Fabric Implementation Guide · Part 4 of 10

Networking & Managed Private Endpoints

Design private networking topologies using Managed VNets, Inbound/Outbound Private Links, On-Premises Data Gateways, and strict egress firewalls.

Target Audience: Cloud Network Engineers, Infrastructure Leads, and SecOps
Estimated Read Time: 10 min

01VNet Injection & Private Endpoint Topology

Protect Fabric compute engines and storage against public internet exposure. Configure Managed Private Endpoints from Fabric workspaces to backend Azure SQL, ADLS Gen2, and Snowflake resources. Enable Azure Private Link for inbound client connections to Fabric tenant workspaces.

Implementation & Verification Checklist

  • Document complete network data paths from source on-prem databases to OneLake
  • Provision Managed Private Endpoints for secure outbound connections from Fabric Spark & Data Factory
  • Configure Azure Private Link for inbound corporate network traffic to Fabric portal
  • Verify private DNS zone resolution across hybrid network boundaries

02On-Premises Data Gateway High Availability

When ingesting data from on-premises SQL Server, Oracle, or SAP sources, deploy On-Premises Data Gateway clusters in High-Availability (HA) load-balanced configurations. Monitor gateway CPU, memory, outbound TCP port connectivity, and failover behavior under peak ETL batch windows.

Implementation & Verification Checklist

  • Cluster minimum 2 gateway nodes for active-active load balancing and redundancy
  • Validate outbound TCP port 443 connectivity to Fabric service endpoints
  • Perform automated failover testing by taking primary gateway node offline during ingestion
  • Monitor gateway network throughput and queue latency in Azure Monitor