Skip to main content

Most Power BI governance is already free. Access control, endorsement, domains, lineage, tenant settings, audit logging, and capacity telemetry are Microsoft-native and included. EPC Group's position: harden the native rings first, and buy a third-party tool only for the four jobs the platform does not do.

Key Facts

  • Fabric activity logs retain 30 days; the Capacity Metrics app shows 14. Anything longer requires export. That pair of numbers decides whether you need a tool or a pipeline.
  • Only users a Fabric administrator names can certify items. Promotion is open to anyone with write permission; certification is not, and enablement can now be delegated to domain administrators. The trust signals are Promoted (open) and Certified and Master data (named reviewers).
  • Sensitivity labels come from Microsoft Purview Information Protection and require an Azure Information Protection P1 or P2 license, plus Power BI Pro or PPU to apply a label.
  • DLP for Fabric and Power BI requires M365 E5, E5 Compliance, E5 Information Protection & Governance, or Purview capacities for the admin creating policies, and evaluation consumes Fabric capacity.
  • Publish to web produces reports that require no authentication. Reviewing its embed codes is the highest-value hour in a Power BI security audit.
  • Power BI Pro lists at $14.00 per user per month and PPU at $24.00, paid yearly, as published at time of writing (July 2026).
  • Governance is configured in four control rings — tenant → capacity → domain → workspace/item — in the Fabric admin portal and the Microsoft Purview portal.
  • Access roles are Admin, Member, Contributor and Viewer — nested, each inheriting those below.
  • Enforcement layers: Purview labels with inheritance, protection policies, DLP, and Defender for Cloud Apps.
  • The highest-risk defaults are publish to web, guest access and external data sharing.
  • What no tool fixes is ownership: every workspace needs a named human owner.

Last updated by Errin O'Connor, Founder & Chief AI Architect, EPC Group

EPC Group is a Houston-based Microsoft consulting firm operating since 1997, with six Microsoft Solutions Partner designations and 216+ M&A tenant migrations covering 1.83M users.

Governance readiness for AI is scored in the Tenant AI Readiness Standard, surface 5.

Why governance-tool vendors cannot answer this question

The page currently ranking fifth on this query is published by Rencore, which sells a Microsoft 365 and Power BI governance product. It is a competent post. It also cannot tell you that oversharing prevention, sprawl control, license monitoring, and access review — the four capabilities it presents — all have Microsoft-native surfaces most enterprises already own and have never configured. That is a structural limit, not bad faith. Syskit, AvePoint, and Quest content on adjacent queries has the same constraint.

Microsoft Learn has the opposite limit. Its Fabric adoption roadmap for governance holds position one and is the correct authority on the conceptual model, the roles table, and the maturity levels. It cannot tell you what governance costs, what to set each switch to in a regulated environment, when a third-party tool is worth buying, or what breaks. This article covers those four things and defers to Learn on the rest.

The Four-Ring Power BI Governance Model

Fabric delegates control downward through four rings. Every governance decision belongs to exactly one ring, and most governance failures are a decision made in the wrong one.

RingControl surfaceWho administersDecisions that belong hereFailure signature when it is skipped
R1 — TenantAdmin portal tenant settingsFabric administratorPublish to web, guest access, external sharing, label enablement, Copilot enablement, who may create workspacesExternal exposure. Nobody ever turned the controls off
R2 — CapacityCapacity settings, delegated tenant settingsCapacity administratorSKU sizing, surge protection thresholds, overage limits, per-capacity CopilotCost and performance incidents misread as product problems
R3 — DomainDomains, subdomains, delegated settingsDomain admin, domain contributorDefault sensitivity label, domain-scoped certification reviewers, workspace assignmentCentral IT becomes the bottleneck for every business-unit decision
R4 — Workspace / itemWorkspace roles, item permissions, endorsement, labelsWorkspace admin, item owner, certification reviewerWho can edit, who can build, what is certified, what is labeledSix versions of revenue. Sprawl is an R4 failure people try to solve in R1

The rule: push each control to the lowest ring that can be held accountable for it. Tenant-wide switches are blunt and generate exception queues. Fabric now delegates certification settings and default sensitivity labels to the domain level specifically so R3 absorbs decisions that used to pile up in R1.

