Microsoft Fabric encrypts all data at rest by default with Microsoft-managed keys. For organizations with strict compliance and regulatory requirements, Customer-Managed Keys (CMK) let you wrap that encryption with your own key stored in Azure Key Vault—giving you full ownership and control of the key protecting your data. The CMK REST APIs are now generally available —so you can enable, inspect, rotate, and turn off workspace encryption programmatically, and give tenant admins a tenant-wide view of encryption state, all without leaving your automation and governance pipelines.
Previously, configuring CMK was a portal-only experience. That worked for a handful of workspaces, but it didn't scale to enabling encryption at provisioning time, rotating keys across many workspaces on a schedule, or auditing which key each workspace is using. With these APIs, CMK becomes a first-class, automation-friendly operation that fits naturally into existing workflows—scriptable, permission-gated, and auditable, so you can enforce and verify encryption posture at scale.
What APIs are new?
Four operations cover the full CMK lifecycle: apply or rotate a key, inspect current state, reset to Microsoft-managed keys, and govern at scale across the tenant.
- Assign a key — POST /v1/workspaces/{workspaceId}/encryption/assign
Enable CMK on a workspace or update to a different key by supplying a keyIdentifier:
{
"keyIdentifier": "https://my-vault.vault.azure.net/keys/my-key"
}
Fabric workspace CMK feature uses version-less key URIs, so key rotation flows through the same operation.
- Get workspace encryption — GET /v1/workspaces/{workspaceId}/encryption
Retrieve the current encryption configuration for a workspace: whether CMK is applied, the key identifier (Azure Key Vault key URI) in use, and the current status (for example, Enabled, EnableInProgress, or a failed state). Ideal for validation, auditing, and drift detection before taking action.
- Reset encryption — POST /v1/workspaces/{workspaceId}/encryption/reset
Disable CMK on a workspace and return it to encryption with Microsoft-managed keys.
- Admin: List workspaces with encryption state — GET /v1/admin/workspaces?include=encryption
The tenant admin API for governance at scale. Returns encryption details alongside each workspace, and can be filtered—for example, &encryptionStatus=EnableInProgress to find workspaces mid-enablement, or &capacityId={capacityId} to scope to a capacity. This gives tenant admins a single, tenant-wide view of which workspaces are CMK-protected and with which key.
All APIs use standard Fabric authentication (Microsoft Entra) and honor existing workspace and tenant-admin permissions, so only authorized identities can view or change a workspace's encryption posture.
Getting started
Refer to the Customer-managed keys for Fabric workspaces documentation and API documentation to learn more.
Have feedback? Your input helps shape the future of Fabric. Try out the new CMK APIs and let us know what works well and what you’d like to see next. Submit your ideas on Fabric Ideas and join the conversation on the Fabric Community.
Happy coding!