Azure's managed data services are reached two ways: by the service's own keys or connection strings (Cosmos DB keys, storage account keys), or by a principal whose Azure RBAC and database identity let it connect. The analytics services are different: Data Factory and Synapse run pipelines as their own managed identity, so compromising one is a path to that identity's token, not just to the data.
Pages#
- SQL Database: Entra and SQL authentication, firewall reach, and the server managed identity.
- Cosmos DB: primary and read-only keys, resource tokens, and RBAC document access.
- Data Factory: pipelines and linked services that run as the factory managed identity.
- Synapse Analytics: SQL and Spark pools, pipelines, and the workspace managed identity.
- Storage Tables: Table storage read through account keys or SAS.