Azure Databricks Serverless queries hang or fail with PERMISSION_DENIED: Cert validation failed. Origin workspace. Even SELECT 1 fails, while basic Python like print("hello") works.

Yogesh Niture 0 Reputation points
2026-09-20T06:22:54.12+00:00

I am using an Azure Databricks Serverless workspace.

My notebooks open normally and basic Python commands such as:

print("hello")

run successfully in under a second.

However, Spark SQL and catalog-related commands either hang for a long time or fail. For example:

%sql

SELECT 1;

and:

%sql

Screenshot 2026-09-20 at 11.42.11 AM.png

USE CATALOG ecommerce;

do not execute normally.

I received the following error:

PERMISSION_DENIED: Cert validation failed. Origin workspace.

The exception also included java.rmi.RemoteException.

Troubleshooting already performed:

  • Tested in a new notebook
  • Started a fresh Serverless session
  • Basic Python execution works
  • Spark SQL execution still hangs or fails
  • Azure Service Health shows no active service issues
  • Azure Databricks automatic diagnostics reported no issues detected

This does not appear to be related to a specific table, dataset, join, or Spark workload because even SELECT 1 fails.

Has anyone encountered this certificate validation issue with Azure Databricks Serverless, and is there a workspace-side or serverless backend fix? Further testing confirms that Unity Catalog and my tables are healthy. Using a SQL Warehouse, SHOW CATALOGS, USE CATALOG ecommerce, SHOW SCHEMAS, and queries against ecommerce.silver.slv_products all execute successfully. The same catalog operations hang or fail only from Serverless notebook compute. This appears isolated to the Serverless notebook compute-to-Unity-Catalog path.

Azure Databricks
Azure Databricks

An Apache Spark-based analytics platform optimized for Azure.

0 comments No comments

2 answers

Sort by: Newest
  1. Maksood Ahmed 15 Reputation points Microsoft External Staff Moderator
    2026-09-28T08:58:52.8+00:00

    Hi @Yogesh Niture ,
    Based on the troubleshooting results, this appears to be isolated to the Azure Databricks Serverless notebook compute path, rather than a Unity Catalog permission or table-level issue.

    Since:

    • Python execution works normally.
    • SELECT 1 and USE CATALOG fail/hang only on Serverless.
    • The same Unity Catalog operations work successfully from a SQL Warehouse.
    • A fresh notebook and Serverless session produce the same behavior.
    • The error is PERMISSION_DENIED: Cert validation failed. Origin workspace.

    I would recommend checking the workspace's Serverless networking/security configuration, particularly any serverless network policies, firewall/NSP rules, private connectivity, or other network controls that could affect Serverless compute. Azure Databricks Serverless uses a managed compute plane, and its connectivity to Azure resources can be controlled through Network Connectivity Configurations (NCCs) and serverless network policies.

    However, because SELECT 1 itself fails and the SQL Warehouse works, if no customer-side network restriction is identified, this should be escalated to Microsoft/Azure Databricks Support as a possible Serverless backend/control-plane certificate validation issue.

    When opening the support request, provide:

    1. Workspace URL/ID and Azure region
    2. Exact UTC timestamp of the failure
    3. The full PERMISSION_DENIED: Cert validation failed. Origin workspace error
    4. Confirmation that SQL Warehouse can access the same catalog successfully
    5. Confirmation that a new Serverless session and notebook were tested
    6. Screenshot/logs showing the failure

    Ask support to specifically investigate the Serverless notebook compute → workspace/Unity Catalog service certificate validation path.

    This distinction is important because Azure Databricks documentation notes that SSL/certificate failures can be caused by networking/security configuration, while Serverless compute has its own managed networking pathBased on the troubleshooting results, this appears to be isolated to the Azure Databricks Serverless notebook compute path, rather than a Unity Catalog permission or table-level issue.

    Since:

    • Python execution works normally.
    • SELECT 1 and USE CATALOG fail/hang only on Serverless.
    • The same Unity Catalog operations work successfully from a SQL Warehouse.
    • A fresh notebook and Serverless session produce the same behavior.
    • The error is PERMISSION_DENIED: Cert validation failed. Origin workspace.

    I would recommend checking the workspace's Serverless networking/security configuration, particularly any serverless network policies, firewall/NSP rules, private connectivity, or other network controls that could affect Serverless compute. Azure Databricks Serverless uses a managed compute plane, and its connectivity to Azure resources can be controlled through Network Connectivity Configurations (NCCs) and serverless network policies.

    However, because SELECT 1 itself fails and the SQL Warehouse works, if no customer-side network restriction is identified, this should be escalated to Microsoft/Azure Databricks Support as a possible Serverless backend/control-plane certificate validation issue.

    When opening the support request, provide:

    1. Workspace URL/ID and Azure region
    2. Exact UTC timestamp of the failure
    3. The full PERMISSION_DENIED: Cert validation failed. Origin workspace error
    4. Confirmation that SQL Warehouse can access the same catalog successfully
    5. Confirmation that a new Serverless session and notebook were tested
    6. Screenshot/logs showing the failure

    Ask support to specifically investigate the Serverless notebook compute → workspace/Unity Catalog service certificate validation path.

    This distinction is important because Azure Databricks documentation notes that SSL/certificate failures can be caused by networking/security configuration, while Serverless compute has its own managed networking path

    Was this answer helpful?


  2. Vinodh247-1375 44,801 Reputation points Volunteer Moderator
    2026-09-20T09:35:33.39+00:00

    Based on the additional testing, this no longer looks like a Unity Catalog permission issue, catalog binding issue, or problem with the underlying tables.

    The key observation is that the same catalog operations (SHOW CATALOGS, USE CATALOG, SHOW SCHEMAS) and table queries execute successfully through a SQL Warehouse, while even a trivial SELECT 1 fails from Serverless notebook compute with:

    PERMISSION_DENIED: Cert validation failed. Origin workspace

    That points to a failure in the Serverless notebook compute path rather than a problem with the catalog objects themselves.

    A few targeted checks that may help further isolate the issue:

    Verify whether any serverless network connectivity configuration (NCC) or serverless egress policy is associated with the workspace. Certificate validation failures can occur when Serverless compute cannot successfully reach required control-plane or governance endpoints.

    Compare behaviour between Serverless notebook compute and a classic/all-purpose cluster in the same workspace. If Spark SQL succeeds on classic compute but fails only on Serverless, that further narrows the issue to the Serverless execution path.

    1. Run a simple Spark operation from Python rather than SQL:

      spark.range(1).count()

    If this also hangs or fails, it strengthens the conclusion that the issue occurs when a Spark session attempts to initialise or communicate with backend services, rather than being specific to SQL parsing or Unity Catalog commands.

    1. Check whether the issue is reproducible across multiple users in the same workspace. If all users experience the same behaviour, that would indicate a workspace-level Serverless configuration issue rather than a user-specific permission problem.

    Given that SQL Warehouse access to the metastore and tables is working correctly, I would avoid spending additional time recreating catalogs, changing table grants, or modifying Unity Catalog permissions. The evidence gathered so far points away from those areas and toward the Serverless notebook compute environment itself.

    Help make this community better for everyone: if this answer resolved your issue, please accept it or leave an upvote. If not, share more details in a comment so we can continue the discussion and find the right solution.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.