<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Azure Databricks: Required change in resource firewalls allowlisting Databricks serverless compute in Product Platform Updates</title>
    <link>https://community.databricks.com/t5/product-platform-updates/azure-databricks-required-change-in-resource-firewalls/ba-p/143061</link>
    <description>&lt;H2 class="body-text"&gt;&lt;STRONG&gt;Background&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P class="body-text"&gt;To improve serverless scalability and expand service endpoint support to&amp;nbsp;additional&amp;nbsp;resources, Azure Databricks will make a change to the identifiers used to&amp;nbsp;firewall&amp;nbsp;storage access from serverless&amp;nbsp;compute.&amp;nbsp;&lt;/P&gt;
&lt;P class="body-text"&gt;If you allow-list Azure Databricks&amp;nbsp;&lt;A class="body-link" href="https://learn.microsoft.com/azure/databricks/security/network/serverless-network-security/serverless-firewall" target="_blank" rel="noopener"&gt;serverless subnet IDs&lt;/A&gt;&amp;nbsp;in any Azure storage firewalls, action is&amp;nbsp;required. Note that if you disallow public access to your storage accounts and use Azure Private Link to connect&amp;nbsp;from&amp;nbsp;Azure Databricks, no action is&amp;nbsp;required.&lt;/P&gt;
&lt;P class="body-text"&gt;&lt;SPAN&gt;Following a comprehensive review, we have identified additional affected subscriptions. To ensure a unified transition across all impacted customers, the migration deadline has been updated to &lt;/SPAN&gt;&lt;STRONG&gt;June 9, 2026&lt;/STRONG&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 class="body-text"&gt;&lt;STRONG&gt;Required Action&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P class="body-text"&gt;By &lt;STRONG&gt;June 9, 2026&lt;/STRONG&gt;, any existing Azure storage account allowlisting Databricks serverless subnet IDs must:&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI class="body-text"&gt;Be onboarded to a&amp;nbsp;&lt;A class="body-link" href="https://learn.microsoft.com/azure/private-link/network-security-perimeter-concepts" target="_blank" rel="noopener"&gt;network security perimeter&lt;/A&gt;&amp;nbsp;in&amp;nbsp;&lt;A class="body-link" href="https://learn.microsoft.com/azure/private-link/network-security-perimeter-transition#enable-transition-mode" target="_blank" rel="noopener"&gt;transition mode&lt;/A&gt;&amp;nbsp;
&lt;OL&gt;
&lt;LI class="body-text"&gt;If you are unable to&amp;nbsp;onboard to&amp;nbsp;a network security perimeter, you must reach out to file a support ticket to discuss alternatives by &lt;STRONG&gt;30 March 2026&lt;/STRONG&gt;.&amp;nbsp;&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI class="body-text"&gt;&lt;SPAN&gt;In your network security perimeter firewall(s), allowlist &lt;/SPAN&gt;&lt;STRONG&gt;AzureDatabricksServerless&lt;/STRONG&gt;&lt;SPAN&gt;. Regional scoping is recommended (e.g., &lt;/SPAN&gt;&lt;STRONG&gt;AzureDatabricksServerless.EastUS2&lt;/STRONG&gt;&lt;SPAN&gt;).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI-CODE lang="markup"&gt;Note: Using the AzureDatabricksServerless service tag and allows Azure Databricks serverless compute to communicate with your Azure resources over the Azure backbone. The tag maps to Azure Databricks public IPs that represent service endpoints and NAT IPs.&lt;/LI-CODE&gt;
&lt;P class="body-text"&gt;&lt;EM&gt;Important callout:&amp;nbsp;Remain in&amp;nbsp;&lt;A class="body-link" href="https://learn.microsoft.com/azure/private-link/network-security-perimeter-transition#enable-transition-mode" target="_blank" rel="noopener"&gt;transition mode&lt;/A&gt;&amp;nbsp;indefinitely to avoid impact to your storage access, if any of the&amp;nbsp;&lt;A class="body-link" href="https://learn.microsoft.com/azure/storage/common/storage-network-security-perimeter#limitations" target="_blank" rel="noopener"&gt;Network Security Perimeter limitations&lt;/A&gt;&amp;nbsp;apply to you.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional details, including the benefits of this change, and step-by-step guidance, can be found &lt;/SPAN&gt;&lt;A href="https://community.databricks.com/t5/product-platform-updates/azure-databricks-required-change-in-resource-firewalls/ba-p/143061" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 class="body-text"&gt;&lt;STRONG&gt;Help and support&lt;/STRONG&gt;&amp;nbsp;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;If you have questions, get answers from community experts in &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/answers/tags/133/azure" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;. If you have a support plan and need technical help, please &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/azure-portal/supportability/how-to-create-azure-support-request" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;create a support request&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Benefits of NSP&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;For Azure Databricks serverless outbound traffic, today’s &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/security/network/serverless-network-security/serverless-firewall" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;subnet ID feature&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; enables customers to connect over service endpoints to in-region or paired-region Azure storage accounts. This access has no data processing charge, and stays on the Azure backbone. The migration to Network Security Perimeter will enable Databricks to add additional resource support for service endpoints in the future, saving significant data processing charges for customers, and improving security posture. &lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Instructions&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Please refer to public documentation for step-by-step instructions:&amp;nbsp;&lt;A