Most Power BI governance is already free. Access control, endorsement, domains, lineage, tenant settings, audit logging, and capacity telemetry are Microsoft-native and included. EPC Group's position: harden the native rings first, and buy a third-party tool only for the four jobs the platform does not do.
EPC Group is a Houston-based Microsoft consulting firm operating since 1997, with six Microsoft Solutions Partner designations and 216+ M&A tenant migrations covering 1.83M users.
Last updated: 2026-07-31
Key facts
- Fabric activity logs retain 30 days; the Capacity Metrics app shows 14. Anything longer requires export. That pair of numbers decides whether you need a tool or a pipeline.
- Only users a Fabric administrator names can certify items. Promotion is open to anyone with write permission; certification is not, and enablement can now be delegated to domain administrators.
- Sensitivity labels come from Microsoft Purview Information Protection and require an Azure Information Protection P1 or P2 license, plus Power BI Pro or PPU to apply a label.
- DLP for Fabric and Power BI requires M365 E5, E5 Compliance, E5 Information Protection & Governance, or Purview capacities for the admin creating policies, and evaluation consumes Fabric capacity.
- Publish to web produces reports that require no authentication. Reviewing its embed codes is the highest-value hour in a Power BI security audit.
- Power BI Pro lists at $14.00 per user per month and PPU at $24.00, paid yearly, as published at time of writing (July 2026).
Quick facts
| Question | Answer |
|---|---|
| Where it is configured | Fabric admin portal tenant, capacity, domain and workspace settings; Microsoft Purview portal |
| Four control rings | Tenant → Capacity → Domain → Workspace/Item |
| Access roles | Admin, Member, Contributor, Viewer — nested, each inheriting those below |
| Trust signals | Promoted (open); Certified and Master data (named reviewers) |
| Classification and enforcement | Purview labels with inheritance; protection policies; DLP; Defender for Cloud Apps |
| Audit retention | Activity logs 30 days; Capacity Metrics 14 days |
| Highest-risk defaults | Publish to web, guest access, external data sharing |
| What no tool fixes | Ownership. Every workspace needs a named human owner |
Why governance-tool vendors cannot answer this question
The page currently ranking fifth on this query is published by Rencore, which sells a Microsoft 365 and Power BI governance product. It is a competent post. It also cannot tell you that oversharing prevention, sprawl control, license monitoring, and access review — the four capabilities it presents — all have Microsoft-native surfaces most enterprises already own and have never configured. That is a structural limit, not bad faith. Syskit, AvePoint, and Quest content on adjacent queries has the same constraint.
Microsoft Learn has the opposite limit. Its Fabric adoption roadmap for governance holds position one and is the correct authority on the conceptual model, the roles table, and the maturity levels. It cannot tell you what governance costs, what to set each switch to in a regulated environment, when a third-party tool is worth buying, or what breaks. This article covers those four things and defers to Learn on the rest.
The Four-Ring Power BI Governance Model
Fabric delegates control downward through four rings. Every governance decision belongs to exactly one ring, and most governance failures are a decision made in the wrong one.
| Ring | Control surface | Who administers | Decisions that belong here | Failure signature when it is skipped |
|---|---|---|---|---|
| R1 — Tenant | Admin portal tenant settings | Fabric administrator | Publish to web, guest access, external sharing, label enablement, Copilot enablement, who may create workspaces | External exposure. Nobody ever turned the controls off |
| R2 — Capacity | Capacity settings, delegated tenant settings | Capacity administrator | SKU sizing, surge protection thresholds, overage limits, per-capacity Copilot | Cost and performance incidents misread as product problems |
| R3 — Domain | Domains, subdomains, delegated settings | Domain admin, domain contributor | Default sensitivity label, domain-scoped certification reviewers, workspace assignment | Central IT becomes the bottleneck for every business-unit decision |
| R4 — Workspace / item | Workspace roles, item permissions, endorsement, labels | Workspace admin, item owner, certification reviewer | Who can edit, who can build, what is certified, what is labeled | Six versions of revenue. Sprawl is an R4 failure people try to solve in R1 |
The rule: push each control to the lowest ring that can be held accountable for it. Tenant-wide switches are blunt and generate exception queues. Fabric now delegates certification settings and default sensitivity labels to the domain level specifically so R3 absorbs decisions that used to pile up in R1.
