The part of the Cloud Adoption Framework concerned with keeping cloud use under control by setting guardrails made of policies, procedures and tools. It runs continuously across the estate alongside Secure and Manage.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Govern in context, with comparison tables and the common traps.
Terms in this definition
- Cloud Adoption Framework
Microsoft's body of guidance on adopting Azure. It runs through seven stages (Strategy, Plan, Ready, Adopt, Govern, Secure, Manage), and the landing zone is what Ready delivers.
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
- Agents (classic) API
First-generation Foundry Agent Service API, based on threads, messages and runs. It is deprecated, replaced by conversations and responses, and retires on 31 March 2027.
- HTTP / HTTPS
The protocols of the web, with HTTPS being HTTP secured by TLS.
- MANAGE
A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of
ALL PRIVILEGES.
Related terms
- AD DS authentication (Azure Files)
Option that domain-joins a storage account to on-premises AD DS, letting synced hybrid users mount its SMB shares using Kerberos. RBAC controls share-level access, while Windows ACLs govern files and folders.
- Admin monitoring workspace
A preview workspace for Fabric admins that appears automatically when an admin first visits Admin monitoring under Workspaces. Its data is read-only and refreshed daily, powering reports like the Govern report in the OneLake catalog, and admins can give others access with the Viewer role.
- Agent pool
A set of agents for running Azure Pipelines jobs, created for the whole organisation and shared with projects. Pool roles and pipeline permissions govern who manages it and which pipelines may use it; in GitHub, runner groups play this part.
- Analyst
A reasoning agent built by Microsoft that comes alongside Researcher for people with a Microsoft Copilot licence, and writes and runs code to work through raw data such as multiple spreadsheets. Agent settings don't govern it, because it belongs to the core Copilot Chat experience.
- Architecture Framework
The conceptual scaffolding used to plan, build, put in place, govern and maintain an architecture; organisations normally adapt it to their needs.
- Bridge all site links
Enabled by default, this makes site links transitive so the KCC may chain them for replication. Switching it off means manually created site link bridges govern routing.
- Compute permissions
Access rules that live inside one Fabric engine and govern only queries run through it. They include T-SQL GRANT or DENY, masking and row-level security on a warehouse or SQL analytics endpoint, and DAX-based security in a semantic model.
- EPAC
Teams fluent in DevOps and infrastructure as code can pick this open-source tooling over the usual platform options to roll out and look after Azure Policy objects of every kind estate-wide. Microsoft says to weigh it up early, because switching how you govern policy later is costly.