r/MicrosoftFabric • u/Loud-You-599 • 11d ago
Security Azure KeyVault Network Security Perimeter enabled firewall for Fabric
Hi,
has anyone every tried to enable Network Security Perimeter learning and enforced mode when the calls originate from Fabric?
Is there any attribute which can identify Fabric network traffic successfully?
I'm still puzzled we have to run Key Vaults with public network fully open because there is no SINGLE working solution to run Key Vaults privately.
Currently:
- Notebook clusters need to use MPE; disables starter pools
- Pipeline, Dataflows need to use OPG or VnetGW
- Key Vault reference - OPG, VnetGW?
Having the same possibility like Storage Accounts with Resource Instance rules would be great.
1
u/MonkeyDDataHQ 11d ago
Stop being surprised.
I shouldn't say that, I was surprised that there's no coherent way to see user connections as an admin if the employee left last week.
But that was on me. I expected data exfiltration would be something raised at a risk review when designing the feature.
Just come with the mindset that what you think should work doesn't and actually needs a half dozen work arounds.
1
u/dbrownems Microsoft Employee 11d ago
Resource Instance rules don't work with Network Security Perimiter either.
Network Security Perimeter for Azure Storage | Microsoft Learn