Governance & Security

Patterns for OneLake security, workspace identity, and audit logging that pass an enterprise compliance review.

Governance in Fabric is layered: tenant settings, workspace roles, item permissions, and — newest and most powerful — OneLake security for row/column/table-level control that every engine honors.

Pages

The layers, top to bottom

LayerControlsSet by
Tenant settingsWho can use SPNs, create capacities, share externallyFabric admin
CapacityWhich workspaces run where; surge protectionCapacity admin
Workspace rolesAdmin / Member / Contributor / ViewerWorkspace admin
Item permissionsPer-report / per-model sharingItem owner
OneLake securityRow / column / table access on lakehouse dataData owner

Design top-down but review bottom-up: an auditor asks "who can read this table", and the answer is the intersection of every layer. Document the whole chain for your regulated datasets.

Stay ahead of Fabric changes

Fabric runtime changes, API updates, and deprecations. No spam, unsubscribe anytime.

On this page