Category Microsoft Fabric – Administration / Governance / CI-CD Business Need Many enterprise customers use Service Principals (SPNs) for CI/CD deployment automation in Microsoft Fabric. As part of security compliance, organizations periodically rotate, replace, or decommission Service Principals. Currently, Fabric items such as Data Pipelines, Notebooks, Lakehouses, Warehouses, Environments, and other artifacts retain ownership metadata associated with the identity that originally created them. There is no unified mechanism to transfer ownership of existing Fabric items from one Service Principal to another Service Principal. This creates operational challenges when an existing Service Principal must be retired. Current Challenges Existing Fabric artifacts remain owned by the old SPN even after redeployment using a new SPN. Customers are often required to recreate or redeploy artifacts to establish new ownership. Large production environments may contain hundreds or thousands of Fabric artifacts, making recreation impractical. Decommissioning old Service Principals becomes risky due to ownership dependencies. This increases governance, operational, and compliance overhead for enterprise customers. Requested Enhancement Provide a supported mechanism to transfer ownership of Fabric items from: Service Principal → Service Principal User → Service Principal Service Principal → Workspace Identity Service Principal → Managed Identity The capability should be available through: Fabric Portal (GUI) REST APIs PowerShell/Automation Bulk ownership migration across a workspace Suggested Features Workspace-level ownership reassignment wizard. Bulk transfer of ownership for all artifacts within a workspace. Validation report showing impacted artifacts before transfer. Audit logs tracking ownership changes. Support for rollback. Support for CI/CD automation scenarios. Expected Benefits Simplifies Service Principal rotation and credential lifecycle management. Improves enterprise governance and security compliance. Reduces downtime and migration effort. Eliminates the need to recreate production artifacts. Enables scalable DevOps and CI/CD practices in Microsoft Fabric. Example Scenario An organization migrates from an existing Service Principal to a new Service Principal for CI/CD deployments. While deployments succeed using the new identity, ownership of existing Fabric items remains linked to the old Service Principal. When the old Service Principal is decommissioned, customers face operational and support challenges. A direct ownership transfer capability would resolve this problem without requiring artifact recreation. Impact High This affects enterprise customers operating production Microsoft Fabric environments with automated DevOps, security-driven Service Principal rotation policies, and large-scale deployments. #Fabric #ServicePrincipal #CI/CD #Governance #OwnershipTransfer #Administration #WorkspaceManagement #DevOps #Security #Enterprise
... View more