The native-first control map
This is the table the tool vendors cannot publish. Column four is the honest one.
| Governance job | Native Microsoft surface | Additional license required | Third-party tool justified? |
|---|---|---|---|
| Access control | Workspace roles, item permissions, Build permission, row-level security | None beyond Pro/PPU/capacity | Only for multi-tenant entitlement-drift reporting |
| Classification and label-driven access | Purview sensitivity labels with source and downstream inheritance; protection policies | AIP P1/P2, plus Pro or PPU to apply | Rarely |
| Leak prevention | Purview DLP for Fabric and Power BI — policy tips, alerts, restrict access | M365 E5, E5 Compliance, E5 Information Protection & Governance, or Purview capacities | Rarely |
| Trust signals | Endorsement: Promoted, Certified, Master data (preview) | None | Never — free, and most tenants have never enabled certification |
| Organizational structure | Fabric domains and subdomains with delegated settings | None | Never |
| Inventory and usage | Admin monitoring workspace; feature usage and adoption report, 30-day active/inactive status | None | For history beyond 30 days without an export |
| Capacity and workspace telemetry | Capacity Metrics app (14 days), capacity events in Real-Time Hub, workspace monitoring via Eventhouse | Workspace monitoring consumes capacity | For multi-capacity trends across quarters |
| Lineage and lifecycle | Native lineage shared with Purview; Git and deployment pipelines | Fabric capacity for Git; capacity or PPU for pipelines | Cross-platform lineage into non-Microsoft systems |
| Audit and spend control | Purview audit logs and named activity log operations; surge protection and capacity overage (preview) | Retention beyond native windows requires export | Long-retention evidence without an in-house pipeline |
The four jobs that justify a purchase: retention beyond native windows without building an export pipeline; bulk remediation with approval chains and rollback; multi-tenant or post-merger estates where the admin surface is per-tenant; and a single pane across Power BI, SharePoint, Teams, and OneDrive. If none apply, configure the native rings and spend the budget on the semantic model.
Tenant-settings hardening baseline
Ring 1. Every row is a real setting in the Fabric admin portal. Treat the recommended posture as a regulated-industry default to argue down from, not up to.
| Tenant setting | Risk if left at default | Recommended posture |
|---|---|---|
| Publish to web | Reports readable on the public internet with no authentication | Disabled, or Enabled with "Allow only existing embed codes". Review the admin-portal Embed codes page on a schedule and delete anything unrecognised |
| Guest users can access Microsoft Fabric (and the invite setting) | External identities browse tenant content | Named security group only, with Entra External ID restrictions and Conditional Access |
| Users can see guest users in lists of suggested people | Accidental external sharing via the people picker | Disabled — sharing to a guest then requires typing the full address |
| External data sharing, accepting external shares, and guest access to shared semantic models | OneLake data leaving the tenant; your model surfacing in someone else's | Disabled unless a named, documented use case exists |
| Create workspaces | Unbounded sprawl | Restricted to a named group; audit changes via UpdatedAdminFeatureSwitch on item CreateAppWorkspaces |
| Allow users to apply sensitivity labels | No classification | Enabled and scoped; labels must already exist and be published in Purview |
| Apply labels from data sources / apply labels to downstream content | Classification stops at the platform boundary; labeled model, unlabeled report | Both enabled — Microsoft recommends inheritance for consistency |
| Certification (endorsement) | No trust signal; every model looks equally authoritative | Enabled, named reviewers only, documentation URL populated, reviewers delegated per domain |
| Endorse master data (preview) | No single-source-of-truth marker | Enabled with restricted reviewers once master data domains are agreed |
| Users can use Copilot and other features powered by Azure OpenAI | Tenant-wide AI on ungoverned models, plus capacity burn | Scope to security groups — Microsoft warns tenant-wide enablement without planning raises utilization and risk. Decide cross-geo processing with legal |
| Email subscriptions to external or B2B users | Scheduled exfiltration by subscription | Disabled |
| Users can download data from notebooks | Bulk export from notebook outputs | Restricted; pair with notebook data export controls (preview) |
The governance operating model and RACI
Nine roles. Learn's adoption roadmap names most of them; the mapping to specific decisions is EPC Group's.
