Microsoft Fabric Updates Blog

Customer-managed keys for Fabric workspaces (Generally Available) 

Protect your data at rest with keys you own and control 

By default, Fabric encrypts all data at rest using Microsoft-managed keys and secures data in transit with TLS 1.2 or higher. Customer-managed keys (CMK), which you create, own, and maintain in your Azure Key Vault (AKV), offer enhanced control over your encryption strategy. With CMK, you oversee the lifecycle, access, and use of your keys, providing an added layer of security beyond what Microsoft-managed encryption offers. This is especially beneficial for organizations that have strict compliance, governance, or advanced security requirements. You can rotate keys and revoke key access at any time to protect sensitive information within your organization. 

What’s new? 

Customer managed keys were launched in preview, offering workspace administrators the ability to use keys in Azure Key Vault and Managed HSM, to protect data in certain Fabric items. Now, we are extending the encryption support to more Fabric workloads. You can now create Fabric Warehouses, Notebooks and utilize the SQL Analytics Endpoint in workspaces enabled with encryption using your keys. The changes are rolling out and should be available in all regions over the next few days.

We are actively working on bringing you additional functionality including API support, ability to use Key Vaults behind a firewall and support for even more Fabric items. To learn more, refer to the customer-managed keys documentation and Warehouse’s CMK launch blog

Getting started with CMK for your Fabric workspace 

Workspace admins can use the Fabric portal to navigate to workspace settings and set up encryption using customer managed keys. Refer to the encryption documentation for a step-by-step guide. 

Your feedback is essential! Let us know how we can make Fabric even more secure and flexible for your workloads by sharing your feedback at Fabric Ideas – Microsoft Fabric Community    

Related blog posts

Customer-managed keys for Fabric workspaces (Generally Available) 

December 10, 2025 by Ted Vilutis

Schema lakehouses are now Generally Available. By using schemas in lakehouses, users can arrange their tables more efficiently and make it easier to find data. When creating new lakehouses, schema-enabled lakehouses will now be the default choice. However, users still have the option to create lakehouses without a schema if they prefer. What do schema … Continue reading “Lakehouse Schemas (Generally Available)”

December 9, 2025 by Kunal Parekh

Discover how Microsoft Fabric’s Forecasting Service system reduces Spark startup latency and cloud costs through proactive AI and ML-driven resource provisioning. Context & Relevance Waiting minutes for a Spark cluster to become available can throttle analytics velocity, delay insights, and drive-up cloud spend. In a world where data teams expect near‐instant execution and seamless burst … Continue reading “How does Fabric make Spark Notebooks Instant?”