Series: Getting Started & Tenant Foundations
Tenant settings are where good governance intentions either get implemented or quietly forgotten.
A bigger catalog than five.
Article 3 covered the headline settings almost every tenant touches first, but the full tenant settings screen runs past 30 categories, from information protection to advanced networking. You won’t master all of it on day one, but knowing what’s there keeps you from being caught flat-footed later. Skim the full list once, even if you’re not ready to configure most of it, just so nothing surprises you when a business unit asks for a capability you didn’t know existed.
Sharing has layers underneath.
Beyond the basic “share externally” toggle, separate settings govern whether guests can accept external data shares, browse Fabric content freely, or appear in people-picker suggestions. Turn on only what a real business case needs, and leave broad guest browsing off until you’ve thought through what it exposes. Each of those sub-settings answers a slightly different question, so read the description carefully before assuming one toggle covers what you think it does.
Export isn’t one switch.
Export to Excel, CSV, PDF, PowerPoint, and image files are each separate toggles, and Export to Excel is on by default because sensitivity labels travel with it. Copy-and-paste of visuals and Publish to Web are off by default for good reason — the latter makes a report public with no login required, so leave it alone unless you have a genuine public-facing need. It’s worth periodically checking who has actually turned on Publish to Web, since a forgotten public link is one of the more embarrassing ways sensitive data leaks out.
Information protection sets the ceiling.
Sensitivity labels, auto-applying labels inherited from data sources, and restricting labeled content from link sharing all live here, and matter more once real customer or financial data lands in Fabric. If your organization already uses Purview labels elsewhere in Microsoft 365, extending them here early saves a painful relabeling project later. Getting labeling consistent from day one is far cheaper than retrofitting it across hundreds of reports after the fact.
Developer settings shape automation.
Whether service principals can create workspaces or call Fabric’s admin APIs is worth deciding deliberately, since it shapes how your future CI/CD pipelines will work. Leave these off until an actual app or pipeline needs them. Turning them on preemptively just widens your attack surface for no immediate benefit.
Networking and encryption can wait.
Tenant-level private link, blocking public internet access, workspace firewall rules, and customer-managed encryption keys are real capabilities, but they assume a security team that’s already defined requirements. Flip these on too early and you’ll troubleshoot connectivity more than you’ll protect anything. These are the settings to revisit once security, not IT alone, has a specific requirement driving the change.
Treat this catalog like a menu, not a checklist. Enable what solves a real, current problem, note what you’re leaving off intentionally, and revisit the rest once governance catches up with the technology.
To learn more: Tenant settings index · Export and sharing tenant settings · Workspace admin settings · Enable and configure Copilot in Microsoft Fabric · Microsoft Fabric admin overview (all Microsoft Learn)
This post is part of the Fabric & Power BI Essentials series — see the full series intro and article list there.
← Previous: Adding users, licenses and guest access | Next →: Planning Your Fabric Rollout: Pilot vs. Enterprise-Wide Adoption Strategies