The native-first control map

This is the table the tool vendors cannot publish. Column four is the honest one.

Governance jobNative Microsoft surfaceAdditional license requiredThird-party tool justified?
Access controlWorkspace roles, item permissions, Build permission, row-level securityNone beyond Pro/PPU/capacityOnly for multi-tenant entitlement-drift reporting
Classification and label-driven accessPurview sensitivity labels with source and downstream inheritance; protection policiesAIP P1/P2, plus Pro or PPU to applyRarely
Leak preventionPurview DLP for Fabric and Power BI — policy tips, alerts, restrict accessM365 E5, E5 Compliance, E5 Information Protection & Governance, or Purview capacitiesRarely
Trust signalsEndorsement: Promoted, Certified, Master data (preview)NoneNever — free, and most tenants have never enabled certification
Organizational structureFabric domains and subdomains with delegated settingsNoneNever
Inventory and usageAdmin monitoring workspace; feature usage and adoption report, 30-day active/inactive statusNoneFor history beyond 30 days without an export
Capacity and workspace telemetryCapacity Metrics app (14 days), capacity events in Real-Time Hub, workspace monitoring via EventhouseWorkspace monitoring consumes capacityFor multi-capacity trends across quarters
Lineage and lifecycleNative lineage shared with Purview; Git and deployment pipelinesFabric capacity for Git; capacity or PPU for pipelinesCross-platform lineage into non-Microsoft systems
Audit and spend controlPurview audit logs and named activity log operations; surge protection and capacity overage (preview)Retention beyond native windows requires exportLong-retention evidence without an in-house pipeline

The four jobs that justify a purchase: retention beyond native windows without building an export pipeline; bulk remediation with approval chains and rollback; multi-tenant or post-merger estates where the admin surface is per-tenant; and a single pane across Power BI, SharePoint, Teams, and OneDrive. If none apply, configure the native rings and spend the budget on the semantic model.

Tenant-settings hardening baseline

Ring 1. Every row is a real setting in the Fabric admin portal. Treat the recommended posture as a regulated-industry default to argue down from, not up to.

Tenant settingRisk if left at defaultRecommended posture
Publish to webReports readable on the public internet with no authenticationDisabled, or Enabled with "Allow only existing embed codes". Review the admin-portal Embed codes page on a schedule and delete anything unrecognised
Guest users can access Microsoft Fabric (and the invite setting)External identities browse tenant contentNamed security group only, with Entra External ID restrictions and Conditional Access
Users can see guest users in lists of suggested peopleAccidental external sharing via the people pickerDisabled — sharing to a guest then requires typing the full address
External data sharing, accepting external shares, and guest access to shared semantic modelsOneLake data leaving the tenant; your model surfacing in someone else'sDisabled unless a named, documented use case exists
Create workspacesUnbounded sprawlRestricted to a named group; audit changes via UpdatedAdminFeatureSwitch on item CreateAppWorkspaces
Allow users to apply sensitivity labelsNo classificationEnabled and scoped; labels must already exist and be published in Purview
Apply labels from data sources / apply labels to downstream contentClassification stops at the platform boundary; labeled model, unlabeled reportBoth enabled — Microsoft recommends inheritance for consistency
Certification (endorsement)No trust signal; every model looks equally authoritativeEnabled, named reviewers only, documentation URL populated, reviewers delegated per domain
Endorse master data (preview)No single-source-of-truth markerEnabled with restricted reviewers once master data domains are agreed
Users can use Copilot and other features powered by Azure OpenAITenant-wide AI on ungoverned models, plus capacity burnScope to security groups — Microsoft warns tenant-wide enablement without planning raises utilization and risk. Decide cross-geo processing with legal
Email subscriptions to external or B2B usersScheduled exfiltration by subscriptionDisabled
Users can download data from notebooksBulk export from notebook outputsRestricted; pair with notebook data export controls (preview)

The governance operating model and RACI

Nine roles. Learn's adoption roadmap names most of them; the mapping to specific decisions is EPC Group's.

