Loading...

Azure Purview Managed Vnet, Vnet Integration Runtime and Managed Private Endpoints

Azure Purview Managed Vnet, Vnet Integration Runtime and Managed Private Endpoints

We are glad to announce support for Azure Purview managed Vnet, Vnet Integration Runtime and managed private endpoint connections today, in public preview! This set of capabilities provides you with a more secure and manageable data scanning solution within Purview. You can now provision the Azure Integration Runtime in a Managed Virtual Network and leverage Private Endpoints to securely connect to supported Azure data sources. Your metadata traffic as a result of scans, between the data source and the Azure Purview Managed Virtual Network during ingestion into the catalog, goes through Azure Private Link which provides secured connectivity and eliminates your metadata exposure to the internet. With the Purview Managed Virtual Network and Managed Private Endpoints, you can also offload the burden of managing the virtual network to Azure Purview, and protect against metadata exfiltration.

 

Azure Purview Managed Virtual Network terminology and steps

 

Managed Virtual Network

 

The Managed Virtual Network is associated with the Azure Purview instance and is managed by Azure Purview. You can choose to have the Azure Integration Runtime created within the Managed Virtual Network. The Managed Virtual Network gets created automatically when you create your first Managed Vnet Integration Runtime as described below.

 

purview-managed-vnet-architecture.png

 

Managed Virtual Network Integration Runtime

 

You need to first create an Azure Integration Runtime within the managed Virtual Network, which ensures that data scanning process is completely isolated and secure, while also being fully managed.

 

You can do so by navigating to the Integration runtimes section in the Purview DataMap, and going through the creation flow as shown below.

 

IRcrud.png

 

 

You must then fill in the details to complete your set up.

 

 

IRdetails.png

 

 

 

Creating and deploying the Managed VNet Integration Runtime for the first time triggers multiple workflows in the Purview Studio for creating managed private endpoints to Azure Purview and its Managed Storage Account. You must click on each workflow to approve the private endpoint for the corresponding Azure resource from the Azure portal. If you don't have the right permissions to approve these requests, then you will have to have the resource owner approve the connection request before proceeding forward.

 

purview-managed-ir-workflows.png

 

 

Managed Private Endpoints

 

Managed Private Endpoints are private endpoints created in the Azure Purview Managed Virtual Network establishing a private link to Azure resources. Azure Purview manages these private endpoints on your behalf. The Private endpoint uses a private IP address in the managed virtual network to effectively bring the service into it. Private endpoints are mapped to a specific resource in Azure and not the entire service. You can limit connectivity to a specific resource approved by your organization using this mechanism.

 

After you create an Azure integration runtime inside your managed Vnet, you must next create a managed Private endpoint connection to your Azure data source. You can do so by navigating to the Purview management center, and then to the Managed private endpoint connections as shown below.

 

managedPECreation.png

 

Private endpoint connections are currently support for the following data source types:

- Azure Blob Storage
- Azure Data Lake Storage Gen 2
- Azure SQL Database
- Azure Cosmos DB
- Azure Synapse Analytics
- Azure Files
- Azure Database for MySQL
- Azure Database for PostgreSQL

 

A private endpoint connection to a data source is created in "Pending" state. An approval workflow is initiated and the data source owner is responsible to approve or reject the connection in the Azure portal.

 

purview-managed-data-source-pe-azure.png

 

Setting up a scan using a managed Vnet Integration Runtime

 

Once you've set up the Managed Vnet IR and the managed private endpoint to the data source, you must set up a scan on the data source, which you have already registered to Purview. While setting up your scan, pick the managed Vnet IR as the connection option and ensure that interactive authoring is enabled. If not, you can do so inline with a click of a button. You must also ensure that the managed private endpoint connection to the data source is in 'Approved' state as shown below.

 

ManagedVnetScan.png

 

Get started today!

  • Quickly and easily create an Azure Preview account to try the generally available features.
  • Read full documentation about how to use Purview Managed Vnet, Vnet IR and Managed Private Endpoints.

Published on:

Learn more
Azure Purview Blog articles
Azure Purview Blog articles

Azure Purview Blog articles

Share post:

Related posts

Azure SDK Release (October 2025)

Azure SDK releases every month. In this post, you'll find this month's highlights and release notes. The post Azure SDK Release (October 2025)...

15 hours ago

Microsoft Copilot (Microsoft 365): [Copilot Extensibility] No-Code Publishing for Azure AI Foundry Agents to Microsoft 365 Copilot Agent Store

Developers can now publish Azure AI Foundry Agents directly to the Microsoft 365 Copilot Agent Store with a simplified, no-code experience. Pr...

23 hours ago

Azure Marketplace and AppSource: A Unified AI Apps and Agents Marketplace

The Microsoft AI Apps and Agents Marketplace is set to transform how businesses discover, purchase, and deploy AI-powered solutions. This new ...

3 days ago

Episode 413 – Simplifying Azure Files with a new file share-centric management model

Welcome to Episode 413 of the Microsoft Cloud IT Pro Podcast. Microsoft has introduced a new file share-centric management model for Azure Fil...

4 days ago

Bringing Context to Copilot: Azure Cosmos DB Best Practices, Right in Your VS Code Workspace

Developers love GitHub Copilot for its instant, intelligent code suggestions. But what if those suggestions could also reflect your specific d...

5 days ago

Build an AI Agentic RAG search application with React, SQL Azure and Azure Static Web Apps

Introduction Leveraging OpenAI for semantic searches on structured databases like Azure SQL enhances search accuracy and context-awareness, pr...

5 days ago

Announcing latest Azure Cosmos DB Python SDK: Powering the Future of AI with OpenAI

We’re thrilled to announce the stable release of Azure Cosmos DB Python SDK version 4.14.0! This release brings together months of innov...

7 days ago

How Azure CLI handles your tokens and what you might be ignoring

Running az login feels like magic. A browser pops up, you pick an account, and from then on, everything just works. No more passwords, no more...

8 days ago

Boost your Azure Cosmos DB Efficiency with Azure Advisor Insights

Azure Cosmos DB is Microsoft’s globally distributed, multi-model database service, trusted for mission-critical workloads that demand high ava...

10 days ago
Stay up to date with latest Microsoft Dynamics 365 and Power Platform news!
* Yes, I agree to the privacy policy