<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article [Action required] [Azure] update outbound connectivity for classic workspaces in Product Platform Updates</title>
    <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/ba-p/70060</link>
    <description>&lt;P&gt;&lt;STRONG&gt;IMPORTANT NOTE: We have indefinitely delayed the automatic enforcement described below for workspaces that had enabled workspace IP access lists prior to July 29, 2024. We still recommend manually enforcing IP access lists on compute plane requests in these workspaces by taking the steps outlined below.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note: New IP access controls enabled on workspaces after July 29, 2024 are still enforced on data plane traffic, per the original communication below.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN&gt;---------------------------------&lt;/SPAN&gt;&lt;/H2&gt;
&lt;H2&gt;&lt;SPAN&gt;Communication&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;To improve security for Azure Databricks customers, we’ll begin applying workspace IP access controls to compute plane traffic. This change will impact workspaces that use both &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/network/classic/secure-cluster-connectivity" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;secure cluster connectivity&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; (no public IP) and &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/network/front-end/ip-access-list" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;workspace IP access lists&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;. We’ll begin enforcing this change for all new workspaces starting July 29 2024 and all existing workspaces starting August 26 2024.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Required action&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To ensure there’s no disruption to connectivity to the Azure Databricks control plane, you’ll need to take one of the following actions:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Add your compute plane IP addresses to the workspace IP access list.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Configure &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/databricks/security/network/classic/private-link" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;back-end private link&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; for all workspaces.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;If you are not the admin responsible for network connectivity to Azure Databricks, please forward this email to that person.&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note that while this change only impacts secure cluster connectivity workspaces that use workspace IP access lists, Microsoft has announced that &lt;/SPAN&gt;&lt;A href="https://azure.microsoft.com/en-us/updates/default-outbound-access-for-vms-in-azure-will-be-retired-transition-to-a-new-method-of-internet-access/" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;default outbound access for VMs in Azure will be retired&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; on 30 September 2025. Therefore, we recommend proactively taking action.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Help and support&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you have questions, get answers from community experts in &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/answers/tags/172/azure-databricks" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;. If you have a support plan and you need technical help, open the &lt;/SPAN&gt;&lt;A href="https://portal.azure.com/%22%20/l%20%22blade/Microsoft_Azure_Support/HelpAndSupportBlade/overview" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Azure portal&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; and select the question mark icon at the top of the page.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN&gt;Step-by-Step Instructions&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Option 1) Add your compute plane IP addresses to the workspace IP access list&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note: If your compute plane traffic egresses through a firewall/proxy appliance, ensure that the IPs of the appliance are added to the workspace IP ACL policy. If it does not, read on for Azure NAT gateway deployment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Note 2: Azure charges for Azure NAT Gateway. See pricing details &lt;A style="font-family: inherit; background-color: #ffffff;" href="https://azure.microsoft.com/en-us/pricing/details/azure-nat-gateway/" target="_blank" rel="noopener"&gt;here.&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Deploy one or more &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/nat-gateway/nat-overview" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Azure NAT Gateways&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;, if one doesn’t exist already&lt;/SPAN&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="4"&gt;&lt;SPAN&gt;How to check if Azure NAT Gateway already exists via Azure Portal&lt;/SPAN&gt;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="5"&gt;&lt;SPAN&gt;Login to portal.azure.com&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="5"&gt;&lt;SPAN&gt;Select the subscription that your workspace and resource group reside in&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="5"&gt;&lt;SPAN&gt;Navigate to your Azure Databricks workspace&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="5"&gt;&lt;SPAN&gt;Select the Resource Group that your workspace is in&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="5"&gt;&lt;SPAN&gt;Check if there is a resource in your resource group of type “NAT Gateway” - if not, you do not have a NAT gateway&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI&gt;&lt;SPAN&gt;How to check if Azure NAT Gateway already exists via &lt;/SPAN&gt;&lt;SPAN&gt;via CLI (cloud shell)&lt;/SPAN&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="4"&gt;&amp;nbsp;&lt;SPAN&gt;Query the public subnet for an existing NAT Gateway&lt;/SPAN&gt;&lt;LI-CODE lang="markup"&gt;az network vnet subnet show 