- Fabric executive sponsor — owns the mandate, breaks ties across business units.
- Data governance board — sets policy, approves exceptions.
- Center of Excellence (COE) — mentors creators, maintains standards, runs certification review.
- Fabric administrator (R1) — high-privilege. It does not automatically grant data access, but it can grant itself workspace access, which is exactly why it needs audit.
- Capacity administrator (R2), domain admin / contributor (R3) — a domain contributor must hold the workspace Admin role to assign a workspace to a domain — and workspace admin (R4).
- Certification reviewer — named by the Fabric admin or a delegated domain admin.
- Data steward — owns data quality for a subject area. Security and compliance admin — owns labels, DLP, and audit.
| Activity | Responsible | Accountable | Consulted | Informed |
|---|---|---|---|---|
| Change a tenant setting | Fabric administrator | Data governance board | Security & compliance admin, COE | Domain admins |
| Size a capacity, set surge protection and overage limits | Capacity administrator | Fabric executive sponsor | COE, finance | Workspace admins |
| Create a workspace and assign its roles | Workspace admin | Domain admin | Data steward | Fabric administrator |
| Define the sensitivity label taxonomy | Security & compliance admin | Data governance board | Legal, COE | All creators |
| Apply a label to an item | Item owner | Workspace admin | Data steward | Security & compliance admin |
| Certify a semantic model | Certification reviewer | COE | Data steward, workspace admin | Consumers |
| Create a DLP policy | Security & compliance admin | Data governance board | Fabric administrator | Domain admins |
| Decommission an orphaned workspace | Fabric administrator | Domain admin | Last known owner | Consumers |
Endorsement and certification: the workflow that makes it real
Endorsement is free, native, and almost universally under-used. Promotion can be applied by anyone with write permission. Certification and master data can only be applied by reviewers a Fabric administrator — or a delegated domain administrator — has named. All items except dashboards can be promoted or certified; master data applies only to items containing data.
A workflow that survives audit has six steps:
- Enable certification and name the reviewer groups. Populate the documentation URL — leave it blank and the in-product "How do I get content certified" link goes nowhere.
- Delegate per domain. Finance should not wait on a reviewer who does not know finance data.
- Publish the standard. Named owner, documented measures, RLS tested, refresh SLA, source lineage, label applied. Write it down and version it.
- Review against the standard, not the requester. A reviewer who has not read the model declines.
- Mark certified models discoverable so users without access find them in the OneLake catalog and request access instead of rebuilding.
- Re-review on a cycle. A certification with no expiry is a claim about a single day.
Certification is also the gate that makes Copilot safe: Copilot grounds on the semantic model, and Microsoft's own guidance suggests treating Copilot readiness as an endorsement criterion. See the CFO AI governance conversation and the Microsoft 365 Copilot pricing and licensing guide for the funding side.
The sprawl burn-down sequence
Sprawl is an R4 problem organizations keep trying to fix in R1. Order matters.
- Freeze. Restrict the Create workspaces tenant setting to a named group. Sprawl that is still growing cannot be measured.
