Current behavior Today, Microsoft Fabric controls item creation through a single tenant or capacityโlevel setting: โUsers can create Fabric items.โ This setting works on an allโorโnothing basis: When enabled, users can create all Fabric item types in a workspace. When disabled, users cannot create any Fabric items. There is currently no supported way to selectively allow or block specific Fabric item types (for example, allowing users to create only reports but not Lakehouses, Warehouses, Pipelines, etc.). Problem / customer impact Many organizations have strong governance and separationโofโduties requirements. Common scenarios include: Allowing report developers to create only Power BI reports Allowing data engineers to create data engineering objects only Preventing accidental creation of highโimpact objects (e.g., Warehouses, Lakehouses, Pipelines) Because item creation is allโorโnothing, admins are forced to: Overโrestrict users (Viewer role), or Overโexpose capabilities that users should not have This creates friction, governance risk, and additional administrative overhead through workarounds such as multiple workspaces per persona. Requested enhancement Provide granular creation controls that allow admins to: Enable or disable specific Fabric item types per tenant, capacity, or security group Align Fabric permissions more closely with realโworld organizational roles Improve governance without limiting adoption or usability Benefits Stronger security and governance Better role separation without workspace sprawl Reduced risk of unintentional resource creation Improved admin and customer experience
... View more