--resource-group &amp;lt;resource group&amp;gt; 
--vnet &amp;lt;vnet name&amp;gt; 
--name &amp;lt;public subnet name&amp;gt; 
--query "natGateway.id"&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="4"&gt;&lt;SPAN&gt;Take the NAT gateway name from resource id from the previous step example and retrieve the public IP of the NAT gateway&lt;/SPAN&gt;&lt;LI-CODE lang="markup"&gt;(/subscriptions/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx/resourceGroups/brn/providers/Microsoft.Network/natGateways/[NAT_gateway_name])

az network nat gateway show --resource-group &amp;lt;resource group&amp;gt; --name &amp;lt;nat-gateway name&amp;gt; --query publicIpAddresses[0].id
&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="4"&gt;&lt;SPAN&gt;Take the public IP from the above command example and confirm the public IP address is static&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="4"&gt;&lt;LI-CODE lang="markup"&gt;(/subscriptions/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx/resourceGroups/brn/providers/Microsoft.Network/publicIPAddresses/[NAT_gateway_name])) 

az network public-ip show 
--resource-group &amp;lt;resource group&amp;gt; 
--name &amp;lt;public-ip name&amp;gt; 
--query "{fqdn: dnsSettings.fqdn, address: ipAddress, type: publicIPAllocationMethod}"

Example : az network public-ip show --resource-group brn --name [NAT_gateway_name]) --query "{fqdn: dnsSettings.fqdn, address: ipAddress, type: publicIPAllocationMethod}"
{
  "address": "[IP_address]",
  "fqdn": null,
  "type": "[e.g., Static]"
}
&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;How to create a NAT gateway&lt;/SPAN&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;Follow the steps outlined here to create a NAT gateway via UI or programatically: &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/nat-gateway/manage-nat-gateway?tabs=manage-nat-portal" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Manage a NAT gateway - Azure&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;How to retrieve IPs for NAT gateway&lt;/SPAN&gt;
&lt;OL&gt;
&lt;LI&gt;Via Azure Portal
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="5"&gt;&lt;SPAN&gt;Login to portal.azure.com&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="5"&gt;&lt;SPAN&gt;Select the subscription that your workspace and resource group reside in&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="5"&gt;&lt;SPAN&gt;Navigate to your Azure Databricks workspace&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="5"&gt;&lt;SPAN&gt;Select the Resource Group that your workspace is in&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="5"&gt;&lt;SPAN&gt;Select the NAT gateway resource&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="5"&gt;&lt;SPAN&gt;Navigate to “outbound IP”&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="5"&gt;&lt;SPAN&gt;Copy the IP address&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="5"&gt;&lt;SPAN&gt;If there are multiple NAT gateways deployed (e.g., for multiple zones), collect all IP addresses for the NAT gateway&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="5"&gt;&lt;SPAN&gt;via CLI (cloud shell)&lt;/SPAN&gt;&lt;LI-CODE lang="markup"&gt;az network public-ip show 
--resource-group &amp;lt;resource group&amp;gt; 
--name &amp;lt;public-ip name&amp;gt; 
--query "{fqdn: dnsSettings.fqdn, address: ipAddress, type: publicIPAllocationMethod}"
&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="5"&gt;&amp;nbsp;&lt;SPAN&gt;Add the Azure NAT Gateway IP addresses to the workspace IP access list&lt;/SPAN&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="4"&gt;&lt;SPAN&gt;Follow the steps outlined here to add the IP addresses for the NAT gateways collected above to your workspace IP ACL policy: &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/network/front-end/ip-access-list-workspace" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://learn.microsoft.com/en-us/azure/databricks/security/network/front-end/ip-access-list-workspace&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;Test that your deployment was successful&lt;/SPAN&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="4"&gt;&lt;SPAN&gt;Log in to your workspace&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="4"&gt;&lt;SPAN&gt;Navigate to "Preview" &amp;gt; "View All"&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="4"&gt;&lt;SPAN&gt;Find "Enforce IP access list on Compute Plane Requests". On toggle on, IP ACL will be enforced on your NAT IP&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="4"&gt;&lt;SPAN&gt;Wait for up to 10 minutes for the config to be applied to the workspace.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="4"&gt;&lt;SPAN&gt;Create and run a python notebook with a new cluster of any type except serverless.&lt;/SPAN&gt;&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;Cell #1&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="lia-code-sample  language-markup"&gt;&lt;CODE&gt;%pip install databricks-sdk --upgrade
dbutils.library.restartPython()
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;Cell #2&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="lia-code-sample  language-markup"&gt;&lt;CODE&gt;from databricks.sdk import WorkspaceClient

w = WorkspaceClient()
w.clusters.list()
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;SPAN&gt;If the code sample works, then your IP access list is set up correctly.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="4"&gt;&lt;SPAN&gt;In case of failures, toggle off "Enforce IP access list on Compute Plane Requests". Wait for up to 10 minutes for the config to be applied to the workspace.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;
