Microsoft Purview Managed VNet IR - Scanning Microsoft Fabric and SQL Server Using Managed Private Endpoints

Junaidul Haq (BEYONDSOFT CONSULTING INC) 0 Reputation points Microsoft External Staff
2026-07-23T21:43:13.52+00:00

Hi Team,

We have configured a Microsoft Purview account and created a Managed** Virtual Network Integration Runtime (Managed VNet **IR) in the Purview Governance Portal. Also, we are able to scan the storage account with the help of managed private endpoint.

Our next requirement is to scan the following data sources:

  1. Microsoft Fabric
  2. SQL Server

However, while reviewing the Microsoft Learn documentation below: Managed virtual networks and private endpoints in Microsoft Purview. We found that only the following services are explicitly listed under "Supported** systems with managed private ****endpoint"**:

  • Azure Blob Storage
  • Azure Cosmos DB
  • Azure Data Lake Storage Gen2
  • Azure Database for MySQL
  • Azure Database for PostgreSQL
  • Azure Databricks
  • Azure Dedicated SQL Pool
  • Azure Files
  • Azure Key Vault
  • Azure SQL Database
  • Azure SQL Managed Instance
  • Azure Synapse Analytics
  • Snowflake

The article does not clearly explain:

  1. Whether Microsoft Fabric can be scanned through a Managed Private Endpoint from Purview Managed VNet.
  2. Whether SQL Server (Azure VM-hosted SQL Server or on-premises SQL Server) supports connectivity through a Managed Private Endpoint.
  3. If Managed Private Endpoints are not supported for these sources, what is the recommended connectivity method when using Managed VNet IR.
  4. Any Microsoft documentation that explains private connectivity architecture for Microsoft Fabric scanning from Purview.

Could Microsoft confirm the supported architecture and recommended approach for these scenarios?

Thank you


Moderator: Moved from SQL Server | Other

Microsoft Security | Microsoft Purview

1 answer

Sort by: Most helpful
  1. Pilladi Padma Sai Manisha 11,700 Reputation points Microsoft External Staff Moderator
    2026-07-23T23:29:38.63+00:00

    Hi @Junaidul Haq (BEYONDSOFT CONSULTING INC)
    Thank you for reaching microsoft Q&A!.

    Based on the current Microsoft Learn documentation, Managed Private Endpoints (MPEs) in Microsoft Purview are supported only for the data sources explicitly listed in the documentation (such as Azure Blob Storage, Azure Data Lake Storage Gen2, Azure SQL Database, Azure SQL Managed Instance, Azure Synapse Analytics, Azure Databricks, Snowflake, etc.).

    For your scenarios:

    • Microsoft Fabric: Microsoft Fabric is not currently listed as a supported data source for Managed Private Endpoints. Based on the public documentation, we cannot confirm that Fabric scanning is supported through Purview Managed VNet Integration Runtime (Managed VNet IR) using a Managed Private Endpoint. Additionally, there is no Microsoft Learn article at this time that describes a private connectivity architecture specifically for Fabric scanning through Purview.
    • SQL Server:
      • For on-premises SQL Server, Microsoft recommends using a Self-hosted Integration Runtime (SHIR) for scanning. This is the documented approach for on-premises data sources.
        • For SQL Server running on an Azure Virtual Machine, the current documentation does not explicitly describe support for connectivity through a Purview Managed Private Endpoint. As a result, we cannot confirm this scenario based on the published guidance alone.

    If your requirement is to scan a source that is not documented as supporting Managed Private Endpoints, the best next step is to verify the supported architecture for your specific scenario with Microsoft Support, as there may be product updates that are not yet reflected in the public documentation.

    To help narrow this down, could you please clarify:

    1. Which Microsoft Fabric asset type are you trying to scan (Lakehouse, Warehouse, SQL Database, or another Fabric resource)?
    2. Is your SQL Server on-premises or hosted on an Azure Virtual Machine?
    3. Are you using only Managed VNet IR, or do you also have a Self-hosted Integration Runtime available?

    References:

    I hope this helps clarify the currently documented support. If you can provide the additional details above, we'd be happy to help determine the most appropriate connectivity approach for your environment.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.