complete analytics platform: unified product, architecture, and experience
lake centric and open: common SaaS data lake shared by all compute engines. Onelake, one copy and always synced.
empower every office user: familar experience, built into office.
pervasive security and governance: built in security and governance. end to end visibility. always governed. secure by default.
Purview, OneLake, AI (copilot), Data factory, Analytics (data engineering, data warehouse, data science), Databases, Real-time intelligence, and Power BI.
Private link for Fabric (to connect to the service from a private network).
For on-prem: Express Route/ VPN. For Azure VNet: Peering.
Fabric is disconnected from the public internet.
Every users needs to connect to the private network to get access on every device.
No longer able to load resources locally (slower reports).
Increases ExpressRoute bandwidth and added costs for private links.
Workspace level private link for Fabric
For example: Workspace_1 contains onelake, lakehouse, warehouse, notebook, spark jobs. This is access through private link. Public access is disabled through Entra conditional access policies.
Workspace_2 contains Power BI reports, pipeline, semantic model, KQL database etc. This is access through public link. Public access is enabled through Entra conditional access policies.
Workspace_2 can access workspace_1 through private data access.
Selected workspaces can be connected to a private links and closed from public internet.
Create a secure connection between public and private workspaces using private data access.
Public workspaces are secured through Entra policies for example to use Power BI.
Zero trust approach (to unknown locations)
Verify explicitly (all requests are authenticated and authorized)
Least privilege access (only the minimum permissions are granted to the user)
Assume breach (all requests are treated as untrusted until proven otherwise)
Outbound protection options:
MFA and passwordless authentication (to verify the identity of the user)
Conditional access policies (to restrict access to the service based on the location, device, and user)
Common decisions: Block, Grant, Require MFA.
Based on users and groups, network location, applications, devices.
Identity protection (to detect and respond to suspicious activity in the service)
All data at rest is encrypted by default by Fabric. CMK for OneLake is coming soon in 2025 Q2.
Fabric multi-geo capacities allows control over content storage location in one of 54 data centers world-wide.
OneLake which logically spans the world, workspaces which can reside in different regions around the world while still being part of the same data lake.
Information protection - Once the data is classified, then the data protection labels are applied to all the places. Even if you export the data as excel file, you will see the data label. All the data lineage will contain the data label.
Data loss prevention - automatically identify sensitive data and apply protection policies to prevent data loss. For e.g., credit card numbers, social security numbers, and other sensitive information.
Insider risk management
discover and auto clasify data and prevent it from unauthorized use across apps, services, and devices.
understand the user intent and context around sensitive data to identify the most critical risks.
enable adaptive protection to assign appropriate DLP policies to high-risk users.