Azure Cosmos DB mirroring in Microsoft Fabric now offers a simpler way to connect accounts secured by private endpoints or virtual networks. A virtual network data gateway provisioned inside your own virtual network keeps public network access disabled throughout setup and ongoing replication.This release builds on the general availability of private network support announced earlier this year, and it reflects the feedback we received from enterprise and regulated customers about reducing the configuration effort required to bring secured operational data into OneLake.A simpler path for secured accounts The most significant improvement in this release is that Fabric service tag IP ranges are no longer part of the configuration. Previously, establishing mirroring required adding the DataFactory and Power Query Online IPv4 ranges for your region to the Azure Cosmos DB IP firewall, then restoring the original network configuration once replication was running. With a virtual network data gateway, connectivity is established entirely through your own network.Several practical benefits follow from that change: The account remains in its locked down state. Public network access stays disabled throughout configuration and replication, which keeps the mirroring setup aligned with existing network security baselines and change control processes. Onboarding is a one time exercise. Creating additional mirrored databases on the same account, and making container configuration changes, no longer depend on firewall state. Connectivity is scoped to your own network. The permitted resource is your subnet or private endpoint rather than a Microsoft service tag range, so there are no external IP ranges to track or maintain.How it worksFabric needs two kinds of access to mirror a private network account, and both now stay inside your network boundary.Control plane access, used for metadata reads during setup, comes from a trusted workspace network ACL bypass. You enable the EnableFabricNetworkAclBypass capability on the account and authorize a specific Fabric workspace as a trusted resource.Data plane access, used for replication itself, runs through the virtual network data gateway. Fabric provisions it into a dedicated, delegated subnet in your virtual network, where it resolves the account through private DNS and reaches it over your existing private endpoint.The approach works with either private connectivity model:Azure Cosmos DB configurationPublic network accessHow the gateway subnet is permittedPrivate endpointDisabledThe subnet resolves the account to its private endpoint through private DNS.Virtual network service endpointsSelected networksEnable the Microsoft.AzureCosmosDB service endpoint on the gateway subnet, then add it as a virtual network rule.Limitations Mirrored databases are created with the Fabric REST API. A gateway connection uses Virtual network connectivity, while the New mirrored Azure Cosmos DB experience currently lists Cloud connections only, so the gateway connection does not appear in the portal picker. Support for virtual network connections in the mirroring interface is on our roadmap. Existing mirrored databases need to be re-created. Because the mirroring interface cannot bind an existing item to a virtual network connection, adopting this model means creating a new mirrored database. OAuth authentication only. Account keys are not supported for private network mirroring. The gateway needs its own subnet. Plan for a dedicated /27 or larger subnet delegated to Microsoft.PowerPlatform/vnetaccesslinks, with outbound access to Microsoft Entra ID for sign in.Get startedConfiguration takes eight steps, and the how-to guide covers each one with Azure CLI and Azure PowerShell commands. Register the Microsoft.PowerPlatform resource provider on your subscription. Create the delegated gateway subnet in your virtual network. Grant the Azure Cosmos DB data plane permissions that mirroring needs. Add the EnableFabricNetworkAclBypass capability to the account. Authorize your Fabric workspace as a trusted resource. Create the virtual network data gateway in Fabric. Create an Azure Cosmos DB v2 connection over that gateway. Create the mirrored database with the Fabric REST API and start replication.Open the mirrored database and review Monitor replication. Once the status reads Running and the rows replicated count begins to climb, you have confirmation that Fabric is reaching your account privately while public network access remains disabled.Try it todayCustomers running Azure Cosmos DB under network isolation requirements can now bring that operational data into OneLake without adjusting their network security posture. We welcome your feedback on how this configuration maps to your environment.If you are attending FabCon Europe in Barcelona, visit the Ask the Experts booth in the expo hall. Our engineers and product team are onsite and would welcome the opportunity to discuss your network security requirements.⚙️ Configure Private Networks for Azure Cosmos DB Fabric mirroring📘 Azure Cosmos DB mirroring in Microsoft Fabric💻 Mirrored database REST API referenceAbout Azure Cosmos DBAzure Cosmos DB is a fully managed and serverless NoSQL and vector database for modern app development, including AI applications. With its SLA-backed speed and availability as well as instant dynamic scalability, it is ideal for real-time NoSQL and MongoDB applications that require high performance and distributed computing over massive volumes of NoSQL and vector data.To stay in the loop on Azure Cosmos DB updates, follow us on X, YouTube, and LinkedIn. Join the discussion with other developers on the #nosql channel on the Microsoft Open Source Discord.