ActivityResponsibleAccountableConsultedInformed
Change a tenant settingFabric administratorData governance boardSecurity & compliance admin, COEDomain admins
Size a capacity, set surge protection and overage limitsCapacity administratorFabric executive sponsorCOE, financeWorkspace admins
Create a workspace and assign its rolesWorkspace adminDomain adminData stewardFabric administrator
Define the sensitivity label taxonomySecurity & compliance adminData governance boardLegal, COEAll creators
Apply a label to an itemItem ownerWorkspace adminData stewardSecurity & compliance admin
Certify a semantic modelCertification reviewerCOEData steward, workspace adminConsumers
Create a DLP policySecurity & compliance adminData governance boardFabric administratorDomain admins
Decommission an orphaned workspaceFabric administratorDomain adminLast known ownerConsumers

Endorsement and certification: the workflow that makes it real

Endorsement is free, native, and almost universally under-used. Promotion can be applied by anyone with write permission. Certification and master data can only be applied by reviewers a Fabric administrator — or a delegated domain administrator — has named. All items except dashboards can be promoted or certified; master data applies only to items containing data.

A workflow that survives audit has six steps:

  1. Enable certification and name the reviewer groups. Populate the documentation URL — leave it blank and the in-product "How do I get content certified" link goes nowhere.
  2. Delegate per domain. Finance should not wait on a reviewer who does not know finance data.
  3. Publish the standard. Named owner, documented measures, RLS tested, refresh SLA, source lineage, label applied. Write it down and version it.
  4. Review against the standard, not the requester. A reviewer who has not read the model declines.
  5. Mark certified models discoverable so users without access find them in the OneLake catalog and request access instead of rebuilding.
  6. Re-review on a cycle. A certification with no expiry is a claim about a single day.

Certification is also the gate that makes Copilot safe: Copilot grounds on the semantic model, and Microsoft's own guidance suggests treating Copilot readiness as an endorsement criterion. See the CFO AI governance conversation and the Microsoft 365 Copilot pricing and licensing guide for the funding side.

The sprawl burn-down sequence

Sprawl is an R4 problem organizations keep trying to fix in R1. Order matters.

  1. Freeze. Restrict the Create workspaces tenant setting to a named group. Sprawl that is still growing cannot be measured.
  2. Inventory. Use the admin monitoring workspace. The feature usage and adoption report's Inventory page lists every item and flags each Active or Inactive based on audit-log activity in the last 30 days, with a decomposition tree by capacity, workspace, and user.
  3. Attribute. Every workspace gets a named owner, a domain, and a tier. Workspaces with no identifiable owner are the finding, not an inconvenience.
  4. Consolidate. One certified semantic model per subject area; retire duplicates on a published schedule with a communicated cut-off. This is the step that removes the six versions of revenue.
  5. Enforce. Labels applied, inheritance on, DLP in monitor mode first and blocking only once the policy is demonstrably accurate — Microsoft's baseline guidance is monitor-then-block.
  6. Sustain. A quarterly audit against the activity log. Query these by name: CreateFolder, UpdateFolder, UpdateWorkspaceAccess / UpdateFolderAccess, MigrateWorkspaceIntoCapacity, UpdateDataDomainFoldersRelationsAsAdmin, and AddAdminPersonalWorkspaceAccess — the last one logs no event when the system revokes access 24 hours later, so it needs watching.

What governance actually costs

ControlPublished figure / requirement
Per-user accessPro $14.00 and PPU $24.00 per user per month, paid yearly, as published at time of writing (July 2026)
Free read-only audienceF64+ lets Fabric Free users with the Viewer role read Power BI content; F2–F32 requires Pro or PPU per viewer
Sensitivity labelsAzure Information Protection P1 or P2, plus Pro or PPU to apply
DLP for Fabric and Power BIM365 E5, E5 Compliance, E5 Information Protection & Governance, or Purview capacities; evaluation consumes capacity
Audit retention30 days activity log, 14 days Capacity Metrics; longer needs an export
Lifecycle toolingFabric capacity for Git; Fabric/Premium capacity or PPU for deployment pipelines
Capacity commitmentAzure states a 1- or 3-year reservation saves approximately 41% versus pay-as-you-go

Two lines decide most budgets: the E5-class licensing DLP requires, and the F64 threshold. Already on E5? DLP for Fabric is a configuration project, not a purchase. On E3, model the delta first — see the E3 vs E5 comparison and the Power BI cost and licensing guide. Capacity sizing sits in the Power BI Premium and Premium vs Premium Per User material.

