Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

60 Days of Data Days! Live and on-demand sessions, challenges, study groups and more! And it's all FREE!. Join now. Learn more

galir

Workspace Outbound Access Protection (OAP) for Real-Time Intelligence (Preview)

Coauthors: Gabi Lehner, Brian Stephens, George Guirguis, Alex Lin, Gali Reznick, and Bodhisatva Gautam 

 

Workspace Outbound Access Protection (OAP) in Microsoft Fabric helps admins secure outbound connections from workspace items to external resources. Admins can control outbound access by blocking unwanted connections by default and allowing only approved connections through configured rules.

 

Real-Time Intelligence components in (Preview)Eventstream, Eventhouse, KQL QuerySet, Activator, Fabric, and Azure Events from the Real-Time dashboard and enabled for OAP

While not all end-to-end scenarios are available currently, the teams are working hard to enable them in the upcoming months and are excited to introduce the new capabilities.

 

Now, RTI customers can keep common real-time ingestion, analytics, dashboard, and action workflows running while applying workspace-level outbound controls.

 

This blog post provides an overview of capabilities and supported configurations along with documentation links and resources for further exploration.

 

Key benefits of Outbound Access Protection (OAP)

  • Reduce data exfiltration risk by restricting outbound connections to approved destinations only.
  • Apply granular controls at the workspace level for different teams, projects, and environments.
  • Implement a default-deny security posture with administrator-managed allowlists.
  • Support compliance and governance requirements with stronger control over outbound data movement.

 

What to expect for Real-Time Intelligence items

Eventstream

With Workspace OAP, Eventstream continues to support routing events to Real-Time Intelligence and other Fabric items within the same workspace. Cross-workspace destinations and outbound communication to external services, databases, and APIs are currently blocked. This provides immediate protection against unauthorized outbound data movement while preserving common real-time processing patterns inside a secured Fabric workspace.

 

Supported Eventstream outbound access scenarios

  • Send data to Real-Time Intelligence items in the same workspace.
  • Send data to supported Microsoft Fabric items in the same workspace.

These scenarios use internal Fabric communication and are allowed when outbound access protection is enabled.

 

Blocked Eventstream outbound access

When you enable workspace outbound access protection, the following Eventstream outbound access scenarios are blocked:

  • Sending data to items in other workspaces, including other Real-Time Intelligence items or supported Microsoft Fabric items.
  • Sending data to external resources outside of Microsoft Fabric, such as external databases, APIs, or services.

 

Eventhouse

Eventhouse now supports OAP (Preview), reducing data exfiltration risk by controlling outbound connections at the workspace boundary. When OAP is enabled, Eventhouse connections are limited to supported patterns, and unsupported routes are blocked by design.

 

A key advantage of Eventhouse OAP is that it provides a balanced approach between security and usability. Customers can continue to work with approved Fabric-native data sources and Event Hubs integrations while enforcing stricter controls over outbound communication from protected workspaces.

 

With OAP enabled, Eventhouse continues to support several important data access scenarios:

  • Azure Event Hubs connections remain supported.
  • Eventstream items located in the same workspace remain supported.
  • OneLake access within the same workspace remains supported.
  • Follower databases within the same workspace remain supported.
  • OneLake and Follower Databases in other Fabric workspaces can be accessed when appropriate access rules are configured.

 

At the same time, to strengthen workspace-level protection, several outbound scenarios are currently restricted:

  • Direct access to Eventhouse databases outside supported OneLake shortcut scenarios is blocked.
  • Connections to external resources other than Azure Event Hubs are blocked.
  • Copilot-powered query generation and data analysis scenarios are not supported when OAP is enabled.

These restrictions are intentional and help ensure that outbound access remains tightly governed in protected workspaces.

 

Immediate benefits

By enabling OAP on Eventhouse workloads, organizations can:

  • Reduce the risk of unauthorized outbound data movement.
  • Apply consistent workspace-level security controls across Real-Time Intelligence assets.
  • Continue using core Eventhouse analytics capabilities while maintaining a stronger security posture.
  • Support governance and compliance initiatives that require greater control over outbound connectivity.

 

As you plan your enterprise environment OAP architecture, we recommend validating supported and blocked paths, especially for cross-workspace data access and Copilot-dependent workflows.

 

KQL QuerySet

KQL QuerySet now supports OAP, protecting your data by controlling outbound connections from KQL QuerySet experiences in your workspace to external data sources. When OAP is enabled, KQL QuerySet outbound access follows the workspace policy while preserving the core query experience.

 

Unlike other RTI experiences that rely on outbound communication to external destinations, KQL QuerySet focuses primarily on querying and analyzing data already available within Fabric. As a result, most day-to-day analytics and investigation workflows continue to work unchanged when OAP is enabled. The main restricted scenario is Copilot-assisted KQL query authoring in protected workspaces.

 

When Workspace OAP is enabled:

  • Standard KQL Queryset query authoring remains supported.
  • Interactive data exploration and analysis continue to work.
  • Existing KQL-based investigation workflows remain available.
  • KQL Queryset follows the same workspace-level outbound access policy as other Real-Time Intelligence items

 

Current limitations

The primary limitation in this preview affects Copilot-powered query generation:

  • Copilot for writing KQL queries is not supported when OAP is enabled.

