A service principal, with its own app registration, that Fabric manages automatically for a single workspace and that only a workspace Admin can create. Items use it to sign in to resources protected by Microsoft Entra, and trusted workspace access depends on it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Workspace identity in context, with comparison tables and the common traps.
Terms in this definition
- Service principal
The tenant-local instance of a managed identity or app registration, which users and Azure or directory roles are assigned to. Those from app registrations authenticate with a stored certificate or secret that needs rotating and can be copied, which suits code running outside Azure.
- App registration
Object in Microsoft Entra ID describing an app's identity, the permissions it needs and which account types it supports; multi-tenant apps and OpenID Connect sign-in depend on it.
- Workspace
Teams in Power BI and Microsoft Fabric collaborate in this folder-style container, which groups items such as reports, semantic models and lakehouses, controls who can access them and is assigned a capacity.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- Trusted workspace access
Firewalled ADLS Gen2 or Blob Storage becomes reachable, via resource instance rules, from workspaces holding a workspace identity, whether through shortcuts, pipelines, COPY INTO, AzCopy or Import semantic models. Only paid F SKUs qualify; trials don't.
Related terms
- Fixed identity
With single sign-on off, a Direct Lake model can be bound to one explicit cloud credential, such as a workspace identity or service principal. Permissions, RLS and CLS are then evaluated for that credential, not per viewer, so readers need no rights on the underlying item.
- Resource instance rule
A firewall rule on an Azure Storage account that trusts one particular Fabric workspace, identified by its workspace identity. You can't add it in the portal, only through ARM or PowerShell, and the resource ID must use 00000000-0000-0000-0000-000000000000 as the subscription.
- Trusted service exception
Admits into a firewalled storage account any workspace holding a workspace identity across that tenant's Fabric capacities. Microsoft advises against this option, preferring resource instance rules naming particular workspaces.