What breaks

SymptomRoot causeFix
A confidential report is publicly reachablePublish to web left enabled; an embed code was created months agoDisable or restrict Publish to web; audit every code on the Embed codes page; make the review recurring
Labels are enabled but coverage is near zeroLabeling was voluntary with no inheritanceEnable inheritance from sources and to downstream content; set a domain default label; measure coverage in the Purview protection metrics report
Certification exists but nothing is certifiedNo named reviewers, no published standard, no documentation URLName reviewers per domain, publish the standard, populate the documentation link so the in-product request path works
DLP generates noise and gets switched offBlocking deployed before the policy was proven accurateRestart in monitor mode with policy tips only; move to restrict-access after measuring false positives
Governance decisions queue behind central ITEverything configured in Ring 1Delegate certification settings and default labels to domains; assign domain admins who own the data
An admin accessed a personal workspace and nobody noticedHigh-privilege Fabric admin actions unmonitoredAlert on AddAdminPersonalWorkspaceAccess; automatic revocation after 24 hours logs no event
Audit evidence unavailable for 60 days agoNative retention is 30 days, and 14 for capacity metricsStand up an export to Log Analytics or an Eventhouse before the auditor asks

What changed in 2026

Platform context: Microsoft Fabric consulting services, the Fabric consulting guide, Fabric vs Databricks, and Snowflake to Fabric migration. Audit-evidence mapping is in the SOC 2 guide for Microsoft 365; the Power BI gateway guide covers the Ring 4 credential and clustering controls.

Where EPC Group starts

A governance engagement begins with a read-only assessment of all four rings: a tenant-settings diff against the baseline above, an inventory with ownership attribution, endorsement and label coverage, and a capacity posture review. The output is a prioritized remediation sequence and a RACI you can staff.

Comparative context: best data governance consulting firms and best enterprise Microsoft consulting firms. Delivery detail sits on the Power BI consulting services page and for Houston, with our operating model on the Microsoft Frontier Company page and at epcgroup.net.

Get the four-ring assessment

EPC Group runs it as a fixed-scope, read-only engagement. Start at Power BI consulting services.

Frequently asked questions

What is Power BI governance?

Power BI governance is the set of policies and controls that decide who can create, access, share, certify, and export content, and how that is enforced and evidenced. In Fabric it is administered across four rings — tenant settings, capacity settings, domains, and workspace or item permissions — plus Microsoft Purview for classification, data loss prevention, and audit.

Do I need a third-party Power BI governance tool?

Usually not. Access control, endorsement, domains, lineage, tenant settings, inventory reporting, and capacity telemetry are Microsoft-native and included. A purchase is justified for four jobs: audit retention beyond 30 days without building an export, bulk remediation with approval workflows, multi-tenant or post-merger estates, and a single pane across Power BI, SharePoint, Teams, and OneDrive.

What is the difference between promoted and certified?

Promotion can be applied by any user with write permission on the item and signals that the creator thinks it is ready to share. Certification means an organization-authorized reviewer has confirmed the item meets published quality standards. Only users named by a Fabric administrator, or by a delegated domain administrator, can certify.

How long does Power BI keep audit data?

Fabric activity logs retain 30 days and the Fabric Capacity Metrics app shows a 14-day window. Longer retention requires exporting to Azure Monitor, Log Analytics, or an Eventhouse. If your compliance requirement is one year, build the export before an auditor asks for evidence from month three.

What licenses do sensitivity labels and DLP require?

Sensitivity labels come from Microsoft Purview Information Protection and require an Azure Information Protection P1 or P2 license, plus Power BI Pro or PPU to apply a label to an item. DLP policies for Fabric and Power BI require the creating admin account to hold Microsoft 365 E5, E5 Compliance, E5 Information Protection & Governance, or Purview capacities.

Which tenant setting is the most dangerous?

Publish to web. It creates reports that anyone on the internet can read without authenticating. Disable it, or enable it with "Allow only existing embed codes", and review the Embed codes page in the admin portal on a schedule. Guest access and external data sharing are the next two.

How do we stop workspace sprawl?

