A firewall rule on an Azure Storage account that trusts one particular Fabric workspace, identified by its workspace identity. You can't add it in the portal, only through ARM or PowerShell, and the resource ID must use 00000000-0000-0000-0000-000000000000 as the subscription.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Resource instance rule in context, with comparison tables and the common traps.
Terms in this definition
- Azure Storage
You reach this Azure data storage platform through a storage account; it covers blobs (Data Lake Storage included), file shares, queues and tables.
- Workspace
Teams in Power BI and Microsoft Fabric collaborate in this folder-style container, which groups items such as reports, semantic models and lakehouses, controls who can access them and is assigned a capacity.
- Workspace identity
A service principal, with its own app registration, that Fabric manages automatically for a single workspace and that only a workspace Admin can create. Items use it to sign in to resources protected by Microsoft Entra, and trusted workspace access depends on it.
- Architecture Definition Document
A key deliverable bringing together the main architecture artifacts across the four domains for every relevant state: baseline, transition and target. It sets out, in qualitative terms, what the architect intends.
- ARM
Short for Azure Resource Manager, the control plane Azure uses for deploying and managing resources.
- Resource ID
The unique path that identifies an Azure resource, shaped like /subscriptions/.../resourceGroups/.../providers/.... Moving the resource to a different resource group or subscription gives it a new ID.
- subscription
Entitlement bought for a product under VCF 9.0 licensing, carrying a set capacity. Where active ones share the same site, unit and product, their capacity is combined into licences, which are then allocated to vCenters.