class="c-link" href="https://learn.microsoft.com/en-us/azure/databricks/security/network/serverless-network-security/serverless-nsp-firewall" target="_blank" rel="noopener noreferrer" data-stringify-link="https://learn.microsoft.com/en-us/azure/databricks/security/network/serverless-network-security/serverless-nsp-firewall" data-sk="tooltip_parent"&gt;https://learn.microsoft.com/en-us/azure/databricks/security/network/serverless-network-security/serverless-nsp-firewall&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN&gt;Automation Tools for Migration&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;If you would like helping to automate migration of your storage accounts, we have created a public repo that takes subscriptions as inputs, and enables retrieving storage accounts configured with Databricks serverless subnet IDs, and creating or updating Network Security Perimeters (NSPs) with the needed policy. Please refer to:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/brucenelson6655/nsp-migrate" target="_blank" rel="noopener"&gt;https://github.com/brucenelson6655/nsp-migrate&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Helpful Links:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/private-link/create-network-security-perimeter-powershell" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Quickstart - Create a network security perimeter - Azure PowerShell - Azure Private Link | Microsoft Learn&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/private-link/create-network-security-perimeter-cli" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Quickstart - Create a network security perimeter - Azure CLI - Azure Private Link | Microsoft Learn&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Mar 2026 19:21:11 GMT</pubDate>
    <dc:creator>AlexEsibov</dc:creator>
    <dc:date>2026-03-13T19:21:11Z</dc:date>
    <item>
      <title>Azure Databricks: Required change in resource firewalls allowlisting Databricks serverless compute</title>
      <link>https://community.databricks.com/t5/product-platform-updates/azure-databricks-required-change-in-resource-firewalls/ba-p/143061</link>
      <description>&lt;P&gt;&lt;SPAN&gt;To improve serverless scalability and expand service endpoint support to additional resources, Azure Databricks will make a change to the network identification used to restrict public access to storage access from serverless compute.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2026 19:21:11 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/azure-databricks-required-change-in-resource-firewalls/ba-p/143061</guid>
      <dc:creator>AlexEsibov</dc:creator>
      <dc:date>2026-03-13T19:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Databricks: Required change in resource firewalls allowlisting Databricks serverless compu</title>
      <link>https://community.databricks.com/t5/product-platform-updates/azure-databricks-required-change-in-resource-firewalls/bc-p/157433#M88</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;im facing difficulty in configuring NSP&amp;nbsp;&lt;/P&gt;&lt;P&gt;Serverless Compute + NCC configration in account console + Private Endpoint (PE) to storage account is working as expected.&lt;/P&gt;&lt;P&gt;When Network security perimeter (NSP) is added and storage account (SA), in NSP we have 2 access mode to choose (transition&amp;nbsp; and enforced )&lt;/P&gt;&lt;P&gt;1). Serverless + NCC + PE and Storage account (SA) Public access disabled - Working&lt;/P&gt;&lt;P&gt;2). Serverless + NCC + PE + NSP (either transition&amp;nbsp; or enforced) and Storage account (SA) Public access disabled -working&lt;/P&gt;&lt;P&gt;ERROR :&lt;/P&gt;&lt;P&gt;3). Serverless + NCC + PE + NSP (either transition&amp;nbsp; or enforced) and Storage account (SA) network access selected as&amp;nbsp; Secured by perimeter - Not Working - Error&amp;nbsp;&lt;/P&gt;&lt;P&gt;simple select query&amp;nbsp; :&lt;/P&gt;&lt;P&gt;select * from databricks_training.training.employees returns error-&lt;BR /&gt;[UNAUTHORIZED_ACCESS] Unauthorized access: PERMISSION_DENIED: Request for user delegation key is not authorized. Details: None SQLSTATE: 42501&lt;BR /&gt;Note&amp;nbsp; : In NSP inbound rule, there is option to select service tag, i have selected both global and regional serverless service tag.&lt;/P&gt;&lt;P&gt;My understanding is that the data plane communication should occur through the private endpoint. However, I am unsure whether any control plane communication is also being initiated and getting blocked, which could be causing the issue.&lt;/P&gt;&lt;P&gt;At this point, I do not have complete clarity on the exact root cause. Additionally, I anticipate that a similar issue may also occur with Classic Compute clusters in the same setup.&lt;/P&gt;&lt;P&gt;See attachment for configurations&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assistance Needed:&lt;/P&gt;&lt;P&gt;Is there any mitigation or supported configuration available when NSP is configured on a Storage Account and the storage account access level is set to “Secured by perimeter,” while accessing it from Databricks clusters?&lt;/P&gt;&lt;P&gt;Could you please help clarify how this scenario should be configured to avoid the access error?&lt;/P&gt;&lt;P&gt;Additionally:&lt;/P&gt;&lt;P&gt;Is the issue occurring because control plane communication is being blocked?&lt;BR /&gt;Since the “Allow Azure Databricks Control Plane” option via service tags is not available in this configuration, is there any alternative configuration or recommended approach that would work in this setup?&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2026 17:28:20 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/azure-databricks-required-change-in-resource-firewalls/bc-p/157433#M88</guid>
      <dc:creator>ittzzmalind</dc:creator>
      <dc:date>2026-05-21T17:28:20Z</dc:date>
    </item>
  </channel>
</rss>