In order: restrict the Create workspaces tenant setting to a named group, inventory the tenant using the admin monitoring workspace, attribute every workspace to a named owner and a domain, consolidate to one certified semantic model per subject area, enforce labels and DLP, then audit quarterly against the activity log. Starting at consolidation without freezing creation does not work.

Does governance slow down self-service?

It does when it is all configured tenant-wide. Fabric supports delegating certification settings and default sensitivity labels to the domain level precisely so business units can decide for themselves inside guardrails. Microsoft's own guidance is that the lightest governance model that meets the objective is the one that succeeds.

What has to be governed before we turn on Copilot?

Copilot requires a paid Fabric capacity of F2 or higher and tenant-level enablement, but the governance prerequisites matter more: scope enablement to security groups rather than the whole tenant, resolve the cross-geo processing decision with legal, and make semantic model quality and endorsement a precondition. Copilot grounded on an ungoverned model produces confident wrong answers.

Who should own Power BI governance?

Not one person. The executive sponsor owns the mandate, the governance board owns policy, the Center of Excellence owns standards and certification review, the Fabric administrator owns tenant settings, capacity admins own capacity, domain admins own their domain, and workspace admins own access. Every workspace also needs a named human owner — that is the control no product can supply.

Sources and verification

  1. Microsoft Learn — Microsoft Fabric adoption roadmap: Governance (roles and responsibilities, governance success factors)
  2. Microsoft Learn — Tenant settings index
  3. Microsoft Learn — Export and sharing settings (Publish to web, guest users, external data sharing)
  4. Microsoft Learn — Roles in workspaces in Power BI
  5. Microsoft Learn — Endorsement overview (Promoted, Certified, Master data)
  6. Microsoft Learn — Endorse Fabric and Power BI items (promote, certify, request certification)
  7. Microsoft Learn — Enable master data endorsement
  8. Microsoft Learn — Fabric domains (domain roles, delegated settings, default sensitivity label, certification delegation)
  9. Microsoft Learn — Information protection in Microsoft Fabric
  10. Microsoft Learn — Enable sensitivity labels in Fabric and Power BI (AIP P1/P2 licensing)
  11. Microsoft Learn — Protected sensitivity labels in Fabric and Power BI
  12. Microsoft Learn — Get started with data loss prevention policies for Fabric and Power BI (licensing, supported item types, actions)
  13. Microsoft Learn — Use Microsoft Purview to govern Microsoft Fabric
  14. Microsoft Learn — What is Microsoft Fabric administration? (admin monitoring workspace, monitoring hub, audit logs, Capacity Metrics)
  15. Microsoft Learn — Feature usage and adoption report (inventory, 30-day active/inactive status)
  16. Microsoft Learn — Track user activities in Microsoft Fabric
  17. Microsoft Learn — Power BI implementation planning: Tenant administration (workspace audit activities)
  18. Microsoft Learn — Microsoft Fabric workload operations (30-day activity log retention, 14-day Capacity Metrics window)
  19. Microsoft Learn — Surge protection (capacity and workspace level)
  20. Microsoft Learn — Capacity overage (preview) in Microsoft Fabric
  21. Microsoft Learn — Power BI Premium P SKU to Fabric F SKU migration decision guide (Azure-native features on F SKUs)
  22. Microsoft Learn — Understand Microsoft Fabric licenses (F64 free-viewer threshold)
  23. Microsoft Learn — Enable and configure Copilot in Microsoft Fabric (F2 minimum, tenant-wide enablement warning)
  24. Microsoft Learn — Use Copilot with semantic models (endorsement as a Copilot-readiness criterion)
  25. Microsoft Learn — Fabric governance and security baselines (monitor-then-block DLP guidance, lineage)
  26. Microsoft Learn — Notebook data export controls in Microsoft Fabric (preview)
  27. Microsoft — Power BI pricing (Pro $14.00, PPU $24.00 per user/month paid yearly; as published at time of writing, July 2026)
  28. Azure — Microsoft Fabric pricing (reservation savings of approximately 41% versus pay-as-you-go; as published at time of writing, July 2026)
  29. Target citation under review — Rencore, Microsoft Power BI governance guide
  30. Secondary target under review — Presidio, Power BI governance and security (published 22 January 2026)

AI assistant — not human