Forum Discussion
Cross tenant trusted workspace
- 1 year ago
I solved this by using the managed private endpoint in combination with a service principal in the same tenant as the storage account, since the workspaces does not work cross tenant without connecting the two tenants in some way.
With the private endpoint, I was able to connect to the storage account that had network restrictions.
With a custom Python script I copied the files from the network restricted storage account to Fabric.
Hi Anonymous,
Unfortunately, I did not get this setup working. I've added the workspace from tenant A in the network settings from tenant B. When I try to setup the connection in tenant A with a SAS-token, I get an invalid credentials error. I've tried all different access rights with the SAS-token.
What I think goes wrong in this case, is that a connection is not set on workspace level, but Fabric tenant level. When I add a workspace as trusted, the connection does not use that trusted workspace. It may only work if I use Workspace Identity as an authorization method. However, I cannot add the Workspace Identity from tenant A in tenant B as a Blob Data Reader for example.
What is the best way to add the Workspace Identity from tenant A in tenant B?
Hi FabianSchut ,
You can try to manage user identity and control user access to resources with the help of IAM.
Refer to below document:
Azure identity & access security best practices | Microsoft Learn
Best Regards,
Adamk Kong
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.