Forum Discussion
User with Contributor Role Unable to Checkout Branches or Create New Workspaces
- 1 year ago
Hi ifeanyi
-
Thank you for sharing your thoughtful workaround for managing least-privilege access in Microsoft Fabric.
-
We understand the current limitations around granular role-based permissions, especially compared to Synapse or Data Factory.
-
Using a dedicated collaboration workspace to isolate contributor access is a practical and effective solution.
In the meantime, if you're open to it, we recommend sharing your approach and suggestions on the Fabric Ideas - Microsoft Fabric Community It’s actively reviewed by the product team and helps influence future roadmap priorities.
Let us know if you’d like assistance with anything else or help streamlining your current setup further.
Thanks for being a part of Microsoft Fabric Community Forum. -
You're absolutely right—this limitation can be quite frustrating, especially when trying to maintain a least-privilege access model. It's not as straightforward as it is in Synapse or Data Factory.
To work around this, we’ve adopted a mitigation strategy by introducing an intermediary collaboration workspace. Here's how we approach it:
We start with a primary workspace, for example, contoso_wsp[Dev]. As an admin, I create a secondary workspace named contoso_collaboration_wsp. I then assign contributor users as admins to this collaboration workspace—not to the original one. This setup gives them the permissions needed to create their own development branches or workspaces (e.g., contoso_collaboration_wsp_contributor1, contoso_collaboration_wsp_contributor2, etc.).
Once their work is complete, I review and merge changes from these contributor workspaces back into the main contoso_wsp [Dev].
While it’s a bit of an overhead and certainly not ideal, this structure helps us maintain control over the dev environment while enabling contributor-level users to work independently.
That said, I’d be keen to hear how others are overcoming this challenge and whether there are any updates on how Microsoft Fabric plans to mature its support for DevOps/DataOps and CI/CD workflows.
Hi ifeanyi
-
Thank you for sharing your thoughtful workaround for managing least-privilege access in Microsoft Fabric.
-
We understand the current limitations around granular role-based permissions, especially compared to Synapse or Data Factory.
-
Using a dedicated collaboration workspace to isolate contributor access is a practical and effective solution.
In the meantime, if you're open to it, we recommend sharing your approach and suggestions on the Fabric Ideas - Microsoft Fabric Community It’s actively reviewed by the product team and helps influence future roadmap priorities.
Let us know if you’d like assistance with anything else or help streamlining your current setup further.
Thanks for being a part of Microsoft Fabric Community Forum.