such as .internal, which the Databricks documentation excludes.
Test it and let me know.
4 weeks ago
Thanks for your response. I had a similar thought and noticed the same recommendation in a few other blogs as well. However, I recently came across the new Private Network Gateway feature for Azure Databricks, which leverages a delegated subnet and is currently in Private Preview.
Based on the documentation, it appears that this feature could potentially address DNS resolution challenges while also enabling access to specified endpoints outside of Azure. It may help resolve not only the current issue but some of the other networking constraints we have been encountering.
I am planning to test this feature in our non-production environment and evaluate whether it provides a viable solution before considering any further adoption.
3 weeks ago
Thank you for your message, Private Network Gateway (PNG) would assist you in creating a unified access to your cloud and on premise hosted resources without using various load balancers and proxy VM's. For the issue you are experiencing around Azure SQL MI, it is stated in our documentation that PNG will only connect to resources hosted in your virtual network, so it wont connect to cloud-hosted services such as ADLS and Azure SQL MI that uses service endpoints.
I would definitely encourage you to test PNG while its free in Private Preview.
Thanks
Sam