Authentication, Managed Identity and Integration Runtime

Understand the authentication and connectivity choices that allow Microsoft Purview to reach and scan technical data sources securely.

Every Microsoft Purview scan depends on two things: a supported way to authenticate to the source and a network path that allows Purview to reach it.

Authentication

Supported methods vary by connector and can include managed identity, service principal, credentials stored in Azure Key Vault or source-specific tokens.

Managed identity

Where supported, managed identity can reduce credential-management overhead because the Purview identity itself is granted the source permissions needed for scanning.

Integration runtime

The integration runtime provides the connectivity path used by the scan. The correct option depends on the source location, network restrictions and connector capabilities.

Operational checks

  • Use the least-privileged supported authentication method.
  • Grant only the permissions required for the intended scan.
  • Confirm firewall, private-network and routing requirements.
  • Document dependencies on source administrators or platform teams.
  • Review Microsoft’s connector-specific prerequisites before implementation.

Learning with Data SkyLab Studio

Follow practical Microsoft Purview and Data Governance learning from Data SkyLab Studio on YouTube.