&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;Optional - Use &lt;/SPAN&gt;&lt;A style="background-color: #ffffff;" href="https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoints-overview" target="_blank" rel="noopener"&gt;Azure virtual network service endpoints&lt;/A&gt;&lt;SPAN&gt; to access storage. To avoid using NAT for outbound connectivity for accessing storage, you can optionally deploy Azure virtual network service endpoints.&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;
&lt;P&gt;&lt;SPAN&gt;In the Azure portal, go to the Databricks workspace object, click on “see more” and take note of the public subnet name.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;
&lt;P&gt;&lt;SPAN&gt;Click on the Virtual network. open the public (host) subnet for you workspace and find the config entry “service endpoints”&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;
&lt;P&gt;&lt;SPAN&gt;In the services drop down choose between “Micrososft.Storage” (for in region service endpoint networking) or “Microsoft.Storage.Global” (for cross region service endpoint networking)&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;Adding service endpoint networking for Databricks public subnet. Note: this approach has the following important limitations:&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Enabling service endpoints will change the route for all storage accounts accessed from that subnet, except routes using private endpoints. This means any routes configured to egress through, for example, a customer firewall, will be bypassed&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Each storage account must explicitly allow access from that public subnet.&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Option 2)&amp;nbsp;Configure back-end private link for all workspaces, if not already done&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Follow the steps outlined here to configure back-end private link for each workspace: &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/network/classic/private-link" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Enable Azure Private Link back-end and front-end connections - Azure Databricks | Microsoft Learn&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;Note: Azure charges for Azure Private Link. See details &lt;/SPAN&gt;&lt;A href="https://azure.microsoft.com/en-us/pricing/details/private-link/" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Oct 2024 16:38:20 GMT</pubDate>
    <dc:creator>AlexEsibov</dc:creator>
    <dc:date>2024-10-16T16:38:20Z</dc:date>
    <item>
      <title>[Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/ba-p/70060</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The following blog post details action required for workspaces that use both secure cluster connectivity and workspace IP access lists.&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;The communication will also be sent out by email to users who Azure Databricks determines might be affected.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 16:38:20 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/ba-p/70060</guid>
      <dc:creator>AlexEsibov</dc:creator>
      <dc:date>2024-10-16T16:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/71420#M21</link>
      <description>&lt;P&gt;Hi, is there a place in the databricks logs where I can see if this switch is enabled (other then in de ui)&amp;gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;Enforce IP ACL on Dataplane Requests ? and second databricks uses NAT or private link connection ?&amp;nbsp;&amp;nbsp;thx in adv, Oscar&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 08:23:17 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/71420#M21</guid>
      <dc:creator>OvZ</dc:creator>
      <dc:date>2024-06-03T08:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/71584#M22</link>
      <description>&lt;P&gt;I have a doubt on this. If i routed databricks traffic through Azure firewall, whether i need to whitelist the Firewall public IP or is there anything else i have to consider.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 11:12:24 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/71584#M22</guid>
      <dc:creator>Said</dc:creator>
      <dc:date>2024-06-04T11:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/71634#M23</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/106160"&gt;@Said&lt;/a&gt;&amp;nbsp;good question - you should allow-list the public IPs associated with the outbound traffic from the Databricks compute plane. Depending on the specific proxy/firewall appliance and configuration, some will obfuscate the source IPs, while others can preserve them. If traffic egressing from your Azure firewall uses the public IP of the firewall, I would make sure to allowlist that IP in the workspace IP ACL.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 15:51:37 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/71634#M23</guid>
      <dc:creator>AlexEsibov</dc:creator>
      <dc:date>2024-06-04T15:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/71962#M24</link>
      <description>&lt;P&gt;Hi, say for example, we have two types of databricks workspace being used. The configurations are&lt;/P&gt;&lt;P&gt;1. &lt;STRONG&gt;Premium&lt;/STRONG&gt; tier, with&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; - IP access list &lt;STRONG&gt;enabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; - Public Network access &lt;STRONG&gt;enabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; - Required NSG Rules: &lt;STRONG&gt;All Rules&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; - Private endpoint: &lt;STRONG&gt;ui_api&lt;/STRONG&gt; service &lt;STRONG&gt;only&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2. &lt;STRONG&gt;Standard&lt;/STRONG&gt; tier, with&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; - IP access list &lt;STRONG&gt;disabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; - Public Network access &lt;STRONG&gt;enabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; - Required NSG Rules: &lt;STRONG&gt;All Rules&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With these two configurations, do we still need to do anything to ensure the these two workspaces are still working as expected?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 00:37:53 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/71962#M24</guid>
