Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Don't miss out! 2025 Microsoft Fabric Community Conference, March 31 - April 2, Las Vegas, Nevada. Use code MSCUST for a $150 discount. Prices go up February 11th. Register now.

Reply
dmct
New Member

Does ADF Managed VNet with Azure IR Connect to Amazon S3 via Public Internet?

Hi everyone,

I'm using Azure Data Factory (ADF) with a Managed Virtual Network (VNet) and the Azure Integration Runtime (IR) to connect to Amazon S3. I want to ensure that my data transfer does not traverse the public internet for security reasons.

Could someone please confirm:

  1. If the data transfer between ADF and Amazon S3 goes through the public internet in this setup?
  2. What configurations or settings are required to ensure the data transfer remains within the Microsoft backbone network?
  3. Any best practices or additional considerations to secure the data transfer?

Thank you for your assistance!

1 ACCEPTED SOLUTION
nilendraFabric
Solution Supplier
Solution Supplier

 

enabling Managed VNet alone does not guarantee that traffic to external services like Amazon S3 stays off the public internet.

 

Quoted from MS doc :

 

Network security

"By default, ADF transfers data from Amazon S3 to Azure Blob Storage or Azure Data Lake Storage Gen2 using encrypted connection over HTTPS protocol. HTTPS provides data encryption in transit and prevents eavesdropping and man-in-the-middle attacks.

Alternatively, if you don't want data to be transferred over public Internet, you can achieve higher security by transferring data over a private peering link between AWS Direct Connect and Azure Express Route. Refer to the solution architecture in the next section on how this can be achieved."


A great articles covering all aspects of your question:

 

https://learn.microsoft.com/en-us/azure/data-factory/data-migration-guidance-s3-azure-storage

 

nilendraFabric_0-1738173993453.png

 

 



If this helps please accept the solution.

 

Thanks

 

View solution in original post

2 REPLIES 2
dmct
New Member

Thank-you for reply @nilendraFabric 
That's the article I was looking for and never found it. 

nilendraFabric
Solution Supplier
Solution Supplier

 

enabling Managed VNet alone does not guarantee that traffic to external services like Amazon S3 stays off the public internet.

 

Quoted from MS doc :

 

Network security

"By default, ADF transfers data from Amazon S3 to Azure Blob Storage or Azure Data Lake Storage Gen2 using encrypted connection over HTTPS protocol. HTTPS provides data encryption in transit and prevents eavesdropping and man-in-the-middle attacks.

Alternatively, if you don't want data to be transferred over public Internet, you can achieve higher security by transferring data over a private peering link between AWS Direct Connect and Azure Express Route. Refer to the solution architecture in the next section on how this can be achieved."


A great articles covering all aspects of your question:

 

https://learn.microsoft.com/en-us/azure/data-factory/data-migration-guidance-s3-azure-storage

 

nilendraFabric_0-1738173993453.png

 

 



If this helps please accept the solution.

 

Thanks

 

Helpful resources

Announcements
Las Vegas 2025

Join us at the Microsoft Fabric Community Conference

March 31 - April 2, 2025, in Las Vegas, Nevada. Use code MSCUST for a $150 discount! Prices go up Feb. 11th.

JanFabricDE_carousel

Fabric Monthly Update - January 2025

Explore the power of Python Notebooks in Fabric!

JanFabricDW_carousel

Fabric Monthly Update - January 2025

Unlock the latest Fabric Data Warehouse upgrades!

JanFabricDF_carousel

Fabric Monthly Update - January 2025

Take your data replication to the next level with Fabric's latest updates!