This time we’re going bigger than ever. Fabric, Power BI, SQL, AI and more. We're covering it all. You won't want to miss it.
Learn moreDid you hear? There's a new SQL AI Developer certification (DP-800). Start preparing now and be one of the first to get certified. Register now
Co-author: Meenal Srivastva
Managing secure, seamless access to data sources is a top priority for organizations using Microsoft Fabric. With workspace identity authentication, teams can simplify credential management, enhance security, and streamline data access across their enterprise.
Workspace identity in Fabric is an automatically managed service principal associated with workspaces (excluding My Workspaces). When you create a workspace identity, Fabric generates a service principal in Microsoft Entra ID, enabling seamless authentication and trusted access to firewall-enabled storage accounts.
Workspace Identity Authentication in connections leverages Microsoft Entra ID (formerly Azure Active Directory) to provide seamless, secure access to data sources using your workspace's managed identity. This modern authentication approach in Microsoft Fabric eliminates the need for storing credentials while providing fine-grained access control and comprehensive audit capabilities.
For more details, refer to the Workspace identity documentation.
Recently, we announced Fabric Workspace Identity: Removing Default Contributor Access for Workspace Identity changes with respect to the default contributor role previously assigned to Workspace identity during creation. As of July 27, 2025, a new Workspace Identity created in your workspace will no longer have default roles on the workspace. Existing workspace identity will no longer have the contributor role; Admins can always assign roles explicitly to workspace identity.
Expanded support for workspace identity in new connectors for Data pipeline, semantic models, and Dataflow Gen2 (CI/CD).
With Workspace Identity authentication, Data pipelines, Copy job, semantic models, and Dataflows Gen2 can connect to data sources, eliminating the need for managing credentials and enabling centralized, secure access control.
The following table shows workspace identity authentication availability in connectors across different fabric items:
Legend:
- 'x' - Available
- 'N/A' - Not applicable due to connector not supported by the runtime
| Connector | Copy Job | Data Pipeline | Dataflow Gen2 (CI/CD), Semantic Models |
|---|---|---|---|
| Azure Analysis Services | N/A | N/A | x |
| Azure Blobs | x | x | x |
| Azure Cosmos DB (SQL API) | x | x | x |
| Azure Data Explorer (Kusto) | x | x | x |
| Azure Data Lake Storage Gen1 | N/A | x | N/A |
| Azure Data Lake Storage Gen2 | x | x | x |
| Azure Synapse Analytics | x | x | x |
| Azure Synapse Workspace | N/A | x | N/A |
| Azure Tables | x | x | x |
| Dataverse | x | x | x |
| Dynamics 365 | N/A | x | N/A |
| Dynamics AX | N/A | x | N/A |
| Dynamics CRM | N/A | x | N/A |
| SharePoint | x | x | x |
| SQL Server | x | x | x |
| Viva Insights | N/A | N/A | x |
| Web | N/A | N/A | x |
In this example, we will demonstrate how to use workspace identity in Microsoft Fabric Dataflows Gen2 for authentication to Azure Blob Storage. While the steps for using workspace identity remain the same across different connectors, the procedures for granting permissions to data sources may vary.
Creating a workspace identity is straightforward and can be done in the workspace settings of any workspace except personal workspaces (My Workspace):
You can also create the workspace identity using the Workspaces – Provision Identity REST API. Workspace admins can create and delete the workspace identity. Admins, members, and contributors can configure workspace identity as an authentication method in supported items, such as Dataflows Gen2.
To enable the workspace identity to access Azure Blob storage accounts:
Workspace_Identity_auth_selection_in_Connection_creation_in_Dataflow_Gen2
Check out the new updates and provide your feedback through comments on this post or Fabric Ideas.
To learn more about this feature, refer to the Authenticate with workspace identity documentation. Ready to try it out? Explore the new connectors, share your feedback, and help shape the future of Microsoft Fabric!
We will continue to add support for new connectors or data sources along with workspace identity authentication. Stay tuned for product announcements and updates.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.