Azure Synapse

The Azure Synapse connector is a Palantir-provided driver for Azure Synapse.

To create a new Azure Synapse source, follow the standard setup flow for Palantir-provided drivers, then use the sections below for Azure Synapse-specific configuration and networking. For the complete property reference, see the official Azure Synapse driver documentation ↗.

Supported capabilities

CapabilityStatus
Exploration🟢 Generally available
Batch syncs🟢 Generally available
Incremental🟢 Generally available
OAuth 2.0 authentication🟢 Generally available
Table exports🟢 Generally available

Configuration

The properties below are mandatory or recommended.

PropertyRequired?DescriptionDefault
AuthSchemeMandatoryThe scheme used for authentication. Accepted entries are Password, AzureAD, AzureServicePrincipal, AzureServicePrincipalCert, AzureMSI, AzurePassword.Password
DatabaseMandatoryThe name of the Synapse database.
EncryptMandatoryThis field sets whether SSL is enabled and whether the 'Strict' encryption type is used.TRUE
ServerMandatoryThe name of the server running Synapse.{serverAddress}
InitiateOAuthRecommendedSpecifies the process for obtaining or refreshing the OAuth access token, which maintains user access while an authenticated, authorized user is working.REFRESH
OAuthClientIdRecommendedSpecifies the client ID (also known as the consumer key) assigned to your custom OAuth application. This ID is required to identify the application to the OAuth authorization server during authentication.
OAuthClientSecretRecommendedSpecifies the client secret assigned to your custom OAuth application. This confidential value is used to authenticate the application to the OAuth authorization server.
PasswordRecommendedSpecifies the password of the authenticating user account.
PortRecommendedThe port of the Synapse.1433
UserRecommendedSpecifies the user ID of the authenticating Azure Synapse user account.

Networking

The table below lists the domains that the source must be able to access to run.

For each domain, add a corresponding egress policy. If the source is hosted on-premises and not directly reachable from Foundry, use an agent proxy egress policy instead. The agent host itself must also be able to reach the listed domains. See using an agent as a proxy for details.

DomainRequired
<Server>:<Port>Always. Server and Port connection properties
<StorageAccountLocation>Used for staging data in COPY mode
login.microsoftonline.comIf AuthScheme=AzureAD, AzureServicePrincipal, AzureServicePrincipalCert, AzurePassword AND AzureEnvironment=GLOBAL (default)
login.chinacloudapi.cnIf AuthScheme=AzureAD, AzureServicePrincipal, AzureServicePrincipalCert, AzurePassword AND AzureEnvironment=CHINA
login.microsoftonline.usIf AuthScheme=AzureAD, AzureServicePrincipal, AzureServicePrincipalCert, AzurePassword AND AzureEnvironment=USGOVT or USGOVTDOD

OAuth 2.0 authentication

This connector supports OAuth 2.0 authentication. Follow the OAuth 2.0 guidance for Palantir-provided drivers to configure and authorize the connection.

Table exports

This connector supports table exports. Learn how to set up a table export.