Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1070180

Microsoft Fabric: Workspace inbound/outbound access protection will be available by default (preview)

Plan for Change

Message ID

MC1070180
View in Admin Center

Services

Power BI

Summary

Microsoft Fabric will preview Workspace-level private links and Outbound access protection starting late August 2025. Tenant admins can enable these features for workspace admins to secure inbound and outbound network access, reducing unauthorized access and data exfiltration risks. Review and adjust settings post-release.

Details

Updated August 5, 2025: We have updated the timeline below. Thank you for your patience.

Microsoft Fabric will introduce two Preview features called Workspace-level private links and Outbound access protection at the Fabric workspace level. At the tenant level, the corresponding settings Configure workspace level inbound network rules and Configure workspace level outbound network rules will be in the Advanced networking section of the Fabric admin portal.The new tenant-level settings will be disabled by default. You (the tenant admin) can switch ON the tenant toggle in the Fabric admin center if you decide to make this feature available to your workspace admins. This will allow the workspace admins to configure Workspace-level private links and Outbound access protection. The workspace admin will then decide whether to configure these features at the workspace level. 

When this will happen:

Public Preview (Worldwide): We will begin rolling out in late August 2025 (previously late July).

We will communicate the plan for General Availability in a future post.

How this will affect your organization:

Feature 1: Workspace-level private links

  • Private links provide secure inbound connectivity to Microsoft Fabric. Workspace admins can set up private links in Microsoft Azure to connect to a Fabric workspace from a specific virtual network.
  • In Fabric, workspace admins can choose to block inbound public access to your data to significantly reduce the risk of unauthorized access and potential data breaches. During Preview, admins can block inbound public access with the public REST API, which does not require a workspace-level private link set up in Azure. The corresponding-level tenant admin setting Configure workspace level inbound network rules will be available in the Fabric admin portal at Tenant settings > Advanced networking:

admin controls

Feature 2: Outbound access protection at the user workspace level

  • Data exfiltration is a concern for many enterprises that store sensitive data in the cloud. When used with other networking features in Fabric, the Outbound access protection feature can help secure your data from exfiltration. Workspace admins will be able to block all the outbound connectivity from the workspace. Once enabled, all outbound connections made by Fabric Spark artifacts from this workspace will be blocked. The only way to enable a connection is by first establishing a managed private endpoint (MPE) from the workspace to the destination. Workspace admins can control this feature in Workspace settings > Network security > Outbound access protection > Switch on the toggle for Block outbound public access:

admin controls

  • In this Preview, we will support OneLake and these Fabric items: Lakehouse, Notebook, Environment, and Spark Job Definition. We will also support Cross Workspace shortcuts.
  • Admin tenant-level setting for Configure workspace level outbound network rules in the Fabric admin portal at Tenant settings > Advanced networking:

admin controls

What you need to do to prepare:

After we release these features, please review these settings to assess the impact on your organization and adjust them as needed.

If you have questions or need further assistance, please do not hesitate to contact our support team.

Learn more: Microsoft Fabric security - Microsoft Fabric | Microsoft Learn

We will update this post with new documentation.

Timeline

📅
Published
May 8, 2025
Message published to Message Center
✏️
Updated
Aug 5, 2025
Message content updated
🏁
End Date
Oct 27, 2025
Message timeline ends

Tags

#Updated message#New feature#User impact#Admin impact

Category

📋Plan for Change

Related Messages

Similar updates

MC1062450

Microsoft Fabric: Changes to delegation capabilities for Microsoft Azure OpenAI tenant settings

Apr 25, 2025
MC1085131●

Important Notice: TLS Deprecation for Fabric Platform

May 29, 2025
MC1102778●

Microsoft Fabric: Removing default contributor access for Workspace Identity

Jun 25, 2025
MC873746

Microsoft Fabric: New tenant settings for short-lived user-delegated SAS tokens (Preview)

Aug 26, 2024
MC1124567

Power BI Cognitive Services and Azure Machine Learning features retiring; transition to Fabric AI services

Jul 30, 2025