 

Immediate benefits

By enabling OAP for workspaces that contain KQL Querysets, organizations can:

  • Apply workspace-level outbound security controls without disrupting core KQL workflows.
  • Reduce the risk of unauthorized outbound communication from protected workspaces.
  • Maintain a consistent security posture across Real-Time Intelligence assets.
  • Support governance and compliance requirements while preserving analyst productivity.

 

When planning enterprise environment deployments, we recommend reviewing the Copilot limitation in advance so teams know what to expect in protected workspaces.

 

Real-Time Dashboard (RTD)

Real-Time Dashboard (RTD) now supports Workspace OAP allowing organizations to apply workspace-level outbound security controls while continuing to monitor and visualize real-time operational data. For RTD, the model is intentionally simple. For most dashboard users, the experience remains largely unchanged, enabling teams to continue tracking business and operational metrics inside protected workspaces.

 

When OAP is enabled, keep the following RTD behaviors in mind:

  • Standard RTD outbound access scenarios remain supported.
  • Workspace outbound access protection is enforced at the workspace level.
  • All Real-Time Intelligence items in the workspace follow the same outbound access rules.

 

At the same time, workspace OAP blocks specific RTD scenarios, including:

  • Copilot to add or edit tiles in Real-Time Dashboard.
  • Copilot-assisted real-time data exploration.
  • Sharing Real-Time Dashboards by using the dashboard editor's identity.

 

That distinction matters for organizations that want strong outbound controls without changing the day-to-day dashboard experience for most users.

 

In practice, RTD remains broadly available under OAP, while a smaller set of scenarios that depend on Copilot or editor-identity-based sharing are restricted.

 

Activator

Activator now supports Workspace OAP, enabling organizations to apply workspace-level outbound security controls to event-driven actions and automated responses. This allows customers to continue building monitoring and automation scenarios while giving workspace administrators greater control over where Activator-generated actions can be sent.

 

Unlike visualization-focused experiences such as RTD, Activator is designed to act when conditions are met. As a result, OAP primarily affects where Activator is allowed to send notifications, launch workflows, or trigger downstream operations. The goal is to preserve common automation patterns while ensuring outbound communications remain governed by workspace security policies.

 

With OAP enabled, the following applies to Actions and downstream destinations:

Target destinations

Behavior with outbound access protection enabled

Fabric items (notebooks, Spark jobs, pipelines, User Data Functions, Dataflows)

Configurable - Actions that target items in the same workspace are always allowed. Actions that target items in other workspaces are blocked unless the workspace admin explicitly permits them using data connection rules.

Microsoft Teams

Configurable - Teams notifications are restricted to your tenant. The workspace admin can allow or block Teams notifications using the Microsoft Teams connection kind in data connection rules.

Email

Blocked by default - email notifications are restricted to recipients within the same tenant.

Power Automate

Blocked - Power Automate flows triggered from Activator are blocked and can't be configured through data connection rules at this time.

 

Immediate benefits

By enabling OAP for Activator workloads, organizations can:

  • Apply security controls to automated actions and notifications.
  • Reduce the risk of unauthorized outbound communication from automated workflows.
  • Continue using event-driven automation within protected workspaces.
  • Enforce consistent governance policies across monitoring, analytics, and action-oriented Real-Time Intelligence experience

 

 

Looking ahead

Activator OAP support extends Fabric's workspace-level security model to automated actions and workflow orchestration scenarios. As OAP capabilities continue to expand across Microsoft Fabric, customers can expect increasingly consistent governance controls across the entire real-time data lifecycle—from ingestion and analytics through visualization and automated response.

 

Activator continues to support automation scenarios that operate within the same workspace while applying stronger controls to actions that communicate across workspace boundaries or other outbound destinations. This helps organizations balance automation agility with enterprise security and compliance requirements.

 

Secure Azure and Fabric Event Flows across workspaces with OAP

Fabric Events and Azure Events now participate in Workspace OAP scenarios, bringing the same workspace-level security model to event-driven architectures built on Real-Time Intelligence. Administrators can apply outbound access controls at the workspace level while continuing to use event-based workflows to connect producers and consumers across Fabric.

 

 

Immediate benefits

Fabric Events and Azure Events continue to support core event-driven scenarios within the Fabric eventing platform.

  • Event subscriptions continue to participate in workspace-level security enforcement.
  • OAP policies are evaluated as part of subscription validation and permission checks.
  • Event-driven solutions can continue to operate when allowed by the workspace security configuration.

 

Looking ahead

This milestone represents the first stage of OAP integration for the events ecosystem. We are continuing to expand OAP support across Fabric experiences and plan to add support for Power BI reports and maps soon.

 

While some advanced scenarios are still being completed, customers can begin adopting OAP today and move toward a more consistent security and governance posture for event-driven solutions.

 

Resources

For more details on Workspace OAP and supported items, explore the Workspace outbound access protection overview documentation.

 

Share your Feedback

Your feedback is essential! Let us know how we can make Fabric even more secure and flexible for your workloads by sharing your feedback at Fabric Ideas – Microsoft Fabric Community.