Skip to main content
Solved

Open Ports for Ingest Instance (and Prepare instance) for Fabric lakehouse

  • July 23, 2026
  • 5 replies
  • 53 views

Hello. This document has the ports which need to be opened. Configure your Firewall | Community It doesn't reference Fabric Lakehouse.. are you able to advise what we need to open for the ingest service to communicate to Fabric Lakehouse?

Thanks

 

Tim

Best answer by Christian Hauggaard

@Tim Turner  Closing the loop on this one. The "Authentication Failed" error when creating Lakehouse storage was a Fabric permissions issue, not a firewall one. Once the Fabric admin had completed the prerequisites in the Fabric Lakehouse Ingest instance storage guide, the Lakehouse could be created from TDI. So for ports, Rory's answer above stands: without private link, traffic to Fabric goes over *.fabric.microsoft.com on TCP 443.

5 replies

rory.smith
TimeXtender Xpert
Forum|alt.badge.img+8
  • TimeXtender Xpert
  • July 24, 2026

Hi,

it depends on your Fabric setup: if you are using private link at the tenant or workspace level, traffic inbound to Fabric may be closed off if your Ingest service lives in a network that cannot reach those private links.

Otherwise traffic to fabric runs over *.fabric.microsoft.com on port 443 using TCP


Christian Hauggaard
Community Manager
Forum|alt.badge.img+5

@Tim Turner 

were you able to connect to fabric lakehouse in ingest and prepare?


  • Author
  • Explorer
  • August 17, 2026

HI ​@Christian Hauggaard , we are currently getting an error when trying to create the lakehouse storage from within the TDI app, and are getting and authentication failed error. So, I assume it is an issue with permissions rather than the firewall. (I have a ticket open on this # 41178)

Thanks 


Christian Hauggaard
Community Manager
Forum|alt.badge.img+5

@Tim Turner  Closing the loop on this one. The "Authentication Failed" error when creating Lakehouse storage was a Fabric permissions issue, not a firewall one. Once the Fabric admin had completed the prerequisites in the Fabric Lakehouse Ingest instance storage guide, the Lakehouse could be created from TDI. So for ports, Rory's answer above stands: without private link, traffic to Fabric goes over *.fabric.microsoft.com on TCP 443.


  • Author
  • Explorer
  • September 8, 2026

Great thanks. The client is going to setup a private link for this.