
The compliance security profile only supports preview features from a fixed list
Turn the compliance security profile on and only what is on the supported list works. Other features in Public Preview, Private Preview or Beta are not supported, part of the list applies only under HIPAA, and the hardening restarts your clusters.
Impact
The compliance security profile is the hardening Azure Databricks needs for a range of compliance standards, and since 1 September 2026 it is also required for HIPAA, HITRUST and IRAP; on that same date the compliance controls for HITRUST and IRAP became generally available. The limitation is not in turning it on but in what is still allowed to run afterwards. On a workspace with the profile, Databricks supports only the preview features explicitly on the supported list; other features in Public Preview, Private Preview or Beta are not supported. That is a hard boundary and not advice, and it hits platforms that have let preview features creep in without a decision. A second layer sits in the list itself: some features are marked HIPAA only and work only on workspaces that are actually set to the HIPAA standard, such as Agent Mode in Genie Agents, `ai_forecast()` and on-behalf-of-user authorization for custom agents. The per-standard scoping is moreover not always a single standard: the Data governance hub is supported in Beta only for C5, HIPAA, HITRUST, PCI-DSS and TISAX, or with the profile on without a standard. IRAP is not in that set, so a workspace you deliberately put on IRAP loses that capability. Others are marked Serverless and exist only on the serverless compute plane, with availability that differs per region and per standard. Under IRAP a condition of its own comes with that: serverless compute only starts when the base environment includes version 5 or higher. Apart from the feature list, the hardening changes your platform's behaviour in three places. Automatic cluster updates restart compute periodically inside a configurable maintenance window, which can catch a long-running job halfway. Traffic inside the cluster and outbound goes over TLS 1.2 or higher, including to the metastore. And monitoring agents run in the compute plane image producing reviewable logs. Two things that look like surprises but are documented behaviour: since 18 September 2026 Databricks Apps is on by default for workspaces with the profile, and account-level Genie One does not aggregate data from workspaces where the profile is on, so such an overview stays empty there. That first point has just inverted. Until mid-September a workspace admin had to enable Apps under the profile on the Previews page; that manual step is gone and the capability is now there by itself. A limitation disappears with that and a design question appears: on a workspace you hardened precisely because it holds regulated data, users can now run applications without anyone asking for it. So check what has appeared on your regulated workspaces rather than waiting until you need it. In the same week the feature list widened on a second point: since 17 September 2026 Unity Gateway supports all compliance security profile standards supported by Azure Databricks and is available by default for workspaces with the profile. Finally two preconditions that belong in a design. The profile is a per-workspace choice and produces a separate line on your invoice through the Enhanced Security and Compliance add-on. And your identities and their attributes are stored in the United States and in every region where you have a workspace; for more granular control over that, a separate Databricks account is the only instrument.
Workaround
Inventory which preview features run in your workspaces before you turn the profile on and hold them against the supported list, because that is where the surprise sits and not in the enabling itself. Keep regulated workloads together on a limited number of workspaces rather than spreading the profile across your whole estate; that saves the add-on on workspaces that do not need it and keeps the narrower feature set in one place. Select the right standard deliberately and not just the profile, because the HIPAA only features look at the selected standard and not at the presence of the profile; for PHI, Databricks explicitly recommends the profile with HIPAA alongside it. Schedule the maintenance window for the automatic cluster updates at a moment that does not hit your longest-running job, and treat a restart as normal behaviour rather than an incident. Inventory whether Databricks Apps runs on your regulated workspaces, because since 18 September 2026 it is on by default there and the manual step on the Previews page is gone. The question is therefore no longer whether you enable it but whether you want to keep it; settle who may publish applications and what those may reach, before the first one appears. Do not build reporting on account-level Genie One across workspaces with the profile, because that data does not arrive there. Check the supported list again with every extension of your platform, because the list moves with the products and a feature that is unsupported today can be on it tomorrow. And hold on to your own responsibility: the profile delivers controls that help meet a standard, not a statement that you meet it.
Microsoft roadmap
Databricks updates the list of supported preview features as features go GA or gain support, so the boundary is not static. By now a whole series of announced movements is queued up that hits workspaces with the profile directly, and almost all of them land in the same month. Databricks Apps was to be turned on automatically in early September 2026; that shipped on 18 September 2026, so that movement is closed. Unity Gateway followed on 17 September 2026 and now supports all compliance security profile standards supported by Azure Databricks, available by default under the profile. Role-based access control becomes available by default in mid-September 2026. Dedicated group clusters follow in September 2026, which makes the Dedicated access mode for groups appear there by itself. Secrets in Unity Catalog and user authorization for Databricks Apps follow in late September 2026. AI Search high QPS became available by default in late August 2026, where existing endpoints are left alone and the extra cost applies only once you set a target QPS yourself. Query-based connectors in Lakeflow Connect are announced without a date. And the Lakeflow Pipelines Editor became the default editor on workspaces with the profile in August, with the legacy editor removed; that last one is no longer a choice. The common thread is that the profile increasingly means a narrower feature set in name only, and that the features arriving do not ask permission. So schedule a moment in September to check what has appeared on your regulated workspaces. For the requirement itself, 1 September 2026 was the announced date for HIPAA, HITRUST and IRAP and it has now taken effect; on that same day the compliance controls for HITRUST and IRAP became generally available. For C5, K-FSI, PCI-DSS, UK Cyber Essentials Plus, CCCS Medium (Protected B), TISAX and ISMAP the requirement already applied. There is no announcement that the limitation on unsupported preview features goes away; expect it to stay and check the page with every extension.
What does the research say?
Read the research: Azure Databricks: Architecture & Cost
