Forum Discussion

TK12345's avatar
TK12345
Resolver II
6 months ago
Solved

Data connection rules combined with block public acces

Hi all, 

I am trying to set up a secure fabric environment with outbound and inbound rules. Combined with block public internet access, so people within the company can only go to Fabric via a dedicated VM. As you can see in the picture i created 3 Managed Private Endpoints for the data extraction, this works fine with notebooks. I also have 2 connections that needs pipelines for the extraction, so that is why I have configured a VnetGateway. Because I block outbound Public access, it is a good way out to use the connection rules to allow the VnetGateway. It worked a few days ago. 

 

It looks like that since I Block Public Internet Access this feature wont work anymore. Is this a bug, or is this just not working because of another reason?

 

 

  • Hi TK12345 ,

    Thanks for clarifying. I can see why this might be confusing. From your description, it doesn’t seem like the Block Public Internet Access toggle is causing issues with connection rules. Since things start working again after a few hours, and it also works in a new workspace with public access still blocked, it’s likely that Fabric just needs some time to refresh or load the tenant connection policies.

     

    This could explain why the page shows an error at first and then works later without any changes. It doesn’t appear to be a misconfiguration on your end, but more likely a backend sync delay or something related to the feature still developing.

     

    I hope this clarifies the situation. If I’ve misunderstood any part of your situation, please let us know.

     

4 Replies

  • Hi TK12345 ,

    Thank you for engaging with the Microsoft Fabric Community. When you enable Block Public Internet Access, Fabric restricts its ability to access external resources. Managed Private Endpoints continue to function because they remain within the private network, allowing notebooks to connect as usual.

     

    However, connection rules and the VNet Gateway operate differently. 

    The error message (“Unable to retrieve the tenant’s data connection policies”)

    suggests that Fabric cannot load the necessary policy details after public outbound access is blocked. This likely explains why the feature worked previously and stopped after enabling the setting.

     

    To verify, you can temporarily disable Block Public Internet Access and see if the connection rules section loads properly. If it does, the issue is probably related to this restriction.

    In this situation, you have two options
    1. Use Managed Private Endpoints where possible, or permit minimal outbound access so Fabric can access and apply the connection policies for the gateway.

    2. This appears to be an interaction between the network restriction and the connection rules feature, rather than a configuration error.

     

    Regards,

    Yugandhar.

    • TK12345's avatar
      TK12345
      Resolver II

      First of all, thanks for the reply. 

      Indeed, when disable public internet access after a few hours it does work again. But in my opinion the outbound and inbound rules are made so we can block the public internet access. So I am not seeing the connection between the toggle and then the connection rules not working. So that is why I am wondering if this is a kind of bug or something. Maybe cause the feature is new...? Cause when I make a new workspace (with the blocked internet still on) I can setup the connection rule for VnetGateway as well, it is not grayed out our something......
      The thing is, I cannot see the connection between Block Public Internet Access

      • V-yubandi-msft's avatar
        V-yubandi-msft
        Community Support

        Hi TK12345 ,

        Thanks for clarifying. I can see why this might be confusing. From your description, it doesn’t seem like the Block Public Internet Access toggle is causing issues with connection rules. Since things start working again after a few hours, and it also works in a new workspace with public access still blocked, it’s likely that Fabric just needs some time to refresh or load the tenant connection policies.

         

        This could explain why the page shows an error at first and then works later without any changes. It doesn’t appear to be a misconfiguration on your end, but more likely a backend sync delay or something related to the feature still developing.

         

        I hope this clarifies the situation. If I’ve misunderstood any part of your situation, please let us know.

         

  • Hi TK12345 ,

    We haven’t received a response from your end yet. Please let us know whether the issue has been resolved or if you’re still facing any difficulties. Feel free to reach out if you need further assistance.

     

    Thank you.