Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

The FabCon + SQLCon recap series starts April 14th at 8am Pacific. If you’re tracking where AI is going inside Fabric, this first session is a can't miss. Register now

Reply

How is data stored at rest and in transit Between Dataverse and Fabric (DV Direct Fabric Link)

Dears,

 

I am creating a Technical Design Document (TDA)

 

I have a Dataverse Fabric Direct Link my Raw Fabric Workspace:

 

fabricpribeiro_0-1772132034564.png

 

Can you please help undertand the best language to describe this from a security perspective?

 

1 - I have a workspace identity which has contributor permissions in my workspace

2 - This is then mappend to a Dataverse App user which has admin previleges in DV

3 - For the above two points, I am clear

3 - But I don't know how to descrive the rest , meaning,

 

4 - When data is flowing (in transit) is it encrypted betwen dataveerse and fabric? and if so, using which proptocol ?

5 - How can I describe the data at Rest , when it lands into the lakehouse  in Raw? is it encrypted by Fabric using the azure encryption?

 

Can you please help clarify this two points?

 

Thanks a lot,

 

Pedro

 

 

 

1 ACCEPTED SOLUTION
deborshi_nag
Resident Rockstar
Resident Rockstar

Hello @fabricpribeiro 

 

4) Data in transit  

Both Dataverse and Fabric being SaaS services in Microsoft, Service‑to‑service communication occurs over Microsoft‑managed Azure backbone networking and is not exposed to the public internet.

All data transferred between Microsoft Dataverse and Microsoft Fabric is encrypted in transit using TLS 1.2 or higher. Dataverse is using the latest TLS 1.3 and TLS 1.2 cipher suites as approved by the Microsoft Crypto Board. 
 
So in summary:
  • Dataverse runs on Azure
  • Fabric runs on Azure
  • Service-to-service traffic:
    • Uses HTTPS
    • Uses TLS 1.2+
    • Uses Microsoft’s internal network where possible
  • You do not manage certificates yourself

On your diagram, in the arrow between Dataverse and Fabric you can indicate this by using this text -

All service-to-service data flows over Microsoft backbone and encrypted using industry‑standard TLS 1.2+ protocols.
 
5) Data at rest
When data is created in Fabric in Tables/, it is stored in OneLake. OneLake is backed by Azure Data Lake Storage Gen2 - encryption is On by default. Data is persisted in OneLake and encrypted at rest using Azure Storage Service Encryption (SSE), using Microsoft‑managed keys and AES‑256 encryption. This is Azure's built-in encryption standard. 

On you Fabric side of your diagram you can indicate this using this text - 
Data stored in Fabric OneLake is encrypted at rest using Azure Storage Service Encryption with Microsoft‑managed keys.
 
I trust this will be helpful. If you found this guidance useful, you are welcome to acknowledge with a Kudos or by marking it as a Solution.

View solution in original post

3 REPLIES 3
v-pnaroju-msft
Community Support
Community Support

Hi fabricpribeiro,

We are pleased to note that your issue has been resolved. Should you have any further queries, please feel free to contact the Microsoft Fabric community.

Thank you.

deborshi_nag
Resident Rockstar
Resident Rockstar

Hello @fabricpribeiro 

 

4) Data in transit  

Both Dataverse and Fabric being SaaS services in Microsoft, Service‑to‑service communication occurs over Microsoft‑managed Azure backbone networking and is not exposed to the public internet.

All data transferred between Microsoft Dataverse and Microsoft Fabric is encrypted in transit using TLS 1.2 or higher. Dataverse is using the latest TLS 1.3 and TLS 1.2 cipher suites as approved by the Microsoft Crypto Board. 
 
So in summary:
  • Dataverse runs on Azure
  • Fabric runs on Azure
  • Service-to-service traffic:
    • Uses HTTPS
    • Uses TLS 1.2+
    • Uses Microsoft’s internal network where possible
  • You do not manage certificates yourself

On your diagram, in the arrow between Dataverse and Fabric you can indicate this by using this text -

All service-to-service data flows over Microsoft backbone and encrypted using industry‑standard TLS 1.2+ protocols.
 
5) Data at rest
When data is created in Fabric in Tables/, it is stored in OneLake. OneLake is backed by Azure Data Lake Storage Gen2 - encryption is On by default. Data is persisted in OneLake and encrypted at rest using Azure Storage Service Encryption (SSE), using Microsoft‑managed keys and AES‑256 encryption. This is Azure's built-in encryption standard. 

On you Fabric side of your diagram you can indicate this using this text - 
Data stored in Fabric OneLake is encrypted at rest using Azure Storage Service Encryption with Microsoft‑managed keys.
 
I trust this will be helpful. If you found this guidance useful, you are welcome to acknowledge with a Kudos or by marking it as a Solution.

This reply was perfect. Thank you very much, I have two similar questions, for other sources but I will put them in a separated thread 

 

Thank you very very much

Helpful resources

Announcements
FabCon and SQLCon Highlights Carousel

FabCon &SQLCon Highlights

Experience the highlights from FabCon & SQLCon, available live and on-demand starting April 14th.

New to Fabric survey Carousel

New to Fabric Survey

If you have recently started exploring Fabric, we'd love to hear how it's going. Your feedback can help with product improvements.

Join our Fabric User Panel

Join our Fabric User Panel

Share feedback directly with Fabric product managers, participate in targeted research studies and influence the Fabric roadmap.

March Fabric Update Carousel

Fabric Monthly Update - March 2026

Check out the March 2026 Fabric update to learn about new features.