5 Governance Gaps in Your Fabric Tenant Creating Compliance Exposure and Remediation Costs

If you're running Fabric at scale, you have undetected governance gaps—orphaned workspaces, exposed reports, missing labels—creating compliance exposure, unplanned remediation costs, and data breach risk.

I've audited Fabric tenants across enterprises and growth-stage companies. The pattern is always the same: governance problems exceed what leadership expects. In a recent 5,000-workspace tenant scan, we found 100% lacked designated admins—creating immediate compliance liability and unplanned remediation costs.

Not because anyone's negligent. Power BI was designed to let business users build and share analytics fast. The problem is that "fast" and "governed" rarely go together, and by the time you've got thousands of workspaces, the sprawl has already happened.

Here are five red flags that tell you it's time to look under the hood.

1. 100% of Unaudited Workspaces Lack Designated Admins—Creating Compliance Liability and Remediation Costs

This is the most basic question, and most organizations can't answer it confidently. In a recent scan, we found 5,000 workspaces—100% without designated admins, creating compliance liability and remediation costs. Thousands of reports, semantic models, and dashboards lack clear ownership, assigned responsibility, and governance enforcement.

If your IT team has to manually check the admin portal to answer "how many workspaces do we have?" — that's a sign.

2. Publish to Web Exposure: 125+ Reports Openly Accessible—Creating Data Breach and Compliance Risk

Publish to Web is one of the most dangerous features in Power BI, and most organizations have no idea how exposed they are. It creates a public URL for a report — no authentication required, no expiration, accessible to anyone on the internet.

In the same tenant scan, we found 125 reports published to the public internet. Some of those contained operational data that had no business being publicly accessible. One report had been published three years ago and forgotten entirely.

If you haven't specifically audited Publish to Web artifacts in the last 90 days, assume you have exposure.

3. Sensitivity Labels at 0%: Missing Classification Creates Compliance and Breach Risk

Microsoft Information Protection labels are one of your strongest governance tools — they classify and protect data at the artifact level. But in our experience, the vast majority of enterprise tenants have zero sensitivity label coverage.

Zero. On thousands of datasets.

That means your DLP policies have nothing to enforce. Your compliance team is flying blind. And if you're subject to SOX, HIPAA, or GDPR, this is a gap that shows up in audits. The good news is that it's fixable — but you have to measure it first.

4. Row-Level Security Policies Exist But Aren't Audited—Creating Unenforced Access Control and Compliance Risk

Most organizations know what RLS is. Many have it documented in their governance guidelines. But when we scan semantic models, the actual adoption rate is almost always near zero.

In the tenant we scanned, 1,169 semantic models had no Row-Level Security configured. That means every user with access sees every row of data. In organizations with sensitive financial, HR, or customer data, that's a compliance risk hiding in plain sight.

The fix isn't hard. But if you don't know which models have RLS and which don't, you can't prioritize.

5. Pre-Migration Governance Gap: Deploying Fabric Without Auditing Current Access Controls and Compliance Policies

Fabric is an incredible platform. But migrating without understanding your current state is like packing for a move without opening the closets first. You'll bring the mess with you.

A real tenant scan gives you visibility into everything: your 8,900+ Fabric items (notebooks, pipelines, lakehouses), your data source connections, your CI/CD maturity (Git adoption, deployment pipelines), your compliance posture, and a Fabric Readiness Score that tells you exactly where you stand on a 0-100 scale.

That score becomes your baseline. Run the scan again in six months and you can prove to leadership that governance actually improved.

What to do about it

If any of these resonated, the next step is straightforward: get a Tenant Scan. It's a read-only, non-invasive assessment that scans 70+ data points across your entire Power BI and Fabric environment. No agents to install. No data leaves your tenant.

You walk away with a Fabric Readiness Score, a complete inventory of every artifact in your tenant, a data exposure audit, compliance mapping, and a prioritized remediation plan your team can actually execute on.

The Starter tier starts at $2,500 and is delivered in 3–5 days. Professional ($5,000) includes a deeper architecture review and 90-day governance roadmap. Enterprise ($7,500) adds compliance mapping, ROI modeling, and migration waves. For AI-powered analysis with a live working session, the AI-Assisted tier is $12,500.

Gastón Cruz
Gastón Cruz is Co-Founder & Managing Partner of The Power Mates and a Dual Microsoft MVP (Data Platform & AI). He's spent 20+ years designing enterprise data platforms for Fortune 500 companies and leads every Tenant Scan engagement personally.

Identify hidden governance gaps before they create compliance violations, unplanned remediation costs, and data breach risk.

Get a Fabric Readiness Score and a prioritized action plan — delivered in 3-5 days.

Learn About Tenant Scan →