This time we’re going bigger than ever. Fabric, Power BI, SQL, AI and more. We're covering it all. You won't want to miss it.
Learn moreDid you hear? There's a new SQL AI Developer certification (DP-800). Start preparing now and be one of the first to get certified. Register now
We announced Outbound Access Protection for Spark (Generally Available) and recently extended it to support SQL Endpoint and Warehouse. Now, Pipelines, Copy job, Dataflows, OneLake Shortcuts as well as Mirrored Databases (such as Mirrored SQL Database, Mirrored Snowflake) support Workspace level Outbound Access Protection (Preview).
OAP ensures that the external connections made from the Fabric workspace are secured and allowed by the Workspace Admins, thereby reducing the risk of exfiltration.
OAP is now expanded to include the support for the following items:
When OAP is set, workspace admins will be able to configure outbound rules on the workspace (allow/deny) connection types and granular endpoints.
Workspace admins will also get the ability to allow/deny specific VNET/On-Prem Data Gateways. After the gateways are allowed, users in the workspace can incorporate those gateway connections into their workflows.
This will give the right flexibility to ensure the workspace is protected from exfiltration and allow connections to the trusted destinations.
In the following workflow diagram, to allow connection to external data sources or to another workspace, the workspace admins will have to first enable OAP (1), then set up Data connection rules for the workspace. Based on the combination of allowed Data sources (for example SQL Server and VNET Data Gateway), items like Pipeline and Dataflows can establish connections to these sources. All other outbound connections will be blocked.
The_image_shows_the_steps_in_setting_and_using_Outbound_access_protection_for_Da
To learn more about Workspace OAP for Data Factory, set-up, scope and limitations, refer to the Workspace outbound access protection overview documentation.
In addition to Data Factory improvements, the momentum continues with updates to OneLake. External shortcuts are now supported with outbound access protection! You can use the new data source connection rules to allow list specific outbound data sources. After allowlisting, you can read existing shortcuts and create new ones only to those allowlisted locations, ensuring your data stays secure without limiting your data estate. For example, you can create a data connection rule allowing outbound connections to your ADLS Gen2 account while blocking outbound requests to other external locations, including any other ADLS Gen2 accounts!
You can also use data connection rules to allow cross-workspace OneLake connections through the Lakehouse connector. By adding a connection rule for a different workspace in the Lakehouse connector, all copy operations and shortcuts from your OAP-enabled workspace to the allowed-listed workspace are allowed. This gives you an alternative way to allow cross- workspace connections without the use of managed private endpoints and a private link service.
Interested in learning more about OneLake and outbound access protection? Check out managing outbound access from OneLake with outbound access protection for more information!
Tenant level Admin APIs for Workspace OAP settings are rolling out and will be available next week (Live Now).
We are actively working to expand OAP support for additional experiences and plan to add support for Power BI Semantic Models and Reports soon.
Your feedback is essential! Let us know how we can make Fabric even more secure and flexible for your workloads by sharing your feedback at Fabric Ideas – Microsoft Fabric Community.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.