A global logistics company uses Azure Synapse Analytics for real-time analytics on supply chain data. They require that all data processing within the Synapse Workspace occurs in a highly secure, isolated network environment that does not expose any data to the public internet. Furthermore, all outbound connections from the Synapse Spark and SQL pools must be routed through a private endpoint to other Azure services. Which network configuration should be implemented?
- AConfigure the Synapse Workspace to use an Azure-managed virtual network with public endpoints.
- BDeploy the Synapse Workspace with a Managed Virtual Network and enable Managed Private Endpoints.
- CIntegrate the Synapse Workspace with an existing customer-managed VNet and configure UDRs.
- DUtilize Synapse IP firewall rules to restrict inbound access to authorized IP ranges only.
Show answer & explanationAnswer & explanation
Correct answer: B. Deploy the Synapse Workspace with a Managed Virtual Network and enable Managed Private Endpoints.
Deploying the Synapse Workspace with a Managed Virtual Network ensures that all compute resources (Spark pools, SQL pools) are isolated within a private, Azure-managed VNet. Enabling Managed Private Endpoints within this Managed VNet guarantees that all outbound connections to other Azure services are established privately, without traversing the public internet, meeting the isolation and private outbound requirements.
Why the other options are wrong
- A. Public endpoints do not meet the requirement for isolation and no public internet exposure.
- C. Integrating with a customer-managed VNet is an option, but the 'Managed Virtual Network' feature of Synapse provides a more streamlined, integrated solution for isolation and private endpoints within the Synapse ecosystem, which is implied by 'highly secure, isolated network environment'. While possible with UDRs, 'Managed Private Endpoints' are the direct solution for outbound private connectivity within a Synapse Managed VNet.
- D. IP firewall rules only restrict inbound public access; they do not provide private network isolation for compute resources or private outbound connectivity.
Synapse Managed VNet & Private Endpoints
Azure Synapse Analytics feature that provisions a dedicated, Azure-managed virtual network for the workspace's compute resources and enables Managed Private Endpoints for secure, private outbound connectivity to other Azure services.
- Provides network isolation for Synapse Spark and SQL pools.
- All compute traffic stays within the Azure network.
- Managed Private Endpoints ensure private outbound access to data sources/sinks.
- Simplifies network configuration compared to customer-managed VNets for Synapse.
Memory trick: Keep your Synapse data flowing privately, both in and out, within its own secure network.