- Inventory. Use the admin monitoring workspace. The feature usage and adoption report's Inventory page lists every item and flags each Active or Inactive based on audit-log activity in the last 30 days, with a decomposition tree by capacity, workspace, and user.
- Attribute. Every workspace gets a named owner, a domain, and a tier. Workspaces with no identifiable owner are the finding, not an inconvenience.
- Consolidate. One certified semantic model per subject area; retire duplicates on a published schedule with a communicated cut-off. This is the step that removes the six versions of revenue.
- Enforce. Labels applied, inheritance on, DLP in monitor mode first and blocking only once the policy is demonstrably accurate — Microsoft's baseline guidance is monitor-then-block.
- Sustain. A quarterly audit against the activity log. Query these by name:
CreateFolder,UpdateFolder,UpdateWorkspaceAccess/UpdateFolderAccess,MigrateWorkspaceIntoCapacity,UpdateDataDomainFoldersRelationsAsAdmin, andAddAdminPersonalWorkspaceAccess— the last one logs no event when the system revokes access 24 hours later, so it needs watching.
What governance actually costs
| Control | Published figure / requirement |
|---|---|
| Per-user access | Pro $14.00 and PPU $24.00 per user per month, paid yearly, as published at time of writing (July 2026) |
| Free read-only audience | F64+ lets Fabric Free users with the Viewer role read Power BI content; F2–F32 requires Pro or PPU per viewer |
| Sensitivity labels | Azure Information Protection P1 or P2, plus Pro or PPU to apply |
| DLP for Fabric and Power BI | M365 E5, E5 Compliance, E5 Information Protection & Governance, or Purview capacities; evaluation consumes capacity |
| Audit retention | 30 days activity log, 14 days Capacity Metrics; longer needs an export |
| Lifecycle tooling | Fabric capacity for Git; Fabric/Premium capacity or PPU for deployment pipelines |
| Capacity commitment | Azure states a 1- or 3-year reservation saves approximately 41% versus pay-as-you-go |
Two lines decide most budgets: the E5-class licensing DLP requires, and the F64 threshold. Already on E5? DLP for Fabric is a configuration project, not a purchase. On E3, model the delta first — see the E3 vs E5 comparison and the Power BI cost and licensing guide. Capacity sizing sits in the Power BI Premium and Premium vs Premium Per User material.
What breaks
| Symptom | Root cause | Fix |
|---|---|---|
| A confidential report is publicly reachable | Publish to web left enabled; an embed code was created months ago | Disable or restrict Publish to web; audit every code on the Embed codes page; make the review recurring |
| Labels are enabled but coverage is near zero | Labeling was voluntary with no inheritance | Enable inheritance from sources and to downstream content; set a domain default label; measure coverage in the Purview protection metrics report |
| Certification exists but nothing is certified | No named reviewers, no published standard, no documentation URL | Name reviewers per domain, publish the standard, populate the documentation link so the in-product request path works |
| DLP generates noise and gets switched off | Blocking deployed before the policy was proven accurate | Restart in monitor mode with policy tips only; move to restrict-access after measuring false positives |
| Governance decisions queue behind central IT | Everything configured in Ring 1 | Delegate certification settings and default labels to domains; assign domain admins who own the data |
| An admin accessed a personal workspace and nobody noticed | High-privilege Fabric admin actions unmonitored | Alert on AddAdminPersonalWorkspaceAccess; automatic revocation after 24 hours logs no event |
| Audit evidence unavailable for 60 days ago | Native retention is 30 days, and 14 for capacity metrics | Stand up an export to Log Analytics or an Eventhouse before the auditor asks |
What changed in 2026
- Master data endorsement (preview) joins Promoted and Certified, applied only by authorized users and only to items containing data.
- Certification enablement and default sensitivity labels can now be delegated to domain administrators, moving both out of Ring 1 into Ring 3 — the most useful change for large federated estates.
