Microsoft purview

Prasant Chettri 146 Reputation points
2024-12-06T05:08:11.88+00:00

Upgrading to the enterprise version of Microsoft Purview in M365 allows access to all governance applications and capabilities, including support for various data sources. However, it does not specifically mention the use of private endpoints or integration runtimes like the self-hosted integration runtime or managed virtual network integration runtime, which are essential for scanning on-premises data sources or ensuring network isolation.

On the other hand, deploying a self-hosted integration runtime in Azure Purview is specifically designed to scan on-premises data sources and requires a setup within a private network for resource on the cloud.

Can I avoid deploying SHIR or Azure managed IR for implementing purview data security for Azure DB resources, if I just upgrade the M365 purview to the enterprise version? If so, is there way to deploy it in private network?

Microsoft Purview
Microsoft Purview
A Microsoft data governance service that helps manage and govern on-premises, multicloud, and software-as-a-service data. Previously known as Azure Purview.
1,467 questions
0 comments No comments
{count} votes

Accepted answer
  1. Smaran Thoomu 21,610 Reputation points Microsoft External Staff
    2024-12-06T11:29:58.17+00:00

    Hi @Prasant Chettri
    Welcome to Microsoft Q&A platform.
    Thank you for the detailed question! You’ve raised an important point about integrating Microsoft Purview with Azure DB resources and the role of integration runtimes.

    Upgrading to the enterprise version of Microsoft Purview in M365 does indeed unlock a wide range of governance applications and capabilities. However, for specific tasks like scanning on-premises data sources or ensuring secure connectivity to Azure DB resources, integration runtimes (either self-hosted or Azure-managed) play a critical role.

    If your primary use case is securing Azure DB resources without deploying a self-hosted integration runtime (SHIR) or Azure-managed IR, you can leverage the native capabilities of Microsoft Purview within Azure. For example:

    1. Azure Purview natively supports scanning Azure resources through its built-in connectors, which don't necessarily require SHIR or managed IR for Azure-native data sources.
    2. For enhanced security and network isolation, you can integrate Microsoft Purview with a managed virtual network (VNet) in Azure. This enables you to securely scan and manage Azure resources without exposing them to the public internet.

    If you're considering deploying Purview entirely within a private network, the managed virtual network integration is your go-to solution. This allows Purview to operate in a secure, private environment while still accessing and securing your Azure DB resources.

    For more information refer the below articles:

    Hope this helps. Do let us know if you any further queries.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.