This is best Fabric, Power BI, SQL and AI community event. How do we know? The last event sold out! Save €200 with code FABCMTY200.
Register nowA new Data Days event is coming soon! This time we’re going bigger than ever. Fabric, Power BI, SQL, AI and more. Don't miss out.
Enterprise analytics platforms increasingly operate under strict security, compliance, and regulatory requirements. For many organizations, encryption is not sufficient without clear ownership and control of cryptographic keys.
Microsoft Fabric supports two complementary key management capabilities:
Now, workspace‑level CMK is supported in all Fabric capacities, including BYOK‑enabled capacities. With this update:
Comparing_previous_and_current_Fabric_encryption_models_showing_workspacelevel_C
Figure: Interoperability between workspace‑level CMK and capacity level-BYOK.
Compliance‑driven organizations: Meet regulatory requirements that mandate customer ownership of encryption keys and granular control over cryptographic boundaries.
Shared capacities with isolated workspaces: Protect sensitive workspaces within shared Fabric capacities, without introducing additional infrastructure.
Defense‑in‑depth strategies: Apply encryption at both the capacity and workspace layers, reducing blast radius and strengthening overall security posture.
By supporting CMK and BYOK together, Fabric enables flexible encryption strategies without increasing operational overhead.
Store keys in Azure Key Vault
Create encryption keys in Azure Key Vault or Azure Key Vault Managed HSM (MHSM).
In the Fabric admin portal:
In the workspace settings:
Organizations gain stronger control over encryption, improved auditability, and the ability to align key management with both operational and regulatory needs—without introducing additional infrastructure or complexity.
Whether you’re securing shared capacities, isolating sensitive workloads, or implementing a defense‑in‑depth strategy, Fabric’s enhanced key management capabilities provide the tools needed to protect analytics data with confidence.
Share your feedback! We’d love to hear from you. Reach out to your Microsoft account team with thoughts, suggestions, or feature requests. You can also leave your feedback in the comment section.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.