Microsoft Fabric Updates Blog

Creating a shortcut to a VPC-protected Google Cloud Storage bucket

This guide will cover how to create a OneLake shortcut to a VPC-protected Google Cloud Storage (GCS) bucket.

Why use the on-premises-data gateway?

Today, organizations are protecting data by leveraging network security capabilities like virtual networks, firewalls and virtual protected clouds (VPC). To access data securely and to provide a bridge between protected environments and Microsoft Fabric, an on-premises data gateway can be used.

Although the name might suggest that the on-premises data gateway can only be used to access your data that is on-premises, it can actually be used to access any data that is protected by any type of firewall or virtual network, including the virtual protected clouds on Google Cloud Platform (GCP). For more information about the on-premises data gateway refer to our documentation.

Setting up a gateway is an easy process. You need to provision a Compute Engine virtual machine (VM) instance within your virtual private cloud; and configure (or open) appropriate ports to securely communicate with Microsoft Fabric. In this tutorial, we will walk you through the steps to complete end-to-end setup.

If you are already using the on-premises data gateway within Fabric for other items, like Pipelines, dataflows or Power BI, you can use the same instance of on-premises data gateway, as long as it also has access to your GCS bucket inside the VPC as shown in the diagram below.

At a high-level, the setup process consists of the following steps:

  1. Create a public subnet in your VPC environment and assign security groups to the GCS bucket subnet.
  2. Create a Compute Engine VM instance within the second subnet.
  3. Install the on-premises data gateway on the Compute Engine VM instance.
  4. Open the right ports to Fabric service.
  5. Create a shortcut using the on-premises data gateway.

Prerequisites

Step-by-step set up

1.     Create a public subnet in your VPC environment and assign NSG’s.

  • If you don’t have a public subnet follow this guide to create an internet gateway for a subnet in your VPC.

2.     Create a Compute Engine VM instance within the public subnet.

3. Install the on-premises data gateway on the VM instance

4. Open the right ports to the Fabric service

  • If a firewall blocks outbound connections, configure the firewall to allow outbound connections from the gateway to its associated Azure region. The firewall rules on the gateway need to be updated to allow outbound traffic from the gateway server to the following endpoints.

5. Create a shortcut to GCS

For more information on troubleshooting guidance on the on-premises data gateway, refer to the troubleshooting documentation.

Entradas de blog relacionadas

Creating a shortcut to a VPC-protected Google Cloud Storage bucket

abril 16, 2026 por Tom Peplow

Have you ever tried to understand what’s stored in your Fabric items? Would you even know where to begin? I had 92,000 UK property transactions sitting in an open mirrored database. Rather than spending hours sorting through documentation, I just asked my AI agent: “Document what’s in the House Price Open Mirror in my UK … Continue reading “Give your AI agent the keys to OneLake: OneLake MCP (Generally Available)”

abril 13, 2026 por Harmeet Gill

Adopted by thousands of active users, OneLake File Explorer enables developers, data scientists, and business users to move data from local files into OneLake quickly—without changing how they work. From local files to cloud analytics—without breaking your flow Imagine this scenario: You’re a data engineer working with files on your local machine—CSV extracts, Excel files … Continue reading “Bring your local files to OneLake with OneLake file explorer (Generally Available)”