Policies were much needed. Until now, many Fabric capabilities were controlled by tenant switches that enable a feature for everyone or restrict it for everyone. Nothing was this fine-grained, which created blind spots and admin headaches. Fabric Policies let admins define who can perform an action, what the rule covers, and where it applies. If no rule matches, the action is denied.
The first three policy types are:
- Item creation (capacity scope): controls who can create specific item types in workspaces on a capacity.
- Edit workspace settings (tenant scope): controls who can change security-sensitive workspace settings, such as network security and customer-managed keys.
- External data sharing (tenant scope): controls who can share data externally, from which workspaces, for which sensitivity labels, and to which recipient domains.
Policies are stored in Policy Set items and managed in the Policies Center in the OneLake catalog. They support public APIs and Git integration, and policy changes are recorded in the Microsoft 365 audit log.
Click through for all ten.