Firewalled ADLS Gen2 or Blob Storage becomes reachable, via resource instance rules, from workspaces holding a workspace identity, whether through shortcuts, pipelines, COPY INTO, AzCopy or Import semantic models. Only paid F SKUs qualify; trials don't.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Trusted workspace access in context, with comparison tables and the common traps.
Terms in this definition
- ADLS Gen2
Short for Azure Data Lake Storage Gen2: a standard GPv2 account with hierarchical namespace turned on, so analytics workloads get true directories and POSIX-style ACLs.
- Blob storage
Azure's object store for unstructured content like images and video; a single block blob can reach roughly 190.7 TiB.
- Workspace identity
A service principal, with its own app registration, that Fabric manages automatically for a single workspace and that only a workspace Admin can create. Items use it to sign in to resources protected by Microsoft Entra, and trusted workspace access depends on it.
- COPY INTO
Loads files from a volume or cloud storage into a Delta table that already exists, skipping anything loaded before, so reruns are safe. Good for thousands of files; for millions, Auto Loader scales further.
- AzCopy
Microsoft's command-line utility for moving data into, out of and between storage accounts; queue management and copying a running VM are outside what it can do.
- QUALIFY
A SQL clause, available from Databricks Runtime 10.4 LTS, that filters rows by a window function's result with no subquery needed, such as retaining only
ROW_NUMBER() = 1for each key.
Related terms
- DFS endpoint
Data Lake Storage Gen2 address in the form https://<account>.dfs.core.windows.net. Use this one, not the blob address, when creating OneLake shortcuts or setting up trusted workspace access to an ADLS Gen2 account.