- Protection policies control access to Fabric items by sensitivity label — distinct from protected labels, which in the service only control who can change or remove a label.
- Workspace-level surge protection caps CU spend per workspace in a rolling 24-hour window with a Mission Critical exclusion. Capacity overage (preview) pays off excess usage up to an admin-set limit instead of throttling; it adds no performance, and Microsoft recommends it only for F16 and higher during preview.
- Notebook data export controls (preview) restrict how data leaves Fabric notebooks.
- P SKU retirement moves the governance surface into Azure. F SKUs bring trusted workspace access, managed private endpoints, Azure Monitor, and Microsoft Cost Management — none available on P SKUs.
- Purview integration deepened: live view of Fabric items in the Unified Catalog, automatic lineage sharing, and DLP extended across lakehouses, warehouses, KQL and SQL databases, mirrored databases, and semantic models.
Platform context: Microsoft Fabric consulting services, the Fabric consulting guide, Fabric vs Databricks, and Snowflake to Fabric migration. Audit-evidence mapping is in the SOC 2 guide for Microsoft 365; the Power BI gateway guide covers the Ring 4 credential and clustering controls.
Where EPC Group starts
A governance engagement begins with a read-only assessment of all four rings: a tenant-settings diff against the baseline above, an inventory with ownership attribution, endorsement and label coverage, and a capacity posture review. The output is a prioritized remediation sequence and a RACI you can staff.
Comparative context: best data governance consulting firms and best enterprise Microsoft consulting firms. Delivery detail sits on the Power BI consulting services page and for Houston, with our operating model on the Microsoft Frontier Company page and at epcgroup.net.
Get the four-ring assessment
EPC Group runs it as a fixed-scope, read-only engagement. Start at Power BI consulting services.
Frequently asked questions
What is Power BI governance?
Power BI governance is the set of policies and controls that decide who can create, access, share, certify, and export content, and how that is enforced and evidenced. In Fabric it is administered across four rings — tenant settings, capacity settings, domains, and workspace or item permissions — plus Microsoft Purview for classification, data loss prevention, and audit.
Do I need a third-party Power BI governance tool?
Usually not. Access control, endorsement, domains, lineage, tenant settings, inventory reporting, and capacity telemetry are Microsoft-native and included. A purchase is justified for four jobs: audit retention beyond 30 days without building an export, bulk remediation with approval workflows, multi-tenant or post-merger estates, and a single pane across Power BI, SharePoint, Teams, and OneDrive.
What is the difference between promoted and certified?
Promotion can be applied by any user with write permission on the item and signals that the creator thinks it is ready to share. Certification means an organization-authorized reviewer has confirmed the item meets published quality standards. Only users named by a Fabric administrator, or by a delegated domain administrator, can certify.
How long does Power BI keep audit data?
Fabric activity logs retain 30 days and the Fabric Capacity Metrics app shows a 14-day window. Longer retention requires exporting to Azure Monitor, Log Analytics, or an Eventhouse. If your compliance requirement is one year, build the export before an auditor asks for evidence from month three.
What licenses do sensitivity labels and DLP require?
Sensitivity labels come from Microsoft Purview Information Protection and require an Azure Information Protection P1 or P2 license, plus Power BI Pro or PPU to apply a label to an item. DLP policies for Fabric and Power BI require the creating admin account to hold Microsoft 365 E5, E5 Compliance, E5 Information Protection & Governance, or Purview capacities.
Which tenant setting is the most dangerous?
Publish to web. It creates reports that anyone on the internet can read without authenticating. Disable it, or enable it with "Allow only existing embed codes", and review the Embed codes page in the admin portal on a schedule. Guest access and external data sharing are the next two.
How do we stop workspace sprawl?
In order: restrict the Create workspaces tenant setting to a named group, inventory the tenant using the admin monitoring workspace, attribute every workspace to a named owner and a domain, consolidate to one certified semantic model per subject area, enforce labels and DLP, then audit quarterly against the activity log. Starting at consolidation without freezing creation does not work.
