Skip to content

Latest commit

 

History

History
163 lines (115 loc) · 11 KB

File metadata and controls

163 lines (115 loc) · 11 KB

Purview - Best Practices Overview

Costa Rica

GitHub GitHub Cloud2BR OSS - Learning Hub

Last updated: 2025-05-05


Use the Purview hub in Fabric to monitor sensitivity labels, DLP activity, and data access. Regularly review audit logs to detect anomalies and ensure compliance with internal and external regulations.

List of References (Click to expand)
Table of Content (Click to expand)

Note

Below is how to upgrade from Free account.

Purview Free: Provides basic data governance capabilities, suitable for small-scale or initial exploration of Purview’s features. It includes basic cataloging, limited data discovery, and basic compliance tools.
Purview Enterprise: Offers comprehensive data governance, protection, and compliance features. It supports a wide range of data sources, advanced classification, full DLP, information protection, compliance management, and seamless integration with Azure services.

Detailed Table: Free vs Enterprise (Click to expand)
Feature Purview Free Purview Enterprise
Data Catalog Basic cataloging capabilities.
Limited to 1,000 annotated assets.
Full cataloging capabilities.
No limit on the number of annotated assets.
Data Discovery Limited to Azure and Microsoft Fabric resources.
Auto discovery of Azure data sources.
Supports a wide range of data sources, including on-premises, multicloud, and SaaS applications.
Automated scans for the hybrid data estate.
Data Lineage Basic lineage tracking for a limited set of data sources. Comprehensive lineage tracking across all supported data sources.
Data Classification Basic classification capabilities.
Definition and manual application of classifications and terms.
Advanced classification with automatic labeling and sensitivity labels.
Automated application of classifications and terms.
Data Loss Prevention (DLP) Not included. Full DLP capabilities to prevent unauthorized sharing of sensitive information.
Information Protection Not included. Includes encryption and access controls to protect sensitive data.
Compliance Management Basic compliance tools. Comprehensive compliance management, including Compliance Manager and audit capabilities.
Data Quality Basic data profiling. Advanced data quality features, including quality rules and continuous monitoring.
Insider Risk Management Not included. Full insider risk management capabilities to detect and respond to potential data leaks.
eDiscovery Not included. Full eDiscovery capabilities for legal and compliance investigations.
Integration with Azure Services Limited integration with Azure services. Seamless integration with a wide range of Azure services, including Synapse Analytics, SQL, and Power BI.
Data Map Basic data map capabilities.
Manual creation of assets using the data map APIs.
Full data map with detailed visualizations and relationship tracking.
Full use of Microsoft Purview's REST APIs.
Monitoring and Reporting Basic monitoring and reporting. Advanced monitoring and reporting, including Data Estate Insights.
User Access Limited to data curators.
Role group access control to platform and apps.
Full access for all users, including data stewards and analysts.
Fine-grained, collection-level access control to platform and apps.
Support and SLA Community support. Enterprise-grade support and SLA.
Workflows Not included. Included.
Business Rules Not included. Included.
Support for Business Assets and Managed Attributes Not included. Included.
Descriptions, Tags, and Contacts Manual descriptions, tags, and contacts. Manual and bulk descriptions, tags, and contacts.
From.Purview.Free.to.Purview.Pay.as.Go.Enterprise.mp4

Unified Data Catalog

Use the Microsoft Purview Unified Catalog to automatically register and view metadata for Fabric items. This helps users discover datasets, semantic models, and reports with full lineage and context. Ensure metadata scanning is enabled across all Fabric workspaces.

Important

  • Admins can configure scanning policies and permissions in the Microsoft Purview governance portal.
  • Ensure that Fabric is registered as a data source in Purview.
  • Use role-based access control (RBAC) to manage who can view or edit catalog metadata.

Access the Purview Hub in Fabric

  • Go to the Microsoft Fabric portal

  • Click on ⚙️, select “Purview hub”.

  • This is your central place for managing governance, metadata, and data protection across Fabric.

    image
    Purview.Hub.-.get.started.mp4

Enable Metadata Scanning

Ensure that metadata scanning is enabled for all relevant Fabric workspaces. This allows Purview to automatically discover and register items like: Lakehouses, Dataflows, Semantic models, Reports

  • Scanning can be configured at the workspace level or tenant level by an admin.
  1. Configure tenant settings:

    • In the Fabric admin portal, go to Tenant Settings.

      image
    • Enable detailed metadata scanning, and allow service principal access:

      How.to.enable.detailed.metadata.scanning.in.tenant.mp4
  2. Run a scan:

    • Use the Purview portal or scanner APIs to initiate a scan.

    • You can perform full, incremental, or scoped scans depending on your governance needs.

      E.g.how.to.configure.Data.Scan.for.Fabric.with.Purview.mp4
  3. Where to monitor: Once scanning is active, go to the Purview hub in Fabric to view registered items, lineage graphs, and metadata properties.

View and Explore the Unified Catalog

  • Once scanning is active, go to the Data Map section within the [Purview hub](

  • Here, you can:

    • Search for datasets, models, and reports.
    • View metadata such as schema, owner, last modified date.
    • See data lineage (e.g how data flows from source to report).
    • Filter by sensitivity labels, endorsements, or domains.
  • Use Lineage for Impact Analysis

    • Click on any item to view its lineage graph.

    • This shows upstream and downstream dependencies (e.g., a semantic model feeding into multiple reports).

    • Use this to assess the impact of changes or troubleshoot data issues.

      How.Data.Map.looks.like.-.Unified.Catalog.mp4
  • Promote Discoverability

    • Add descriptions, tags, and endorsements to important items.
    • This helps other users find and trust the right data assets.
    • Encourage data producers to maintain metadata hygiene.

Sensitivity Labeling

Apply sensitivity labels to all Fabric items (e.g., Lakehouses, semantic models, reports) using Microsoft Purview Information Protection. Labels persist across exports and help enforce data protection policies. Regularly audit label usage and ensure labels align with your data classification framework. Click Learn about sensitivity labels.

Data Loss Prevention (DLP)

Implement DLP policies for Power BI semantic models to prevent accidental data leaks. Define rules that restrict sharing or exporting sensitive data. Monitor DLP alerts and refine policies based on usage patterns. Click to Learn about data loss prevention

End-to-End Lineage

Enable data lineage tracking to visualize how data flows from sources (e.g., OneLake, SQL, Cosmos DB) through transformations to reports. Use this to assess impact before making changes and to support compliance audits. Click Data lineage user guide

Role-Based Governance

Use tenant, domain, and workspace-level settings to delegate governance responsibilities. Platform admins should define global policies, while domain and workspace admins manage local configurations. This supports scalability and autonomy. Click Data governance roles and permissions in Microsoft Purview

Trust & Endorsement

Encourage data producers to endorse trusted datasets and models. Use tags and descriptions to improve discoverability and promote reuse. This builds a culture of data trust and reduces duplication. Click Govern your Fabric data

Total views

Refresh Date: 2025-10-15