Docs · updated October 2026

Connecting your tenant

Fabriscope signs in to your tenant as one service principal that your admins create and control. About 15 minutes of work, plus up to 15 minutes for a tenant setting to apply.

1. Create the app registration

In Entra ID → App registrations → New registration, register an app with any name, for example fabriscope. It needs no redirect URI. Under Certificates & secrets, create a client secret and copy its value; you paste it once, under Settings → Connection.

Note the Application (client) ID and the Directory (tenant) ID from the app's overview.

2. Microsoft Graph permissions (optional)

Only Report Audience uses Microsoft Graph, for two things: Pro and Premium Per User licences, and the people inside an Entra group that holds access to a report.

APIPermission (application)Used for
Microsoft GraphUser.Read.All, Organization.Read.AllLicences: who holds a Pro or PPU seat
Microsoft GraphGroupMember.Read.AllThe people inside a group, nested groups included

Grant admin consent. Without them, the Licences page says it is unavailable and a group grant shows as the group rather than its people.

3. Allow the read-only admin APIs

In the Fabric admin portal → Tenant settings, create a security group (for example sg-fabriscope) containing the service principal, and enable Service principals can use read-only admin APIs for that group. This is required: both products read the inventory, access and audit log through it.

The two Enhance admin API responses with detailed metadata settings are not needed. Tenant settings take up to 15 minutes to apply.

4. Contributor on the workspaces to document

For the Data Catalog, add the service principal as Contributor on each workspace to document: Workspace → Manage access → Add people or groups. Include the workspaces your code writes into, not only those that hold the code. Report Audience needs no workspace role at all.

5. Connect

Under Settings → Connection, enter the directory (tenant) ID, the application (client) ID and the secret value, then choose Connect. The secret is encrypted and never shown again; enter a new one there to rotate it.

The page then checks each part live:

CheckNeeded forIf it fails
Read-only admin APIsBoth products — requiredStep 3 has not applied yet, or the principal is not in the group
Fabric REST APIData Catalog: items and codeStep 4: the principal has no role on the workspaces
OneLakeData Catalog: tables and the Delta logStep 4: Contributor on the workspace
Microsoft GraphReport Audience: licences, group membersStep 2 — optional

Changed a setting? Use Re-validate; Microsoft can take 15–60 minutes to apply a change.