This time we’re going bigger than ever. Fabric, Power BI, SQL, AI and more. We're covering it all. You won't want to miss it.
Learn moreDid you hear? There's a new SQL AI Developer certification (DP-800). Start preparing now and be one of the first to get certified. Register now
Security is non-negotiable when it comes to real-time data streaming. In regulated industries such as banking, healthcare, and telecommunications, organizations must ensure that every data connection is encrypted and mutually authenticated. But many enterprises rely on internal Certificate Authorities (CAs) or require mutual TLS (mTLS) to meet their security policies, which means that the standard, publicly trusted certificates that come pre-installed with most platforms simply aren’t enough.
Microsoft Fabric Eventstream, part of Real-Time Intelligence (RTI), provides nearly 20 streaming connectors that ingest real-time data from popular sources such as Apache Kafka, Amazon Managed Streaming for Apache Kafka, and Confluent Cloud for Apache Kafka. Until now, these connectors only supported TLS encryption using system-predefined CA certificates from a trusted CA list. If your source systems used certificates signed by a custom CA—or if your infrastructure required mTLS for two-way authentication—you couldn’t use Eventstream to connect.
We heard this loud and clear from customers across industries, and today we’re announcing Custom CA and mTLS support for Kafka-based sources in Eventstream, now available in preview for Kafka-based sources, including Apache Kafka, Amazon Managed Streaming for Apache Kafka, and Confluent Cloud for Apache Kafka, as well as Confluent Schema Registry.
This approach offers significant advantages over traditional file-based certificate management. Azure Key Vault serves as a centralized, secure store for all your certificates. Multiple data engineers across your organization can reference the same certificates without needing individual file handoffs. When it’s time to rotate or update a certificate, you update it once in Key Vault—Eventstream connectors that reference it will automatically pick up the new version.
The_architecture_diagram_for_the_Eventstream_connector_custom_CA_and_mTLS_suppor
Figure 1 Architecture custom CA and mTLS in Eventstream.
Animation_to_show_the_end_to_end_flow_to_configure_the_custom_CA_or_mTLS_support
Figure: Custom CA and mTLS configuration end to end flow.
For detailed guide, please refer to the specific eventstream source configuration documentations in Add and Manage Eventstream Sources, such as Apache Kafka source, Confluent Cloud for Apache Kafka, and Amazon Managed Streaming for Apache Kafka.
We welcome your feedback through the community forum, idea submission, or via email.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.