Showing posts with label Tenant settings. Show all posts
Showing posts with label Tenant settings. Show all posts

Friday, August 22, 2025

Changes to Fabric Tenant Settings for API's

If you are a Fabric Administrator, either for your own tenant / company or for customers, you might get the weekly emails from Microsoft 365 Message center. I've mentioned this briefly in an earlier post about Changes to default values for a tenant setting for SQL Database.

I advice you to at least have a look through that weekly email and check for any Fabric or Power BI updates. An example update you can get is like the below. This screenshot is actually from the Message Center itself, not from the email.



The problem with the M365 Message Center is that only people with privileged roles can access it. And not all updates shown there are communicated in other ways by Microsoft. Sometimes they write a blog post, like this one: Cognitive services and Azure ML will be fully retired, sometimes there's a specific info message in Fabric, or there might be a new tag in the tenant settings, but more often you don't see any other communications around the topic.

So if you are not a Fabric Admin, you probably haven't seen the message I want to inform you about today, so that's why I'm writing this post!


Call To Action

TL;DR

Two new admin toggles are live in the Fabric Tenant Settings, under Developer settings. Check your Tenant Settings and see how they relate to your policies and governance!


Action Required on API Access Setting Split

Microsoft Fabric is changing how service principal access to public APIs is controlled. The existing all-or-nothing tenant setting was split into two separate settings — giving us admins more granular control, but also introducing a change you might need to act on after August 1, 2025.


The previous setting


What Has Changed?

From mid-May to early June 2025, the previous admin setting for public API access via service principals was replaced with:

  1. Service principals can create workspaces, connections, and deployment pipelines
    → Governs “global” APIs not tied to specific Fabric permissions (e.g., workspace creation).
    Disabled by default.

  2. Service principals can call Fabric public APIs
    → Governs APIs protected by the Fabric permission model (CRUD access to workspaces, folders, etc).
    Enabled by default.

The new settings


Why This Matters

This split is a long-needed improvement: previously, disabling API access to protect core resources also blocked developers from using safe, permission-based APIs.

Now, you can lock down the high-risk parts (like workspace creation) without blocking everything else.

But: Microsoft may have enabled the second setting (permission-based API access) by default in your tenant unless you opted out.

Why should I care? You might have service principals running scripts to create workspaces, deploy certain items or manage workspace objects for example.

What You Should Do Now

  • Check your Fabric admin portal for the two new settings under Developer Settings

  • Before August 1, 2025, you could've shown a checkbox labeled "Accept Microsoft’s change to enable...", and you want to keep permission-based API access disabled, uncheck the box and hit Apply

  • Check the values of both settings

Timeline Recap

  • May–June 2025: Settings split rolls out

  • July 31, 2025: Last day to opt out of automatic enablement

  • August 1, 2025: Microsoft finalizes the transition


Conclusion

In case you are running a monitoring solution that keeps a history of Tenant Settings, for example FUAM, you can check the Tenant Settings history and see when the change became active in your tenant. If you don't have such a monitoring solution, I highly recommend checking FUAM out. You can get started with setup and deployment of the solution with a few hours of work.

I spotted this setting shift on telemetry around June 1 in my tenant:


There were some changes in how tenant settings can control access for Service Principals to API's. Make sure to check your settings and adjust them accordingly.
If you want to read more info on the exact workings of the tenant settings, have a look at the Tenant Settings documentation.

Did you already notice these changes and take action?
Let me know in the comments.

Friday, May 2, 2025

There's No Free Lunch - (Billing of) Preview Features in Fabric

Another post on my favorite topic: Governance and Administration!

With all the Fabric announcements in the last months, some of the Admin announcements might have slipped through. As you might know, the Admin part of Fabric is dear to my heart. I've posted about it earlier hereherehere, and here, to name a few 😀.

So in the next weeks I am going to highlight a few things with short, informative posts.

I decided to leave "Governance & Administration" out of the titles of my blog posts from now on.
The titles were getting a bit lengthy, just because I wanted to include the focus on Governance & Administration. I am already using labels which you can use for that: Governance, Administration, etc..

Today, let's talk about preview features in Fabric!

Preview features

First of all, when using Preview features in Fabric, you should be aware of the small print.
Next, we all know, there's no such thing as a free lunch, right?

Because: preview does not mean free! Let me explain.

Two of those preview features - SQL Database and Workspace Monitoring - have recently moved to a charging model as Fabric develops further. It's essential to understand these adjustments if you want to maximize your resources, govern your capacity and efficiently control expenses.

Fabric SQL Database


I wrote about it earlier when they were about to change the tenant setting for SQL Database: you should be aware that billing for SQL Database already started.

Compute and data storage for SQL databases are now charged according to your Fabric capacity beginning of February 1, 2025. The start date of backup billing is April 1, 2025. You can only pay for the resources you use because compute charges only apply when you are actively using the service. Automatic backups and storage are priced individually each month. Check Microsoft Learn for more details on billing and utilization reporting.

If you check the doc's on the usage of SQL Database you can see that:
1 Fabric capacity unit corresponds to 0.383 Database vCores, or, 1 Database vCore corresponds to 2.611 Fabric capacity unit.
For example, a Fabric capacity SKU F64 has 64 capacity units, which is equivalent to 24.512 SQL database vCores.

