About fabric-lens: Microsoft Fabric governance and tenant auditing
How workspace health scoring, the security audit, and capacity monitoring work, and what access each one needs.
What is fabric-lens?
fabric-lens is a free, open-source governance and health intelligence dashboard for Microsoft Fabric tenants. It connects directly to the Fabric and Power BI Admin APIs using your existing Azure AD credentials. No backend server, no data export, no third-party data handling. Every API call runs in your browser, so tenant data never leaves your session. It is designed for Fabric administrators and Microsoft data platform consultants who need a fast, structured way to audit a tenant's workspace hygiene, security posture, and capacity utilisation.
Key capabilities
Every workspace scored across 9 governance checks, from capacity assignment to tag coverage. Grades A through F with drill-down.
Access concentration, SPOF workspaces, SPN governance, widely shared objects, ghost workspace detection, and tenant settings risk.
Live SKU pricing, CU allocation, and workspace distribution across all capacities in the tenant.
Surfaces high- and medium-risk tenant settings that are currently enabled (e.g. Publish to Web, external sharing).
Identifies reports, dashboards, and semantic models shared via organisation-wide links.
Fully functional with realistic mock data. No Azure tenant or credentials required; share a link and it just works.
How to use this site
Demo mode (no credentials needed)
- 1The app opens in demo mode automatically. No login or credentials needed.
- 2Explore the Dashboard to see health grade distribution and governance issues.
- 3Open the Security page and click "Scan All" to run the full security audit against mock data.
- 4Browse the Workspaces and Capacity pages to see inventory and cost breakdowns.
- 5Use the demo as a walkthrough script when introducing the tool to a client.
Live mode: connected to your Fabric tenant
- 1Click "Sign in to tenant" in the top-right corner.
- 2Authenticate with a Microsoft account that has Fabric Administrator role in your tenant.
- 3Workspaces and capacities load automatically. Open Security → Scan All for the full audit.
- 4Export workspace data as CSV or JSON using the export button on any data table.
What you need for a Fabric tenant audit
Required permissions
- Fabric Administrator role in the target tenant, required for admin API access (workspace users, tenant settings, scanner API)
- A Microsoft account in the target tenant, or a guest account with Fabric Admin role assigned
Note on consent prompts: fabric-lens requests only the scopes it needs, when it needs them. Core Fabric and ARM scopes are requested on sign-in. Admin API scopes are requested the first time you visit the Security or Settings page. Group expansion (Microsoft Graph) is opt-in from Settings. You will see a Microsoft consent prompt once per scope, not on every page visit.
Fabric workspace health scoring explained
Every workspace is scored across nine governance checks, worth a combined maximum of 110 points when the workspace has items (100 points when empty; tag coverage is skipped). The score is normalised to a percentage and converted to a letter grade.
| Check | Points | Note |
|---|---|---|
| Assigned to a capacity | 15 | Critical |
| Workspace identity configured (SPN + Git) | 25 | Critical |
| Has a description | 10 | Critical |
| Assigned to a domain | 10 | — |
| Follows naming convention | 10 | — |
| Contains at least one item | 10 | — |
| Includes a data layer (Lakehouse/Warehouse/Semantic Model) | 10 | — |
| Reasonable item count (< 100) | 10 | — |
| Tag coverage ≥ 80% of items | 10 | Skipped if no items |
Fabric tenant security audit explained
The security audit runs when you click "Scan All" on the Security page. It requires Fabric Administrator role for most checks. The overall posture score is a weighted composite of individual check results, expressed as a percentage.
Access concentration
Identifies workspaces with an unusually high proportion of Admin-role assignments relative to total members.
Single point of failure (SPOF) workspaces
Workspaces where only one user holds the Admin role. If that user leaves, the workspace becomes unmanageable.
Service principal governance
Surfaces service principals with Admin or Member roles across workspaces, useful for auditing automation access.
Tenant settings risk
Flags high- and medium-risk tenant settings that are currently enabled, such as Publish to Web or external sharing options.
Widely shared objects
Lists reports, dashboards, and datasets shared via organisation-wide links using the Power BI Admin API.
Ghost workspace detection
Finds workspaces with no recorded user activity in the last 28 days, the full retention window of the Power BI audit log.
Demo mode
No credentials needed. The app opens in demo mode automatically, with a complete audit of a realistic mock Fabric tenant: 35 workspaces, 3 capacities, 200+ items across 21 item types, and pre-loaded security findings.