Currently, Fabric Spark Notebook & Eventstreams run through the managed private endpoint defined in the Fabric workspace.
For Fabric UDF's (User Data Functions), this is not supported.
The idea focuses on allowing UDF flows to run through the private endpoint (of the Fabric workspace).
The most common use case is getting secrets from an Azure Key Vault that is not open to public internet (default in an enterprise setup).
Note that
a) it is possible to get secrets in the notebook over MPE and call the UDF, but this setup is not desired for UDF's in the context of Power BI integrations. In this case, the UDF is being called by a linked button action from Power BI.
b) Fabric IP whitelisting is not desired as this setup can easily be replicated by another party
@deborshi_nag
@mksuni
1 Comment
- michal_januszewNew Member
We strongly support this feature request.
Private connectivity for Fabric UDFs is becoming a baseline enterprise requirement rather than a nice-to-have. Across enterprise implementations, organizations are increasingly standardizing on "private access only" for services such as Azure Key Vault, storage accounts, databases, and internal APIs as part of their security and compliance posture.
Today, the lack of private connectivity support for UDF execution creates an inconsistency within Fabric and with broader Microsoft platform networking capabilities. Notebooks and other workloads can securely access private resources, but UDFs cannot. This becomes particularly problematic when UDFs are exposed through Power BI experiences, where introducing intermediary notebooks or relying on IP allowlists is not an acceptable enterprise architecture.
For many organizations, the ability for Fabric UDFs to securely access private-only services through private connectivity is a critical prerequisite for production adoption and governance approval.
Recent ideas
Reintroduce Tenant/Capacity Switch to Control "Users can create Plan items" Post-GA
During the Preview phase of Fabric Plan items, administrators had access to a dedicated tenant/capacity setting: "Users can create Plan items". With General Availability (GA), this granular administr...Sri-Surendra_Ku1 hour agoNew MemberNew97Views13likes1CommentSupport Fabric SQL Database with workspace-level inbound Private Link
Fabric SQL Database supports tenant-level Private Link but not workspace-level Private Link. Securing a small number of databases therefore requires enabling Private Link across the entire tenant, in...WorkFull223 hours agoAdvocate INew8Views1like0CommentsImprove Relationship UI Wording to Better Reflect Filter Propagation Direction
The current relationship dialog can be confusing because the UI labels "From" and "To" do not always align with users' linguistic expectations regarding filter propagation. As per document : Relation...v-varunvv4 hours agoMicrosoft EmployeeNew14Views4likes0CommentsDynamic ADLS-Gen2 path input for Spark Jobs Main definition file
I would like the ability to add a dynamic input box on a spark job definition's "Main Definition File" "ADLS-Gen2 path". this would be useful to set base and variable paths across all spark jobs...mfink_db4 hours agoNew MemberNew224Views2likes1Comment