This time we’re going bigger than ever. Fabric, Power BI, SQL, AI and more. We're covering it all. You won't want to miss it.
Learn moreDid you hear? There's a new SQL AI Developer certification (DP-800). Start preparing now and be one of the first to get certified. Register now
Enterprise analytics platforms increasingly operate under strict security, compliance, and regulatory requirements. For many organizations, encryption is not sufficient without clear ownership and control of cryptographic keys.
Microsoft Fabric supports two complementary key management capabilities:
Now, workspace‑level CMK is supported in all Fabric capacities, including BYOK‑enabled capacities. With this update:
Comparing_previous_and_current_Fabric_encryption_models_showing_workspacelevel_C
Figure: Interoperability between workspace‑level CMK and capacity level-BYOK.
Compliance‑driven organizations: Meet regulatory requirements that mandate customer ownership of encryption keys and granular control over cryptographic boundaries.
Shared capacities with isolated workspaces: Protect sensitive workspaces within shared Fabric capacities, without introducing additional infrastructure.
Defense‑in‑depth strategies: Apply encryption at both the capacity and workspace layers, reducing blast radius and strengthening overall security posture.
By supporting CMK and BYOK together, Fabric enables flexible encryption strategies without increasing operational overhead.
Store keys in Azure Key Vault
Create encryption keys in Azure Key Vault or Azure Key Vault Managed HSM (MHSM).
In the Fabric admin portal:
In the workspace settings:
Organizations gain stronger control over encryption, improved auditability, and the ability to align key management with both operational and regulatory needs—without introducing additional infrastructure or complexity.
Whether you’re securing shared capacities, isolating sensitive workloads, or implementing a defense‑in‑depth strategy, Fabric’s enhanced key management capabilities provide the tools needed to protect analytics data with confidence.
Share your feedback! We’d love to hear from you. Reach out to your Microsoft account team with thoughts, suggestions, or feature requests. You can also leave your feedback in the comment section.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.