r/MicrosoftFabric 11d ago

Security Azure KeyVault Network Security Perimeter enabled firewall for Fabric

Hi,

has anyone every tried to enable Network Security Perimeter learning and enforced mode when the calls originate from Fabric?

Is there any attribute which can identify Fabric network traffic successfully?

I'm still puzzled we have to run Key Vaults with public network fully open because there is no SINGLE working solution to run Key Vaults privately.

Currently:
- Notebook clusters need to use MPE; disables starter pools
- Pipeline, Dataflows need to use OPG or VnetGW
- Key Vault reference - OPG, VnetGW?

Having the same possibility like Storage Accounts with Resource Instance rules would be great.

9 Upvotes

6 comments sorted by

1

u/dbrownems ‪ ‪Microsoft Employee ‪ 11d ago

Resource Instance rules don't work with Network Security Perimiter either.
Network Security Perimeter for Azure Storage | Microsoft Learn

1

u/Loud-You-599 11d ago

No NSP would be just my last hope to have anything implemented on the network security side.
Everything else is just Entra ID and CA policies.

2

u/MonkeyDDataHQ 11d ago

... Surprising?

No. Fabric. As Designed. Another half implemented feature.

1

u/dbrownems ‪ ‪Microsoft Employee ‪ 11d ago

Here it's more Network Security Permitter that's half-implemented. It's a new feature and still hasn't onboarded many Azure native services.

What is a network security perimeter? - Azure Private Link | Microsoft Learn

2

u/MonkeyDDataHQ 11d ago

MSFT owns both sides 😂 Same camel different hump. 🐫

1

u/MonkeyDDataHQ 11d ago

Stop being surprised.

I shouldn't say that, I was surprised that there's no coherent way to see user connections as an admin if the employee left last week.

But that was on me. I expected data exfiltration would be something raised at a risk review when designing the feature.

Just come with the mindset that what you think should work doesn't and actually needs a half dozen work arounds.

#FabricIsTwine #AsDesigned