A global logistics company uses Azure Synapse Analytics for real-time analytics on supply chain data. To comply with data residency rules and minimize latency, they need to ensure that all network traffic between their Azure Synapse workspace and its associated storage accounts (Azure Data Lake Storage Gen2) remains entirely within the Microsoft Azure backbone network, without traversing the public internet. Which networking configuration should be implemented?
- AUtilize Service Endpoints for Azure Storage
- BForce TLS for Azure Synapse Analytics
- CEnable Azure Synapse Workspace Managed Virtual Network and Private Endpoints
- DConfigure Storage Account Firewalls with VNet rules
Show answer & explanationAnswer & explanation
Correct answer: C. Enable Azure Synapse Workspace Managed Virtual Network and Private Endpoints
Enabling Azure Synapse Workspace Managed Virtual Network and creating Private Endpoints for the associated Data Lake Storage Gen2 accounts ensures that all traffic between the Synapse workspace and storage travels over the Azure backbone, meeting the requirements for private, secure, and low-latency connectivity without public internet exposure.
Why the other options are wrong
- A. Service Endpoints provide direct connectivity from a VNet to Azure services over the Azure backbone but expose the service to the entire VNet, and don't provide the same level of isolation and granular control as private endpoints within a managed VNet.
- B. Force TLS ensures encrypted communication but doesn't guarantee that traffic remains on the private Azure backbone; it can still traverse the public internet while encrypted.
- D. Storage Account Firewalls with VNet rules allow traffic from specific VNets but don't inherently ensure that the Synapse workspace itself is part of a private network or that its internal traffic to storage remains private.
Synapse Managed VNet & Private Endpoints
A networking configuration for Azure Synapse Analytics where the workspace is injected into a managed virtual network, and Private Endpoints are used to privately connect to associated Azure services (like ADLS Gen2) over the Azure backbone.
- Ensures all traffic to linked services stays on the Azure backbone.
- Eliminates public internet exposure for data movement.
- Enhances security, data residency, and reduces latency.
- Managed VNet simplifies network configuration for the workspace.
Memory trick: Managed VNet + Private Endpoints: Your Synapse's exclusive, high-speed, private data highway.