|
| 1 | +--- |
| 2 | +title: Azure Purview Self-service access concepts |
| 3 | +description: Understand what self-service access and data discovery are in Azure Purview, and explore how users can take advantage of it. |
| 4 | +author: bjspeaks |
| 5 | +ms.author: blessonj |
| 6 | +ms.service: purview |
| 7 | +ms.subservice: purview-data-policies |
| 8 | +ms.topic: conceptual |
| 9 | +ms.date: 03/10/2022 |
| 10 | +--- |
| 11 | + |
| 12 | +# Azure Purview Self-service data discovery and access (Preview) |
| 13 | + |
| 14 | +This article helps you understand Azure Purview Self-service data access policy. |
| 15 | + |
| 16 | +> [!IMPORTANT] |
| 17 | +> Azure Purview Self-service data access policy is currently in PREVIEW. The [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability. |
| 18 | +
|
| 19 | +## Important limitations |
| 20 | + |
| 21 | +The self-service data access policy is only supported when the prerequisites mentioned in [data use governance](./how-to-enable-data-use-governance.md) are satisfied. |
| 22 | + |
| 23 | +## Overview |
| 24 | + |
| 25 | +Azure Purview Self-service data access workflow allows data consumer to request access to data when browsing or searching for data. Once the data access request is approved, a policy gets auto-generated to grant access to the requestor provided the data source is enabled for data use governance. Currently, self-service data access policy is supported for storage accounts, containers, folders, and files. |
| 26 | + |
| 27 | +A **workflow admin** will need to map a self-service data access workflow to a collection. Collection is logical grouping of data sources that are registered within Azure Purview. **Only data source(s) that are registered** for data use governance will have self-service policies auto-generated. |
| 28 | + |
| 29 | +## Terminology |
| 30 | + |
| 31 | +* **Data consumer** is anyone who uses the data. Example, a data analyst accessing marketing data for customer segmentation. Data consumer and data requestor will be used interchangeably within this document. |
| 32 | + |
| 33 | +* **Collection** is logical grouping of data sources that are registered within Azure Purview. |
| 34 | + |
| 35 | +* **Self-service data access workflow** is the workflow that is initiated when a data consumer requests access to data. |
| 36 | + |
| 37 | +* **Approver** is either security group or AAD users that can approve self-service access requests. |
| 38 | + |
| 39 | +## How to use Azure Purview self-service data access policy |
| 40 | + |
| 41 | +Azure Purview allows organizations to catalog metadata about all registered data assets. It allows data consumers to search for or browse to the required data asset. |
| 42 | + |
| 43 | +With self-service data access workflow, data consumers can not only find data assets but also request access to the data assets. When the data consumer requests access to a data asset, the associated self-service data access workflow is triggered. |
| 44 | + |
| 45 | +A default self-service data access workflow template is provided with every Azure Purview account.The default template can be amended to add more approvers and/or set the approver's email address. For more details refer [Create and enable self-service data access workflow](./how-to-workflow-self-service-data-access-hybrid.md). |
| 46 | + |
| 47 | +Whenever a data consumer requests access to a dataset, the notification is sent to the workflow approver(s). The approver(s) can view the request and approve it either from Azure purview portal or from within the email notification. When the request is approved, a policy is auto-generated and applied against the respective, data source. self-service data access Policy gets auto-generated only if the data source is registered for **data use governance**. The pre-requisites mentioned within the [data use governance](./how-to-enable-data-use-governance.md) have to be satisfied. |
| 48 | + |
| 49 | +## Next steps |
| 50 | + |
| 51 | +If you would like to preview these features in your environment, follow the link below. |
| 52 | +- [Enable data use governance](./how-to-enable-data-use-governance.md) |
| 53 | +- [create self-service data access workflow](./how-to-workflow-self-service-data-access-hybrid.md) |
| 54 | +- [working with policies at file level](https://techcommunity.microsoft.com/t5/azure-purview-blog/data-policy-features-accessing-data-when-file-level-permission/ba-p/3102166) |
| 55 | +- [working with policies at folder level](https://techcommunity.microsoft.com/t5/azure-purview-blog/data-policy-features-accessing-data-when-folder-level-permission/ba-p/3109583) |
0 commit comments