Tags defined at account level and controlled by a tag policy that sets permitted values and who can apply them. Catalogs and schemas pass them down to child objects (columns do not inherit them), and ABAC policies use them as the attributes to match.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Governed tags in context, with comparison tables and the common traps.
Terms in this definition
- Image tagging
An Image Analysis feature producing single-word tags, each with a confidence score, for actions, scenery, objects and living things in an image.
- Tag
Key-value label on compute (for cost tracking) or on a Unity Catalog securable or column, applied with
SET TAGorSET TAGSand requiringAPPLY TAG. Governed tags restrict allowed keys, values and assigners across the account. - Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- VALUES
Returns in DAX the distinct column values, or table rows, still visible after filters are applied, sometimes with an extra blank entry. CALCULATE often takes the result as a table filter.
- APPLY
Evaluates a table-valued expression for every row on its left, inside
FROM. Think ofOUTER APPLYas a left outer join andCROSS APPLYas an inner join. - Azure ABAC
Attribute-based conditions added on top of Azure RBAC role assignments, such as granting access only to blobs carrying a certain index tag. Blobs (ADLS Gen2 included) and queues support them; Azure Files and Tables do not.
- MATCH
Used in WHERE when querying SQL Graph, it describes how to walk from node to node through edge tables, with patterns written like p1-(f1)->p2.
Related terms
- ABAC policy
Governed tags drive this kind of Unity Catalog rule: when a table or column has tags that satisfy its
WHENandMATCH COLUMNSconditions, a row filter or column mask UDF is put on it automatically. Policies are written withCREATE POLICYand can sit on a metastore, catalog, schema or table. - DENY policy
A Beta ABAC policy type that takes a privilege away rather than granting one; at the moment it can only block
MANAGE ACCESS CONTROL. It applies wherever governed tags match and beats every grant, ownership too, though it never restricts metastore admins. - GRANT policy
An ABAC policy that hands out a Unity Catalog privilege automatically whenever governed tags on an object satisfy its condition. It can only add access, never take away a privilege granted directly.
- System tags
Governed tags that Azure Databricks defines in advance, for example
system.certification_statuswith valuescertifiedordeprecated, and theclass.*classification tags. Their keys and values are fixed, though who can apply them can be controlled. - Unity Catalog ABAC
Attribute-based access control: policies on catalogs, schemas or tables pick objects via governed tags and automatically enforce GRANT, DENY, column masks or row filters. Azure role-assignment conditions are something else.