A way of grouping workspaces by area of the business, in support of a data mesh approach. Items take on their workspace's domain, letting you filter the OneLake catalog by it, and certain tenant settings can be passed to domain admins; domains have no effect on access permissions.
Also called Fabric domain.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Domain in context, with comparison tables and the common traps.
Terms in this definition
- Workspace
Teams in Power BI and Microsoft Fabric collaborate in this folder-style container, which groups items such as reports, semantic models and lakehouses, controls who can access them and is assigned a capacity.
- FILTER
Returns just those rows of a table that meet a condition. In CALCULATE it handles conditions too complex for a Boolean filter argument, though a Boolean filter is faster whenever one will work.
- OneLake catalog
The hub in Fabric for finding, exploring and governing the items you have access to, split into Explore and Govern tabs. Tenant settings can now be reached from OneLake catalog > Govern too.
- Tenant settings
Admins in Fabric flip these toggles to enable or disable features across an organisation, either globally, just for chosen security groups, or excluding certain groups. Recent releases moved them to OneLake catalog > Govern > Configurations.
- Domain Admins
A built-in global group that has complete control over its domain. Its members are local administrators on all computers joined to that domain.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
Related terms
- AAD DC Administrators
Grants members admin rights over joined VMs and control of Group Policy for AADDC containers in an Entra Domain Services managed domain. Enterprise Admins and Domain Admins rights don't exist there.
- AADDC Computers
Container built into an Entra Domain Services managed domain, holding joined VMs' computer accounts, with a GPO of its own.
- AADDC Users
Container built into an Entra Domain Services managed domain, holding groups and users synchronised there, with a GPO of its own.
- Account lockout policy
Locks accounts after a set number of failed sign-ins, using domain settings for threshold, duration and counter reset. Thresholds run from 0 to 999, and 0 disables lockout.
- AD DS
Short for Active Directory Domain Services, the domain controller-based Windows directory run on-premises. Microsoft Entra Domain Services offers a managed counterpart.
- ANC
Tells Windows 365 which Azure subscription, virtual network and subnet to place Cloud PCs in (plus, where they're hybrid joined, which AD OU and domain). Provisioning policies use it, Intune checks its health at intervals of one to six hours, and you can have 50 per tenant.
- Apex domain
The bare domain without any subdomain (example.com), also known as the zone apex or root domain. Since a CNAME is not allowed there, routing it to a service like Front Door relies on CNAME flattening or Azure DNS alias records.
- ASN
Short for autonomous system number, which identifies a BGP routing domain. Azure VPN gateways use 65515 by default, a reserved value on-premises peers must avoid; Defender EASM also discovers ASNs as an internet asset type.