Skip to main content
General Validation hosts the application and stores its configuration and result metadata. Your Azure subscription owns validation execution, source access, staging, exact results, and captured failed rows. The environment setup flow shows the exact resources, names, template, and permissions before you deploy. Your Azure administrator deploys that template; General Validation then verifies it and manages its reusable Data Factory content.

Resources in your subscription

The storage account uses hierarchical namespace, HTTPS, TLS 1.2, and Microsoft Entra authentication. Shared-key and anonymous access are disabled. The standard template enables thirty-day soft deletion for blobs and containers. Browser CORS permits the General Validation application origin. The application, API, background services, and application database are operated by General Validation. They are separate from the execution resources billed to your Azure subscription.

Who receives access

General Validation’s Azure roles have no customer-storage data permissions. They do not allow it to read source rows, result artifacts, storage keys, or customer secrets. Exact-value and evidence reads use customer identities. Organization membership and Azure storage access are separate. An Owner grants product access in Organization; a customer Azure administrator controls storage RBAC and the membership of the optional reader group.

Data Factory discovery

By default, the template grants General Validation a read-only metadata role across your subscription so accessible factories appear in the discovery picker. This includes factory definitions and related metadata, with no source-data read permission. You can turn off subscription-wide discovery in the Azure deployment form. Grant metadata Reader access on each selected factory instead. The execution factory is separate from discovery sources and cannot be registered as one. An organization Owner registers a discovery source. Contributors can refresh its catalog and import selected datasets.

ADLS Gen2 source access

When you import a supported storage dataset, preparation uses the customer execution factory to check access and schema. If a qualified probe proves a missing read permission, General Validation can create or reuse a container-scoped Storage Blob Data Reader assignment for that execution factory’s identity. The template’s delegation permits only that reader role for this environment’s execution identity. The preparation workflow further limits the assignment to the verified source container. General Validation itself receives no storage data access. A fresh customer-side probe must verify access before the Dataset becomes ready. Azure RBAC propagation can delay that check. A missing file, blocked network route, or unsupported schema needs its own correction; creating a role assignment does not resolve those problems. Existing customer grants are preserved. Product-created grants remain while imported datasets or active validation work need them and are cleaned up under the environment’s disconnect workflow.

Azure SQL Database

The supported Azure SQL path uses the execution Data Factory’s system-assigned managed identity. A customer SQL administrator creates its Entra database user and grants SELECT on the required tables. Azure subscription or server RBAC does not replace database permissions. Preparation runs a fixed access check against the exact imported table, then reads its schema through customer Data Factory activities. Follow the Dataset’s remediation if it needs a table grant or SQL network access. Automated SQL permission grants are not available in the application.

Microsoft Fabric

Guided Fabric setup requires an organization Owner who is also an Admin or Member of the workspace. The Fabric tenant must allow the required service principals to call its APIs; tenant policy may also require administrator consent for the browser’s Fabric permission. The browser connects the selected workspace and reconciles direct Viewer access for General Validation’s metadata application and the execution factory identity. Existing higher permissions are preserved. The Fabric token stays in the browser. The application identity discovers metadata. Customer Data Factory activities read schema and selected columns through supported Lakehouse and Warehouse SQL endpoints. Fabric capacity and networking must permit that access.

Costs and retention

Microsoft bills execution resources and validation activity to your Azure subscription. The General Validation subscription is separate. Azure costs continue during the free trial and can continue after disconnect while the resources remain. Set a customer-side retention policy for results, captured failed rows, and staging. Staging files do not currently have automatic cleanup or expiry; account for active runs before deleting their folders. Soft delete helps recover deleted objects for its configured window and does not replace your retention plan. See Security and the data boundary and Runs, results, and evidence for how these resources participate in a validation.