Compute is billed by the minute, but the database is also kept alive for 15 minutes afterwards. So if you use it for 4 minutes, you are actually billed for 19 minutes!
Storage will be billed per hour, regardless of usage.


Workspace Monitoring


Workspace Monitoring gathers and arranges logs and metrics from different Fabric components by building an Eventhouse database inside your workspace, providing insightful data about workspace performance and usage.
You can use this tool to optimize queries, minimize data downtime, investigate mistakes, and fix performance concerns.

As of February 2025, Workspace Monitoring billing has begun. Make sure you have a Power BI Premium or Fabric capacity and that the required tenant settings are set up in order to enable monitoring in your workspace. Check Microsoft Learn for a detailed tutorial on how to enable and use Workspace Monitoring.

Check your usage after this changeover


It is crucial to examine your present and anticipated consumption in order to foresee any expenses now that invoicing for these functions has been activated. To keep an eye on capacity utilization across all workloads and make sure it fits your organization's demands and budget, use the Fabric Capacity Metrics app
See Fabric capacity billing guidelines for a more thorough explanation of how these modifications affect your Azure bill.

Are you using these preview features in your tenant?
And did you know they are already billed?
Let me know in the comments!

Friday, February 28, 2025

Changes to the Default Tenant Setting value for SQL Database

Another post on my favorite topic: Governance and Administration!

With all the Fabric announcements in the last months, some of the Admin announcements might have slipped through. As you might know, the Admin part of Fabric is dear to my heart. I've posted about it earlier hereherehere, and here, to name a few 😀.

So in the next weeks I am going to highlight a few things with short, informative posts.

I decided to leave "Governance & Administration" out of the titles of my blog posts from now on.
The titles were getting a bit lengthy, just because I wanted to include the focus on Governance & Administration. I am already using labels which you can use for that: GovernanceAdministration, etc..

UPDATE 2025-03-12:

Microsoft released an update on the rollout of the changes to this setting. The actual enablement is postponed for 20 days to March 28. The timelines mentioned in the blog below are now:

  • February 28, 2025 - Checkbox notification rolled out globally.
  • March 8, 2025 -  Infobox will display this as the enablement date.
  • March 28, 2025 Actual enablement date for tenants that take no action.

Extending flexibility: default checkbox changes on tenant settings for SQL database in Fabric


Microsoft 365 Message Center

In case you have access to the M365 Admin Center, or more specific the M365 Message Center, you might have seen this message. I reckon not many people did.. That's why I'm blogging about it here 😁

I'm specifically talking about this message in the Message Center, being a major update and with admin impact

Changes to SQL Database Tenant Setting

Recently, there's been a change to the tenant setting for SQL Database, but only in case you haven't changed the setting before.. 😉
Below is the setting in my own tenant, where the setting is still disabled, which was and still is the default option (hint: this is about to change!).


So if I do nothing, then after March 8, the default value will change to ON, or Enabled for the entire organization.
If I decide to opt out before March 8, so if I uncheck the checkbox Accept Microsoft's default selection (Off for the entire organization), this tenant setting will stay disabled, also after March 8.

To be clear, as I mentioned, you only see this message if you haven't changed the default setting (off).
In the Powerdobs tenant we already enabled SQL Database, so I only see the below:


M365 Message Center for Non-Admins

In case you don't have access to the Message Center, I found another site, called the Microsoft 365 Message Center Archive, where all those messages are replicated, set up by Merill Fernando, Principal Product Manager for Microsoft Entra.


Direct link to the message: https://mc.merill.net/message/MC996579.

I have been searching for a (regular) blog post on this topic, but I haven't seen anything:
Multiple other blog posts were written on the Fabric blog, but none of them explicitly mentioned any of this:

Billing for SQL Database (preview)

Last thing I want to explicitly call out in accordance with the changed tenant setting:
While SQL Database in Fabric is still in preview, billing already started at February 1. Furthermore, billing for backup starts after April 1.

So when the setting is changed to ON, and you don't run a trial, you can start seeing SQLDbNative on your Capacity Metrics App as explained here. 😉

Friday, April 19, 2024

Governance & Administration - Tenant Settings: Searching

With all the Fabric announcements in the last months, some of the Admin announcements might have slipped through. As you might know, the Admin part of Fabric is dear to my heart. I've posted about it earlier here, here, here, and here, to name a few 😀.

So in the next weeks I am going to highlight a few things with short, informative posts.
You can find other posts in the series here:

Monday, March 4, 2024

Governance & Administration - Tenant Settings: Visual Cues

With all the Fabric announcements in the last months, some of the Admin announcements might have slipped through. As you might know, the Admin part of Fabric is dear to my heart. I've posted about it earlier hereherehere, and here, to name a few 😀.

So in the next weeks I am going to highlight a few things with short, informative posts.

You can find other posts in the series here:


Featured Post

Power Apps or Translytical Task Flows?

I think I have gotten this question at least five or six times in the last few months, and with Translytical Task Flows reaching GA in the M...