Remove secrets from Azure data pipelines: a user-assigned managed identity with least-privilege roles in Bicep, Entra-only SQL access, Key Vault for what's left, Databricks storage credentials, and audit logging.
Enterprise practices for Azure Data Lake Storage Gen2: account topology, redundancy, directory layout, file sizing, RBAC versus ACLs, private endpoints, HNS feature support and lifecycle tiering.