This time we’re going bigger than ever. Fabric, Power BI, SQL, AI and more. We're covering it all. You won't want to miss it.
Learn moreDid you hear? There's a new SQL AI Developer certification (DP-800). Start preparing now and be one of the first to get certified. Register now
Hi everyone,
I'm using Azure Data Factory (ADF) with a Managed Virtual Network (VNet) and the Azure Integration Runtime (IR) to connect to Amazon S3. I want to ensure that my data transfer does not traverse the public internet for security reasons.
Could someone please confirm:
Thank you for your assistance!
Solved! Go to Solution.
enabling Managed VNet alone does not guarantee that traffic to external services like Amazon S3 stays off the public internet.
Quoted from MS doc :
"By default, ADF transfers data from Amazon S3 to Azure Blob Storage or Azure Data Lake Storage Gen2 using encrypted connection over HTTPS protocol. HTTPS provides data encryption in transit and prevents eavesdropping and man-in-the-middle attacks.
Alternatively, if you don't want data to be transferred over public Internet, you can achieve higher security by transferring data over a private peering link between AWS Direct Connect and Azure Express Route. Refer to the solution architecture in the next section on how this can be achieved."
A great articles covering all aspects of your question:
https://learn.microsoft.com/en-us/azure/data-factory/data-migration-guidance-s3-azure-storage
If this helps please accept the solution.
Thanks
Thank-you for reply @nilendraFabric
That's the article I was looking for and never found it.
enabling Managed VNet alone does not guarantee that traffic to external services like Amazon S3 stays off the public internet.
Quoted from MS doc :
"By default, ADF transfers data from Amazon S3 to Azure Blob Storage or Azure Data Lake Storage Gen2 using encrypted connection over HTTPS protocol. HTTPS provides data encryption in transit and prevents eavesdropping and man-in-the-middle attacks.
Alternatively, if you don't want data to be transferred over public Internet, you can achieve higher security by transferring data over a private peering link between AWS Direct Connect and Azure Express Route. Refer to the solution architecture in the next section on how this can be achieved."
A great articles covering all aspects of your question:
https://learn.microsoft.com/en-us/azure/data-factory/data-migration-guidance-s3-azure-storage
If this helps please accept the solution.
Thanks
Check out the April 2026 Fabric update to learn about new features.
Sign up to receive a private message when registration opens and key events begin.
| User | Count |
|---|---|
| 4 | |
| 4 | |
| 2 | |
| 1 | |
| 1 |
| User | Count |
|---|---|
| 8 | |
| 6 | |
| 3 | |
| 3 | |
| 2 |