Does governance slow down self-service?
It does when it is all configured tenant-wide. Fabric supports delegating certification settings and default sensitivity labels to the domain level precisely so business units can decide for themselves inside guardrails. Microsoft's own guidance is that the lightest governance model that meets the objective is the one that succeeds.
What has to be governed before we turn on Copilot?
Copilot requires a paid Fabric capacity of F2 or higher and tenant-level enablement, but the governance prerequisites matter more: scope enablement to security groups rather than the whole tenant, resolve the cross-geo processing decision with legal, and make semantic model quality and endorsement a precondition. Copilot grounded on an ungoverned model produces confident wrong answers.
Who should own Power BI governance?
Not one person. The executive sponsor owns the mandate, the governance board owns policy, the Center of Excellence owns standards and certification review, the Fabric administrator owns tenant settings, capacity admins own capacity, domain admins own their domain, and workspace admins own access. Every workspace also needs a named human owner — that is the control no product can supply.
Sources and verification
- Microsoft Learn — Microsoft Fabric adoption roadmap: Governance (roles and responsibilities, governance success factors)
- Microsoft Learn — Tenant settings index
- Microsoft Learn — Export and sharing settings (Publish to web, guest users, external data sharing)
- Microsoft Learn — Roles in workspaces in Power BI
- Microsoft Learn — Endorsement overview (Promoted, Certified, Master data)
- Microsoft Learn — Endorse Fabric and Power BI items (promote, certify, request certification)
- Microsoft Learn — Enable master data endorsement
- Microsoft Learn — Fabric domains (domain roles, delegated settings, default sensitivity label, certification delegation)
- Microsoft Learn — Information protection in Microsoft Fabric
- Microsoft Learn — Enable sensitivity labels in Fabric and Power BI (AIP P1/P2 licensing)
- Microsoft Learn — Protected sensitivity labels in Fabric and Power BI
- Microsoft Learn — Get started with data loss prevention policies for Fabric and Power BI (licensing, supported item types, actions)
- Microsoft Learn — Use Microsoft Purview to govern Microsoft Fabric
- Microsoft Learn — What is Microsoft Fabric administration? (admin monitoring workspace, monitoring hub, audit logs, Capacity Metrics)
- Microsoft Learn — Feature usage and adoption report (inventory, 30-day active/inactive status)
- Microsoft Learn — Track user activities in Microsoft Fabric
- Microsoft Learn — Power BI implementation planning: Tenant administration (workspace audit activities)
- Microsoft Learn — Microsoft Fabric workload operations (30-day activity log retention, 14-day Capacity Metrics window)
- Microsoft Learn — Surge protection (capacity and workspace level)
- Microsoft Learn — Capacity overage (preview) in Microsoft Fabric
- Microsoft Learn — Power BI Premium P SKU to Fabric F SKU migration decision guide (Azure-native features on F SKUs)
- Microsoft Learn — Understand Microsoft Fabric licenses (F64 free-viewer threshold)
- Microsoft Learn — Enable and configure Copilot in Microsoft Fabric (F2 minimum, tenant-wide enablement warning)
- Microsoft Learn — Use Copilot with semantic models (endorsement as a Copilot-readiness criterion)
- Microsoft Learn — Fabric governance and security baselines (monitor-then-block DLP guidance, lineage)
- Microsoft Learn — Notebook data export controls in Microsoft Fabric (preview)
- Microsoft — Power BI pricing (Pro $14.00, PPU $24.00 per user/month paid yearly; as published at time of writing, July 2026)
- Azure — Microsoft Fabric pricing (reservation savings of approximately 41% versus pay-as-you-go; as published at time of writing, July 2026)
- Target citation under review — Rencore, Microsoft Power BI governance guide
- Secondary target under review — Presidio, Power BI governance and security (published 22 January 2026)
