Selected Fabric tenant settings that the tenant-level admin hands down so that domain, capacity or workspace admins may choose differently within their own area, by ticking Override tenant admin selection. Delegation for any one setting happens through domains or through capacities, but never via both routes.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Delegated tenant settings in context, with comparison tables and the common traps.
Terms in this definition
- Tenant settings
Admins in Fabric flip these toggles to enable or disable features across an organisation, either globally, just for chosen security groups, or excluding certain groups. Recent releases moved them to OneLake catalog > Govern > Configurations.
- Domain
A way of grouping workspaces by area of the business, in support of a data mesh approach. Items take on their workspace's domain, letting you filter the OneLake catalog by it, and certain tenant settings can be passed to domain admins; domains have no effect on access permissions.
- Capacity
A reserved block of compute for a tenant whose size is fixed by its SKU; Fabric F SKUs express it in capacity units (CUs). Workspaces assigned to it unlock features like Copilot, and from F64 upwards people with free licences can view Power BI content.
- Workspace
Teams in Power BI and Microsoft Fabric collaborate in this folder-style container, which groups items such as reports, semantic models and lakehouses, controls who can access them and is assigned a capacity.
- Tenant
A trusted, dedicated Microsoft Entra ID instance that stores the users, groups and app registrations of one organisation. A subscription trusts only a single tenant, although a tenant can be trusted by several subscriptions.