Does the new workspace-level opt-in setting (default change 1 June 2027) supersede the 1 August 2026 trusted-services retirement?

Youness Kabbouch 20 Reputation points
2026-07-06T11:37:43.07+00:00

We previously received communications about the retirement of the "Allow trusted Microsoft services" firewall exception for Azure Synapse Analytics workspaces, with an effective date of 1 August 2026, requiring migration to Managed VNet + managed private endpoints for Storage/Key Vault access.

We've now received a follow-up notification (tracking id: ZQ53-8KZ) describing a new workspace-level setting under Workspace Settings > Security, with the following timeline:

  • The new setting becomes available before 1 March 2027
  • Starting 1 June 2027, the default for new and existing workspaces changes to network-scoped access
  • Administrators can still opt in to keep the current (trusted-services) token behavior if needed

This appears to conflict with, or supersede, the earlier 1 August 2026 deadline. Could you please clarify:

  1. Does this new communication supersede/replace the earlier 1 August 2026 retirement date for the trusted-services firewall exception? In other words, is the effective retirement date now 1 June 2027 (with an opt-in to defer further), rather than 1 August 2026?
  2. If a workspace takes no action, will it continue to function using the current trusted-services/token behavior until at least 1 June 2027, without disruption on 1 August 2026?
  3. Once the setting is available (before 1 March 2027), if we explicitly select "Opt-in enabled," is there any end date for that option, or can it be retained indefinitely subject to the security considerations shown in the portal
  4. Does this change apply uniformly to all workspaces using managed identity + trusted-services firewall exception for Storage/Key Vault access, including workspaces with an active Azure Synapse Link for Dataverse/Dynamics 365 F&O connection?

The communication from Microsoft:

Review upcoming managed identity token behavior changes in Azure Synapse Analytics

You’re receiving this notification because you’re associated with one or more Azure subscriptions that currently use Azure Synapse Analytics workspaces with a managed identity and firewall exception for trusted services.

Following our earlier communications about firewall-protected Azure Storage and Azure Key Vault resources, we’re providing an update that introduces new configuration flexibility for Azure Synapse Analytics workspaces.

What’s changing

A new workspace-level setting will allow administrators to choose how Azure Synapse Analytics workspaces access Azure Storage and Azure Key Vault when firewalls are enabled. This setting gives administrators more control so they can choose the access behavior that best fits their security and architecture requirements.

The new setting will be available before the default behavior changes on 1 March 2027. Starting on 1 June 2027, the default for new and existing workspaces will change to network-scoped access. Administrators will still be able to select the previous behavior if needed, subject to the security considerations presented in the product experience.

About the configuration options

A new setting will be available in Workspace Settings > Security:

Opt-in enabled

When this setting is enabled, workspaces continue using the current token behavior pattern for accessing Azure Storage and Azure Key Vault. When this option is selected, the Azure portal will display information describing the considerations associated with this approach so administrators can review them before making a selection.

Opt-in disabled (default for new and existing workspaces on 1 June 2027)

With this selection, workspaces use a network-scoped access pattern. Access to Azure Storage and Azure Key Vault in this configuration requires a Managed workspace Virtual Network and Managed private endpoints. Microsoft Learn states that managed private endpoints are supported only in workspaces that use a Managed workspace Virtual Network and that they establish private links to Azure resources.

What this means for you

No immediate changes are required for existing workspaces. Existing workspaces continue operating with their current behavior unless administrators choose to adjust the setting when the new workspace level setting is available on 1 March 2027.

Customers who prefer a network-isolated architecture can use the network-scoped configuration if it aligns with their requirements. If you want to use that configuration, review your workspace design and confirm that your Azure Synapse Analytics workspace uses a Managed workspace Virtual Network and Managed private endpoints for Azure Storage and Azure Key Vault.

Azure Synapse Analytics
Azure Synapse Analytics

An Azure analytics service that brings together data integration, enterprise data warehousing, and big data analytics. Previously known as Azure SQL Data Warehouse.


Answer accepted by question author

Manoj Kumar Boyini 19,265 Reputation points Microsoft External Staff Moderator
2026-07-09T10:33:16.86+00:00

Hi @Youness Kabbouch

Based on the latest guidance from the product team, the previously communicated retirement timeline has been updated.

1. Does the new communication supersede the earlier 1 August 2026 retirement?

Yes. The earlier retirement of the "Allow trusted Microsoft services" firewall exception has been postponed. The updated timeline introduces a new workspace-level security setting, with:

The setting becoming available before 1 March 2027.

