Governance & Security
Patterns for OneLake security, workspace identity, and audit logging that pass an enterprise compliance review.
Governance in Fabric is layered: tenant settings, workspace roles, item permissions, and — newest and most powerful — OneLake security for row/column/table-level control that every engine honors.
Pages
OneLake security
RLS, CLS, and table-level roles enforced across Spark, SQL, and Direct Lake.
Workspace identity
Trusted access to storage without stored secrets or a service principal.
Audit logs
Where Fabric activity lands, retention, and pulling it for SIEM / compliance.
The layers, top to bottom
| Layer | Controls | Set by |
|---|---|---|
| Tenant settings | Who can use SPNs, create capacities, share externally | Fabric admin |
| Capacity | Which workspaces run where; surge protection | Capacity admin |
| Workspace roles | Admin / Member / Contributor / Viewer | Workspace admin |
| Item permissions | Per-report / per-model sharing | Item owner |
| OneLake security | Row / column / table access on lakehouse data | Data owner |
Design top-down but review bottom-up: an auditor asks "who can read this table", and the answer is the intersection of every layer. Document the whole chain for your regulated datasets.
Stay ahead of Fabric changes
Fabric runtime changes, API updates, and deprecations. No spam, unsubscribe anytime.