Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Workspace inbound access protection is a network security feature that ensures that connections to a workspace are from secure and approved networks. It prevents the items from establishing unsecure connections to sources outside the workspace boundary unless allowed by the workspace admin.
The Configure workspace-level inbound network rules tenant setting in the Fabric admin center allows tenant admins to enable or disable the ability for workspace admins to restrict inbound public access to their workspaces. This setting is disabled by default, meaning workspace admins can't restrict inbound public access to their workspaces. However, if permitted in Azure, workspace admins can still set up workspace-level private links in Azure.
If the tenant admin chooses to enable this setting, workspace admins can configure restricted inbound public access for their workspaces.
Prerequisites
- You must have the Fabric administrator role to enable the workspace inbound access protection feature on your tenant.
Enable workspace inbound access protection on your tenant
Open the admin portal and go to the tenant settings.
Find and expand the Configure workspace-level inbound network rules tenant setting.
Switch the toggle to Enabled.
Select Apply. It could take up to 15 minutes to take effect.
Restrict inbound public access to a workspace
Once the tenant setting is enabled, workspace admins can restrict inbound public access for individual workspaces:
- In the Fabric portal, navigate to your workspace.
- Select Settings from the workspace menu.
- Go to the Network tab.
- Under Inbound access protection, switch the toggle to Restrict public access.
- Review the warning and confirm your selection.
- Select Save to apply the changes.
Note
After restricting public access, only approved private endpoints or networks can connect to the workspace. Public internet access is blocked unless explicitly allowed.