Get certified for free when you join Fabric Data Days 2026 and dive into Fabric, Power BI, SQL, AI, and other essential data skills.
Join now60 Days of Data Days! Live and on-demand sessions, challenges, study groups and more! And it's all FREE!. Join now. Learn more
Coauthors: Gabi Lehner, Brian Stephens, George Guirguis, Alex Lin, Gali Reznick, and Bodhisatva Gautam
Workspace Outbound Access Protection (OAP) in Microsoft Fabric helps admins secure outbound connections from workspace items to external resources. Admins can control outbound access by blocking unwanted connections by default and allowing only approved connections through configured rules.
While not all end-to-end scenarios are available currently, the teams are working hard to enable them in the upcoming months and are excited to introduce the new capabilities.
Now, RTI customers can keep common real-time ingestion, analytics, dashboard, and action workflows running while applying workspace-level outbound controls.
This blog post provides an overview of capabilities and supported configurations along with documentation links and resources for further exploration.
With Workspace OAP, Eventstream continues to support routing events to Real-Time Intelligence and other Fabric items within the same workspace. Cross-workspace destinations and outbound communication to external services, databases, and APIs are currently blocked. This provides immediate protection against unauthorized outbound data movement while preserving common real-time processing patterns inside a secured Fabric workspace.
These scenarios use internal Fabric communication and are allowed when outbound access protection is enabled.
When you enable workspace outbound access protection, the following Eventstream outbound access scenarios are blocked:
Eventhouse now supports OAP (Preview), reducing data exfiltration risk by controlling outbound connections at the workspace boundary. When OAP is enabled, Eventhouse connections are limited to supported patterns, and unsupported routes are blocked by design.
A key advantage of Eventhouse OAP is that it provides a balanced approach between security and usability. Customers can continue to work with approved Fabric-native data sources and Event Hubs integrations while enforcing stricter controls over outbound communication from protected workspaces.
With OAP enabled, Eventhouse continues to support several important data access scenarios:
At the same time, to strengthen workspace-level protection, several outbound scenarios are currently restricted:
These restrictions are intentional and help ensure that outbound access remains tightly governed in protected workspaces.
By enabling OAP on Eventhouse workloads, organizations can:
As you plan your enterprise environment OAP architecture, we recommend validating supported and blocked paths, especially for cross-workspace data access and Copilot-dependent workflows.
KQL QuerySet now supports OAP, protecting your data by controlling outbound connections from KQL QuerySet experiences in your workspace to external data sources. When OAP is enabled, KQL QuerySet outbound access follows the workspace policy while preserving the core query experience.
Unlike other RTI experiences that rely on outbound communication to external destinations, KQL QuerySet focuses primarily on querying and analyzing data already available within Fabric. As a result, most day-to-day analytics and investigation workflows continue to work unchanged when OAP is enabled. The main restricted scenario is Copilot-assisted KQL query authoring in protected workspaces.
When Workspace OAP is enabled:
The primary limitation in this preview affects Copilot-powered query generation:
By enabling OAP for workspaces that contain KQL Querysets, organizations can:
When planning enterprise environment deployments, we recommend reviewing the Copilot limitation in advance so teams know what to expect in protected workspaces.
Real-Time Dashboard (RTD) now supports Workspace OAP allowing organizations to apply workspace-level outbound security controls while continuing to monitor and visualize real-time operational data. For RTD, the model is intentionally simple. For most dashboard users, the experience remains largely unchanged, enabling teams to continue tracking business and operational metrics inside protected workspaces.
When OAP is enabled, keep the following RTD behaviors in mind:
At the same time, workspace OAP blocks specific RTD scenarios, including:
That distinction matters for organizations that want strong outbound controls without changing the day-to-day dashboard experience for most users.
In practice, RTD remains broadly available under OAP, while a smaller set of scenarios that depend on Copilot or editor-identity-based sharing are restricted.
Activator now supports Workspace OAP, enabling organizations to apply workspace-level outbound security controls to event-driven actions and automated responses. This allows customers to continue building monitoring and automation scenarios while giving workspace administrators greater control over where Activator-generated actions can be sent.
Unlike visualization-focused experiences such as RTD, Activator is designed to act when conditions are met. As a result, OAP primarily affects where Activator is allowed to send notifications, launch workflows, or trigger downstream operations. The goal is to preserve common automation patterns while ensuring outbound communications remain governed by workspace security policies.
With OAP enabled, the following applies to Actions and downstream destinations:
Target destinations | Behavior with outbound access protection enabled |
Fabric items (notebooks, Spark jobs, pipelines, User Data Functions, Dataflows) | Configurable - Actions that target items in the same workspace are always allowed. Actions that target items in other workspaces are blocked unless the workspace admin explicitly permits them using data connection rules. |
Microsoft Teams | Configurable - Teams notifications are restricted to your tenant. The workspace admin can allow or block Teams notifications using the Microsoft Teams connection kind in data connection rules. |
Blocked by default - email notifications are restricted to recipients within the same tenant. | |
Power Automate | Blocked - Power Automate flows triggered from Activator are blocked and can't be configured through data connection rules at this time. |
By enabling OAP for Activator workloads, organizations can:
Activator OAP support extends Fabric's workspace-level security model to automated actions and workflow orchestration scenarios. As OAP capabilities continue to expand across Microsoft Fabric, customers can expect increasingly consistent governance controls across the entire real-time data lifecycle—from ingestion and analytics through visualization and automated response.
Activator continues to support automation scenarios that operate within the same workspace while applying stronger controls to actions that communicate across workspace boundaries or other outbound destinations. This helps organizations balance automation agility with enterprise security and compliance requirements.
Fabric Events and Azure Events now participate in Workspace OAP scenarios, bringing the same workspace-level security model to event-driven architectures built on Real-Time Intelligence. Administrators can apply outbound access controls at the workspace level while continuing to use event-based workflows to connect producers and consumers across Fabric.
Fabric Events and Azure Events continue to support core event-driven scenarios within the Fabric eventing platform.
This milestone represents the first stage of OAP integration for the events ecosystem. We are continuing to expand OAP support across Fabric experiences and plan to add support for Power BI reports and maps soon.
While some advanced scenarios are still being completed, customers can begin adopting OAP today and move toward a more consistent security and governance posture for event-driven solutions.
For more details on Workspace OAP and supported items, explore the Workspace outbound access protection overview documentation.
Your feedback is essential! Let us know how we can make Fabric even more secure and flexible for your workloads by sharing your feedback at Fabric Ideas – Microsoft Fabric Community.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.