The default behavior changing to network-scoped access starting 1 June 2027.

Administrators retaining the ability to opt in to the previous token behavior if required, subject to the security considerations presented in the Azure portal.

2.If no action is taken, will existing workspaces continue to function until at least 1 June 2027?

Yes. No immediate action is required for existing workspaces. Existing workspaces will continue operating with their current behavior unless administrators choose to change the new workspace-level setting once it becomes available. The default behavior change will occur on 1 June 2027.

3.Is there an end date for the "Opt-in enabled" option?

At this time, no end date has been announced for the Opt-in enabled option. Customers can continue using the current token behavior by enabling this setting, subject to the security considerations displayed in the product experience. If Microsoft announces any future changes, they will be communicated separately.

4.Does this apply to all workspaces using managed identity and the trusted-services firewall exception, including Azure Synapse Link for Dataverse/Dynamics 365 Finance & Operations?

The updated behavior applies to Azure Synapse Analytics workspaces that use system-assigned managed identity together with the trusted-services firewall exception to access Azure Storage and Azure Key Vault. The new workspace-level setting governs how these workspaces authenticate to firewall-protected Storage and Key Vault resources. If your Synapse Link for Dataverse or Dynamics 365 Finance & Operations environment relies on this access pattern, it should follow the same updated behavior. However, if there are service-specific implementation details for Synapse Link, Microsoft will communicate those separately if needed.

--The previous 1 August 2026 retirement has been postponed.
--No immediate action is required for existing workspaces.
--The new workspace-level setting will be available before 1 March 2027.
--The default changes to network-scoped access on 1 June 2027, while customers can continue using the previous behavior by selecting Opt-in enabled, subject to the security considerations presented in the Azure portal.

Please let us know if you have any questions.

Was this answer helpful?

4 people found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Jerald Felix 17,475 Reputation points Volunteer Moderator
    2026-07-06T13:51:57.55+00:00

    Hello Youness Kabbouch,

    Greetings!

    Thanks for the detailed timeline this is a good question, and I want to be upfront that the specifics of the follow-up notification you received (tracking ID ZQ53-8KZ) aren't something I can independently verify against public documentation, so treat the answer below as guidance rather than a confirmed answer:

    What's publicly documented: The retirement of the "Allow trusted Microsoft services" firewall exception for Azure Synapse workspaces accessing Storage/Key Vault via managed identity is confirmed for 1 August 2026 in Microsoft's public guidance (the Synapse Link transition FAQ). That guidance does not currently reference a workspace-level opt-in setting or a 1 June 2027 date.

    On your specific questions:

    Does the new communication supersede the 1 August 2026 date? This can't be confirmed from public documentation alone. Targeted notifications like the one you received (with a tracking ID) sometimes reflect a refined or staged rollout that hasn't yet been published to the general docs. I'd treat the 1 August 2026 date as still authoritative until you get explicit written confirmation otherwise.

    Will workspaces keep working past 1 August 2026 with no action taken? Based on the public guidance alone, no — the expectation is that trusted-services access stops working after 1 August 2026 unless you've migrated to Managed VNet + managed private endpoints. If your notification genuinely extends that, you'll want written confirmation this applies to your workspace specifically before relying on it.

    Is the opt-in retained indefinitely? No public information exists on this yet, since the setting itself isn't in public documentation.

    Does this apply uniformly, including to Synapse Link for Dataverse/D365 F&O? The general 1 August 2026 retirement does apply to any workspace using managed identity + trusted-services for Storage/Key Vault, which would include Synapse Link–connected workspaces. Whether the newer opt-in setting changes that for your scenario isn't confirmed.

    Recommended next step (highest priority): Since this notification appears to be account/subscription-specific rather than a general product announcement, I'd strongly recommend opening an Azure support ticket referencing tracking ID ZQ53-8KZ directly, and ask them to confirm in writing whether it supersedes the 1 August 2026 date for your workspace(s). You can also check the Message Center in the Azure Portal (Service Health) for the full text of that notification, since forum readers can't see anything beyond what you've quoted.

    In parallel, since the 1 August 2026 deadline is still the only publicly confirmed date, it's worth continuing migration planning to Managed VNet + managed private endpoints so you're not caught out if the newer setting turns out to be scoped more narrowly than it first appears.

    If this helps kindly accept the answer and support the community.

    Best Regards,

    Jerald Felix

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.