Comment
Databricks Employee
Databricks Employee

@Said good question - you should allow-list the public IPs associated with the outbound traffic from the Databricks compute plane. Depending on the specific proxy/firewall appliance and configuration, some will obfuscate the source IPs, while others can preserve them. If traffic egressing from your Azure firewall uses the public IP of the firewall, I would make sure to allowlist that IP in the workspace IP ACL.