      <dc:creator>chang_vnext</dc:creator>
      <dc:date>2024-06-07T00:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/72820#M26</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/106451"&gt;@chang_vnext&lt;/a&gt;&amp;nbsp;Hi, only the (1) bucket will potentially be affected. Please check the "enableNoPublicIp" parameter of your Azure Databricks workspace. If for your premium tier workspace (1) you have&amp;nbsp;enableNoPublicIp = true, then this workspace is affected and please add the public IP of your NAT gateway to your workspace IP access list, then turn on "Enforce IP access list on Compute Plane Requests" to secure your workspace.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2024 15:53:51 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/72820#M26</guid>
      <dc:creator>yankaiZhang-db</dc:creator>
      <dc:date>2024-06-12T15:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/74909#M29</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/49493"&gt;@OvZ&lt;/a&gt;&amp;nbsp;sorry I missed your questions:&lt;/P&gt;
&lt;P&gt;1) To check if the switch is enabled, you could check logs but using a service 'workspace', action of 'setSetting' and tags.settingTypeName of 'enforce_ip_acl_on_dp'.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Your classic compute resources can connect to the Azure Databricks Control Plane over NAT or Private Link - it depends on your deployment.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 22:12:11 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/74909#M29</guid>
      <dc:creator>AlexEsibov</dc:creator>
      <dc:date>2024-06-18T22:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/75990#M31</link>
      <description>&lt;P&gt;Is there any way to check what IP is used from the compute plane to control plane, for example, logs?&lt;/P&gt;&lt;P&gt;In my case, the traffic going out from the compute plane SNet is not going through NAT gateway or firewall. I believe that some sort of Azure public IP will be used. I would like to confirm what are the exact IP(s) that I need to whitelist.&lt;/P&gt;&lt;P&gt;The workspace is with SCC and IP whitelist on and without backend private endpoint.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 02:47:14 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/75990#M31</guid>
      <dc:creator>elvisleung</dc:creator>
      <dc:date>2024-06-28T02:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/76617#M32</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I understand that the change will primarily affect workspaces utilizing both secure cluster connectivity (no public IP) and workspace IP access lists.&lt;/SPAN&gt;&lt;SPAN&gt; In my Azure Databricks workspace,&lt;/SPAN&gt;&lt;SPAN&gt; I'm currently only using secure cluster connectivity,&lt;/SPAN&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;STRONG&gt;I do not have workspace IP access lists configured&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My question is:&lt;/STRONG&gt; &lt;STRONG&gt;Will this upcoming change regarding workspace IP access controls impact my environment in any way?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2024 12:34:57 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/76617#M32</guid>
      <dc:creator>Said</dc:creator>
      <dc:date>2024-07-03T12:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/76819#M33</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/106160"&gt;@Said&lt;/a&gt;&amp;nbsp;this change will not impact you. You must meet both conditions as you pointed out.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 18:54:14 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/76819#M33</guid>
      <dc:creator>AlexEsibov</dc:creator>
      <dc:date>2024-07-04T18:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/76820#M34</link>
      <description>&lt;P&gt;There is a simple way to check your outbound IP from the Databricks compute plane - its a great way to validate a NAT gateway or FW NAT IP .. also can tell you the default SNAT ip if you are NPIP and going direct to the internet.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In a notebook cell run :&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;%sh
curl ipinfo.io | grep ip&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 20:25:40 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/76820#M34</guid>
      <dc:creator>rugger-bricks</dc:creator>
      <dc:date>2024-07-04T20:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/76823#M35</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/109853"&gt;@elvisleung&lt;/a&gt;&amp;nbsp;please see the response above from&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/34414"&gt;@rugger-bricks&lt;/a&gt;&amp;nbsp;and let us know if it resolves your question&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 21:39:10 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/76823#M35</guid>
      <dc:creator>AlexEsibov</dc:creator>
      <dc:date>2024-07-04T21:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/77265#M36</link>
      <description>&lt;P&gt;Hi, we are affected by this change. We are using classic compute with vnet injection. But we does not have a NAT as explained above nor the backend private link.&lt;/P&gt;&lt;P&gt;If I will go for option 1 by adding the compute plane IP to the IP access list, what IP-address should I add? Is it the addresses of my VNET that I have injected?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 08:42:56 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/77265#M36</guid>
      <dc:creator>MarkusL</dc:creator>
