Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Fabric 外部データ共有を試してわかったこと ~テナント間共有の便利さとガバナンスリスク~...

Fabric 外部データ共有を試してわかったこと ~テナント間共有の便利さとガバナンスリスク~(Exploring Microsoft Fabric External Data Sharing: Cross-Tenant Convenience and Governance Risks)

2026/6/10(水) 20:00~21:00 OneLake Deep Dive 勉強会にて発表します!ご参加ください!
▽勉強会URL
https://sqlserver.connpass.com/event/395052/

▽YouTubeリンク
https://youtu.be/a7klO5AcNdM?si=cHtcn8ilytCril5E

【概要】
Microsoft Fabric には、テナントをまたいでデータを共有できる「外部データ共有」機能があります。
通常、Fabric パイプラインでは、テナント A からテナント B へデータを直接書き込むようなクロステナント連携は簡単には実現できません。一方、外部データ共有を利用することで、GUI 操作により、共有元テナントのデータを別テナントのユーザーへ比較的簡単に共有できます。
本資料では、この便利な外部データ共有機能について、単なる設定手順だけではなく、実運用で重要となる観点まで掘り下げます。具体的には、共有者・利用者のアクセス権をどのように考えるべきか、組織としてどこまでリスクを許容するべきか、監査ログにはどのように記録されるのか、そして運用上どのような点に注意すべきかを整理します。
外部データ共有の便利さとガバナンスリスクのバランスを理解し、実際の業務で安全に活用するための判断材料になるでしょう。

【対象読者】
・Fabricが複数テナントに分かれていて、テナント間のデータ共有に悩んでいる
・グローバル企業で海外支社とのデータ連携の方法を検討している
・Snowflakeのデータシェアのような機能がFabricにもあるのか

【目次】
・Fabric 外部データ共有とは
・Demo
・実際に使ってわかったこと
 ・サポートアイテム
 ・アクセス管理
 ・監査運用
・Deep Dive
 ・アクセス権と監査
 ・うまくいかなかったこと

👉関連 Qiita記事:
Microsoft Fabricの別テナント間でデータ共有する3つの方法と注意点-クロステナント,外部データ共有-
 https://qiita.com/ReijiOtake/items/e392cda05ce13c22460c

(English Description)
【Overview】
Microsoft Fabric provides an External Data Sharing feature that enables data to be shared across tenants.
In a typical Fabric pipeline, directly writing data from Tenant A to Tenant B is not easy to implement. By using External Data Sharing, however, data in the provider tenant can be shared with users in another tenant relatively easily through the graphical user interface.
This session explores this useful feature beyond the basic configuration steps, focusing on the considerations that matter in real-world operations. Specifically, it covers how access permissions should be designed for both data providers and consumers, how much risk an organization should be willing to accept, how activities are recorded in audit logs, and what operational precautions should be considered.
The session will help participants understand the balance between the convenience of External Data Sharing and its governance risks, providing practical guidance for using the feature safely in business environments.

【Target Audience】
・Organizations using Microsoft Fabric across multiple tenants and looking for ways to share data between them
・Global companies considering methods for sharing data with overseas subsidiaries or affiliated companies
・People wondering whether Microsoft Fabric provides a feature similar to Snowflake data sharing

【Agenda】
・What is External Data Sharing in Microsoft Fabric?
・Demo
・What I learned from using it
 ・Supported items
 ・Access management
 ・Audit operations
・Deep dive
 ・Access permissions and auditing
 ・What did not work

👉Related Qiita Article:
Three Ways to Share Data Between Different Microsoft Fabric Tenants and Key Considerations: Cross-Tenant Integration and External Data Sharing
 https://qiita.com/ReijiOtake/items/e392cda05ce13c22460c

More Decks by 大竹礼二(REIJI OTAKE)

Transcript

  1. 目次 • Fabric 外部データ共有とは? • Demo • 実際に使ってわかったこと • サポートアイテム

    • アクセス管理 • 監査運用 • Deep Dive • 認証と監査 • うまくいかなかったこと
  2. Demo ①テナント設定 ③メールまたはリンクから承諾 ④指定のレイクハウスに格納 Tenant A Tenant B ①テナント設定 Lakehouse

    A Lakehouse B Table A ②外部データ共有の設定 ⑤共有ステータスの確認 User B Table A (Short cut Table) User A Short cut
  3. 共有後のアクセス管理 コンシューマー側(tenant B)のアクセス制御ポリシーが適用される • 共有元は、コンシューマーのテナント内のデータにアクセスできるユーザーを制御できない • セマンティックモデルの行レベル セキュリティ (RLS)、Microsoft Purview

    情報保護ポリシー、Purview データ損失 防止ポリシーなど、共有元のテナントで定義されているアクセス制御ポリシーは、組織の境界を越えるデータには適用 されない • 一方でコンシューマーのテナントで定義されているポリシーは、そのテナント内のデータに対する方法と同様に、 受信した共有データにも適用される
  4. 有効化粒度がテナントレベル 必ず以下を理解してから使うこと 外部データ共有の有効 / 無効はテナントレベルで制御 制御できること • 外部共有できるユーザーはセキュリティグループレベルで指定 できる •

    外部共有できるユーザーが共有できるデータはそのユーザー がアクセス権をもつデータのみ(そのユーザーが閲覧できない データは共有されない) • 共有リンクは、Fabricポータル上で指定した相手以外はそ のリンクを開くことはできない 制御できないこと • 外部共有できるユーザーが見えるデータの範囲内で、その ユーザー次第でどこにでも配布可能 外部共有ができるユーザーは必ず制御すること!
  5. どのユーザーのアクセス権が使われるのか ①テナント設定 ③メールまたはリンクから承諾 ④指定のレイクハウスに格納 Tenant A Tenant B ①テナント設定 Lakehouse

    A Lakehouse B Table A ②外部データ共有の設定 ⑤共有ステータスの確認 User B-1 Table A (Short cut Table) User A Short cut User B-2 ①Table A(short cut) のアクセス権付与 ②閲覧 ③共有者(ユーザーA)の アクセス権が使われる ②閲覧
  6. 参考 Microsoft Fabric での外部データ共有 - Microsoft Fabric | Microsoft Learn

    Microsoft Fabric のワークスペースのロール - Microsoft Fabric | Microsoft Learn Microsoft Fabricの別テナント間でデータ共有する3つの方法と注意点-クロステナント,外部データ共有- #Azure - Qiita