An Apache Spark-based analytics platform optimized for Azure.
Hi @Yogesh Niture ,
Based on the troubleshooting results, this appears to be isolated to the Azure Databricks Serverless notebook compute path, rather than a Unity Catalog permission or table-level issue.
Since:
- Python execution works normally.
-
SELECT 1andUSE CATALOGfail/hang only on Serverless. - The same Unity Catalog operations work successfully from a SQL Warehouse.
- A fresh notebook and Serverless session produce the same behavior.
- The error is
PERMISSION_DENIED: Cert validation failed. Origin workspace.
I would recommend checking the workspace's Serverless networking/security configuration, particularly any serverless network policies, firewall/NSP rules, private connectivity, or other network controls that could affect Serverless compute. Azure Databricks Serverless uses a managed compute plane, and its connectivity to Azure resources can be controlled through Network Connectivity Configurations (NCCs) and serverless network policies.
However, because SELECT 1 itself fails and the SQL Warehouse works, if no customer-side network restriction is identified, this should be escalated to Microsoft/Azure Databricks Support as a possible Serverless backend/control-plane certificate validation issue.
When opening the support request, provide:
- Workspace URL/ID and Azure region
- Exact UTC timestamp of the failure
- The full
PERMISSION_DENIED: Cert validation failed. Origin workspaceerror - Confirmation that SQL Warehouse can access the same catalog successfully
- Confirmation that a new Serverless session and notebook were tested
- Screenshot/logs showing the failure
Ask support to specifically investigate the Serverless notebook compute → workspace/Unity Catalog service certificate validation path.
This distinction is important because Azure Databricks documentation notes that SSL/certificate failures can be caused by networking/security configuration, while Serverless compute has its own managed networking pathBased on the troubleshooting results, this appears to be isolated to the Azure Databricks Serverless notebook compute path, rather than a Unity Catalog permission or table-level issue.
Since:
- Python execution works normally.
-
SELECT 1andUSE CATALOGfail/hang only on Serverless. - The same Unity Catalog operations work successfully from a SQL Warehouse.
- A fresh notebook and Serverless session produce the same behavior.
- The error is
PERMISSION_DENIED: Cert validation failed. Origin workspace.
I would recommend checking the workspace's Serverless networking/security configuration, particularly any serverless network policies, firewall/NSP rules, private connectivity, or other network controls that could affect Serverless compute. Azure Databricks Serverless uses a managed compute plane, and its connectivity to Azure resources can be controlled through Network Connectivity Configurations (NCCs) and serverless network policies.
However, because SELECT 1 itself fails and the SQL Warehouse works, if no customer-side network restriction is identified, this should be escalated to Microsoft/Azure Databricks Support as a possible Serverless backend/control-plane certificate validation issue.
When opening the support request, provide:
- Workspace URL/ID and Azure region
- Exact UTC timestamp of the failure
- The full
PERMISSION_DENIED: Cert validation failed. Origin workspaceerror - Confirmation that SQL Warehouse can access the same catalog successfully
- Confirmation that a new Serverless session and notebook were tested
- Screenshot/logs showing the failure
Ask support to specifically investigate the Serverless notebook compute → workspace/Unity Catalog service certificate validation path.
This distinction is important because Azure Databricks documentation notes that SSL/certificate failures can be caused by networking/security configuration, while Serverless compute has its own managed networking path