Microsoft Purview
Azure-native data governance and catalog (formerly Azure Purview)
Access mode: Read-only
Required information
| Field | Details |
|---|---|
| Purview account name | Account URL: https://<account>.purview.azure.com. |
| Collection(s) | Purview collections to access. |
| Azure AD app registration | Service principal with Purview API permissions. |
| Roles | Read-only: Purview Data Reader role on target collections. |
Network considerations
Fully managed Azure service. HTTPS to <account>.purview.azure.com.
Private Endpoints: If Purview uses private endpoints, Flume needs network access to the private endpoint.
Managed VNet: If Purview uses managed VNet for scanning, doesn’t affect API access.
Credential and auth management
Preferred: Azure AD service principal. Same pattern as other Azure services. Client credentials with Purview Data Reader role assignment.
Token: Standard Azure AD OAuth2 token. Flume handles refresh.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Authentication | GET https://<account>.purview.azure.com/catalog/api/atlas/v2/types/typedefs?api-version=2022-03-01-preview | Returns type definitions |
| Search | POST .../catalog/api/search/query with keyword query | Returns catalog assets |
| Lineage | GET .../catalog/api/atlas/v2/lineage/<guid> | Returns lineage graph |
| Collection access | GET .../account/collections | Lists accessible collections |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.