Microsoft Fabric: Removing default contributor access for Workspace Identity
Microsoft Fabric is removing default Contributor access for Workspace Identities to enhance security. This change will be rolled out from mid-July to early August 2025. Admins can still manually assign roles using RBAC. Review and update your configurations and notify relevant personnel. Learn more [here](https://learn.microsoft.com/fabric/security/workspace-identity). To strengthen security and align with customer feedback, Microsoft Fabric is updating how Workspace Identity permissions are handled. This change removes default Contributor access from Workspace Identities, reducing the risk of unintended access or misuse. This change will be on by default. When this will happen: General Availability (Worldwide): We will begin rolling out mid-July 2025 and expect to complete by early August 2025. How this will affect your organization: After this rollout, new Workspace Identities will no longer be granted default Contributor permissions. We will also remove the default Contributor access from existing Workspace Identities. Important: Modifying the application associated with a Workspace Identity is not supported and may cause the identity to stop functioning. You can still manually assign Workspace Identity service principals to any workspace role (such as Contributor, Member) using role-based access control (RBAC). However, be aware that anyone with access to the identity can assume it. To access this change: Navigate to the Fabric Workspace where you want to add RBAC role. Select Manage Access. Select Add people or groups. Enter the name of the Workspace identity (same as Workspace Name). Assign roles as appropriate. NOTE: After this rollout, admins can still add Workspace identity service principles to any workspace RBAC role if needed. Consider the implications if you plan on doing so, as any individual given access to the identity—example through workspace roles such as member or contributor—is allowed to assume the identity. Learn more: Workspace identity – Microsoft Fabric | Microsoft Learn What you need to do to prepare: This rollout will happen automatically by the specified dates with no admin action required before the rollout. Review your current Workspace Identity configurations and evaluate whether any existing workflows rely on default Contributor access. You may want to notify your admins and/or users about this change and update internal documentation. […]
The post Microsoft Fabric: Removing default contributor access for Workspace Identity appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Fabric: Removing default contributor access for Workspace Identity
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft Copilot (Microsoft 365): Local inferencing
Local inferencing expands Microsoft Copilot’s sovereign controls by enabling AI inferencing for supported Copilot interactions to occur within...
Dynamics 365 Customer Service: Quality evaluation supports knowledge source in criteria
Criteria questions can now use knowledge sources to help evaluate customer interactions. This allows organizations to ground evaluation criter...
Microsoft Viva: Ability for leaders to publish Power BI reports
Microsoft Viva Insights is extending its report publishing capabilities from analysts to leader personas such as Chief Officers, Managers and ...
Dynamics 365 Customer Service: Detailed quality evaluation score breakdown
Evaluation details now include a scoring breakdown at the overall, section, and question level. Users can see how the final evaluation score w...
Dynamics 365 Customer Service: Support Not Applicable answer option for quality evaluation criteria
Criteria questions now support a Not Applicable answer option. When a question is marked as not applicable, it is excluded from scoring instea...
Dynamics 365 Customer Service: Inactivate quality evaluation records
Quality managers can now inactivate evaluation records that should no longer contribute to scoring or reporting. Inactive evaluations are pres...
Microsoft Teams: Granular Conditional Access for Teams meetings
Granular Conditional Access for Teams meetings gives organizations greater control over access to sensitive meetings. Administrators can apply...
Customized PowerBI reports behavior after major report updates
Microsoft Viva Insights customized Power BI reports will remain tied to their original report versions and won’t auto-update with major report...
Microsoft SharePoint: Changes to the FAQ web part authoring experience
The SharePoint FAQ web part will shift AI-assisted FAQ creation to Copilot in SharePoint, while retaining manual FAQ editing in the web part. ...
Microsoft 365 Copilot: Federated Copilot connectors support create, update, and delete actions
Microsoft 365 Copilot’s federated connectors will support create, update, and delete actions in third-party services starting October 20...