Private endpoints that a managed virtual network, such as the one in Data Factory or Synapse, creates towards a target resource. They only work after the target's owner approves them.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Managed private endpoints in context, with comparison tables and the common traps.
Terms in this definition
- Managed virtual network
VNet that Azure manages for a service, for example a Synapse workspace, isolating its compute and keeping traffic on the Microsoft backbone. You can only pick it when creating the service.
- Azure Data Factory
Managed data integration service for ETL and ELT, built from pipelines, copy activities, triggers, mapping data flows and integration runtimes. It works in batches rather than routing individual transactions.
- Full control
Gives every right over protected content, EXTRACT included, plus the ability to alter or strip the encryption. Owners and the Rights Management issuer always hold it.
Related terms
- Foundry managed virtual network
Virtual network run by Microsoft that isolates outbound traffic from Foundry Agent Service and connects to Storage, Cosmos DB and AI Search over managed private endpoints. Once switched on, it cannot be turned off.
- Synapse workspace
Azure Synapse Analytics workspace that brings together pipelines, Spark pools and SQL pools. When it uses a managed VNet, data stores can be reached only via managed private endpoints.
- Workspace outbound access protection
Available only for workspaces on F SKU capacities, this setting cuts off every outbound connection made by items in the workspace. Exceptions are allowed through data connection rules (for mirroring, Data Factory and Real-Time Intelligence) or managed private endpoints (for OneLake and Data Engineering).