Users to Azure Databricks networking

This guide introduces features to customize network access between users and their Azure Databricks workspaces and account-level resources.

By default, users and applications can connect to Azure Databricks from any IP address. Users might access critical data sources using Azure Databricks. If a user's credentials are compromised through phishing or a similar attack, securing network access dramatically reduces the risk of an account takeover. Configurations like private connectivity, IP access lists, and firewalls help keep critical data secure.

You can also configure authentication and access control features to protect your users' credentials, see Authentication and access control.

The features on this page secure how users and applications connect to Azure Databricks, one of the three connection points in the Azure Databricks networking architecture.

See Network reference architecture overview.

Note

Users to Azure Databricks secure networking features require the Premium plan.

Private connectivity

Between Azure Databricks users and the control plane, Private Link provides strong controls that limit the source for inbound requests. If your organization routes traffic through an Azure environment, you can use Private Link to ensure the communication between users and the Databricks control plane does not traverse public IP addresses. See Configure inbound Private Link for workspaces.

Context-based ingress control

Context-based ingress control uses account-configured policies that combine identity, request type, and network source to determine who can reach your workspaces and account-level resources. Workspace-level policies govern access to workspaces, and a single account-level policy (account-policy) governs access to account-level resources, such as the account console.

For the access types, network sources, and identities you can match, along with enforcement modes and how ingress interacts with IP access lists and private connectivity, see Context-based ingress control.

To configure policies, see Manage workspace context-based ingress policies and Manage account context-based ingress policies.

IP access lists

Authentication proves user identity, but it does not enforce the users' network location. Accessing a cloud service from an unsecured network poses security risks, especially when the user may have authorized access to sensitive or personal data. Using IP access lists, you can configure Azure Databricks workspaces so that users connect to the service only through existing networks with a secure perimeter.

You can also use IP access lists to control access to account-level resources.

Admins can specify the IP addresses that are allowed access to Azure Databricks. You can also specify IP addresses or subnets to block. For details, see Manage IP access lists.

You can also use Private Link to block all public internet access to a Azure Databricks workspace.

Firewall rules

Many organizations use firewall to block traffic based on domain names. You must allow list Azure Databricks domain names to ensure access to Azure Databricks resources. For more information, see Configure domain name firewall rules.

Azure Databricks also performs host header validation to ensure requests use authorized Azure Databricks domains like .azuredatabricks.net. Requests using domains outside of the Azure Databricks network will be blocked. This security measure protects against potential HTTP host header attacks.