      <dc:date>2024-07-09T08:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/77542#M37</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/111049"&gt;@MarkusL&lt;/a&gt;&amp;nbsp;please deploy a NAT gateway, or configure backend private link. If you go with the former, the instructions above include a step for "&lt;SPAN&gt;Deploy one or more&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/nat-gateway/nat-overview" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;SPAN&gt;Azure NAT Gateways&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;, if one doesn’t exist already". Let me know if you have any questions.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 16:59:28 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/77542#M37</guid>
      <dc:creator>AlexEsibov</dc:creator>
      <dc:date>2024-07-09T16:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/78527#M38</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;After enabling the IP access list for my databricks workspace, CI/CD pipeline between the DevOps repo and Databricks is failing. The IPs that are failing are those I added to the access list, but all failing IPs are dynamic. How can I mitigate this issue? TIA&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 13:24:46 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/78527#M38</guid>
      <dc:creator>Said</dc:creator>
      <dc:date>2024-07-12T13:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/79463#M39</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/106160"&gt;@Said&lt;/a&gt;&amp;nbsp;to be clear - this communication was scoped only to customers who are already using workspace IP ACLs already. That said, it's hard to know exactly why your scenario is failing - if you have a support subscription, you can follow the steps here to submit a support ticket. That would probably be the easiest way to diagnose the issue: &lt;A href="https://docs.databricks.com/en/resources/support.html" target="_blank"&gt;https://docs.databricks.com/en/resources/support.html&lt;/A&gt;.&amp;nbsp;&lt;SPAN&gt;You can also submit a support case by emailing&amp;nbsp;&lt;/SPAN&gt;&lt;A class="reference external" href="mailto:help%40databricks.com" target="_blank" rel="noopener"&gt;help&lt;SPAN&gt;@&lt;/SPAN&gt;databricks&lt;SPAN&gt;.&lt;/SPAN&gt;com&lt;/A&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 15:52:31 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/79463#M39</guid>
      <dc:creator>AlexEsibov</dc:creator>
      <dc:date>2024-07-19T15:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/81937#M41</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our databricks set up is VNET injection and SCC, enabled private link as simplified deployment. as per the implementation i believe we have one front-end and back-end one Browser authentication private endpoint.&lt;/P&gt;&lt;P&gt;i believe we won't be impacted but wanted to get some inputs from community&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/network/classic/private-link-simplified" target="_blank"&gt;Enable Azure Private Link as a simplified deployment - Azure Databricks | Microsoft Learn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Avvar2022_0-1722888065956.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/10146i2AA07301B9AA7468/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Avvar2022_0-1722888065956.png" alt="Avvar2022_0-1722888065956.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 20:04:03 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/81937#M41</guid>
      <dc:creator>Avvar2022</dc:creator>
      <dc:date>2024-08-05T20:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/81939#M42</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/55459"&gt;@Avvar2022&lt;/a&gt;&amp;nbsp;correct - if you already have backend private link configured, you do not need to take action on that workspace.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 20:22:25 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/81939#M42</guid>
      <dc:creator>AlexEsibov</dc:creator>
      <dc:date>2024-08-05T20:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/83071#M43</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/89926"&gt;@AlexEsibov&lt;/a&gt;&amp;nbsp;we are going to implement the nat-gateway solution here. I have two questions:&lt;/P&gt;&lt;P&gt;1. We have 3 workspaces in dev and 3 in prod. Should we use a unique public-ip/nat-gateway per each workspace or should/could they share the same? The 3 workspaces are devided in to two vnets, please see below clarification:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;vnet1&lt;UL&gt;&lt;LI&gt;workspace 1&lt;/LI&gt;&lt;LI&gt;workspace 2&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;vnet2&lt;UL&gt;&lt;LI&gt;workspace 3&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;2. Should we NAT the traffic from both the public and private cluster subnets, or is it only the public clusters that communicates with the control plane?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 09:37:48 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/83071#M43</guid>
      <dc:creator>MarkusL</dc:creator>
      <dc:date>2024-08-15T09:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [Azure] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/83719#M44</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;In my company we have Databricks deployed in Azure with Simplified terraform deployment. We have the two private endpoints for &lt;STRONG&gt;databricks_ui_api&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;and second &lt;STRONG&gt;browser_authentication&lt;/STRONG&gt;. As far as I understand, we don't have to make any updates regarding the security update on 26th August. Is that right, because we are little worried? Thank you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 06:49:59 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-azure-update-outbound-connectivity-for-classic/bc-p/83719#M44</guid>
      <dc:creator>Abadoom</dc:creator>
      <dc:date>2024-08-21T06:49:59Z</dc:date>
    </item>
  </channel>
</rss>

