Forum Discussion
Outbound Access Protection Tenant Level
Hi, what is the GA timeline for outbound access protection on tenant level in Fabric? Here are the relevant articles on the same. Any input is appreciated.
Workspace outbound access protection overview - Microsoft Fabric | Microsoft Learn
Hi zeesoft,
Thanks, that makes the requirement much clearer.
For the Data Ingestion / Data Factory side specifically, I checked the current Fabric documentation and roadmap again, but I still cannot find a published GA date.
Microsoft currently documents Outbound Access Protection for Data Factory at workspace level, but I do not see a GA milestone or target date published for that capability yet.
There is a useful comparison in the current release history: OAP support for Warehouse was announced as Generally Available in March 2026, while other OAP integrations remain at different maturity levels. Microsoft appears to be moving the workloads independently rather than taking the whole OAP feature set to GA at once.
So for planning the automation across 500+ workspaces, I would not currently build around an assumed GA date for Data Ingestion.
If this is blocking a production security rollout, I think the best next step would be to raise it through your Microsoft account team / support channel and ask specifically for the roadmap status of Data Factory / Data Ingestion OAP GA, because I do not see a public date that we can reliably plan against today.
In the meantime, automating the workspace-level configuration still looks like the practical route once the workload reaches the maturity level you are comfortable deploying.
AI-assisted drafting: AI was used to help structure and phrase this response. I reviewed and validated the technical content before posting.
5 Replies
- ShivekMaharaj
Memorable Member
Hi zeesoft,
I checked the current Fabric docs and roadmap, but I cannot find a published GA date for the tenant-level outbound access protection control yet.
One distinction that may be useful is that the tenant setting itself is really an enablement control. Microsoft documents Configure workspace-level outbound network rules as allowing Fabric admins to decide whether workspace admins can configure OAP. The actual blocking and allow-list rules are still applied at the individual workspace level.
The underlying workspace outbound access protection support is also at different maturity levels depending on the workload. For example, Spark, Warehouse and Data Factory have GA support, while some newer integrations are still in preview.
I also checked the current Fabric roadmap and do not see a separate published milestone for making this a tenant-wide enforcement policy or for a GA date on the tenant control itself.
So at the moment I would treat the tenant setting as the administrative gate for workspace-level OAP, rather than a tenant-wide OAP policy.
If the requirement is to enforce the same outbound policy across every workspace centrally, I do not see that capability documented today.
AI-assisted drafting: AI was used to help structure and phrase this response. I reviewed and validated the technical content before posting.
- zeesoft
Microsoft Employee
Thanks ShivekMaharaj. The reason why I'm looking for a tenant-wide control is because my customer has over 500 workspaces and they want to enforce this rule on all the workspaces under that tenant.
Since there is no such plan to introduct tenant-wide enablement so they'll have to use some sort of automation to enable OAP on individual workspace level.
The OAP on Data Ingestion is in Preview at the moment, so they are asking if there is any GA timeline for that in Fabric roadmap so that they can plan this enablement through automation.
- ShivekMaharaj
Memorable Member
Hi zeesoft,
Thanks, that makes the requirement much clearer.
For the Data Ingestion / Data Factory side specifically, I checked the current Fabric documentation and roadmap again, but I still cannot find a published GA date.
Microsoft currently documents Outbound Access Protection for Data Factory at workspace level, but I do not see a GA milestone or target date published for that capability yet.
There is a useful comparison in the current release history: OAP support for Warehouse was announced as Generally Available in March 2026, while other OAP integrations remain at different maturity levels. Microsoft appears to be moving the workloads independently rather than taking the whole OAP feature set to GA at once.
So for planning the automation across 500+ workspaces, I would not currently build around an assumed GA date for Data Ingestion.
If this is blocking a production security rollout, I think the best next step would be to raise it through your Microsoft account team / support channel and ask specifically for the roadmap status of Data Factory / Data Ingestion OAP GA, because I do not see a public date that we can reliably plan against today.
In the meantime, automating the workspace-level configuration still looks like the practical route once the workload reaches the maturity level you are comfortable deploying.
AI-assisted drafting: AI was used to help structure and phrase this response. I reviewed and validated the technical content before posting.
- v-kathullac
Community Support
Thankyou ShivekMaharaj for Addressing the issue.
Hi zeesoft ,
As we haven’t heard back from you, we wanted to kindly follow up to check if the solution provided for the issue worked? or Let us know if you need any further assistance?
Regards,
Chaithanya
- v-kathullac
Community Support
Hi zeesoft ,
As we haven’t heard back from you, we wanted to kindly follow up to check if the solution provided for the issue worked? or Let us know if you need any further assistance?
Regards,
Chaithanya