seconds, but restructuring workspaces after people build content takes a long time. Moving content typically requires redeploying or recreating it, rebinding item IDs (reports, notebooks, pipelines), and re-sharing or rebuilding app content and saved links. Much of that rework is avoidable with a few deliberate decisions up front.
The original post lists ten design decisions to make before anyone creates a workspace. The guidance frames each decision by the available options, the factors that should drive the choice, and the Fabric platform constraints that can force or block options. The brief below covers the first three decisions in detail—region and capacity, network security posture, and who builds/owns content—because they impose constraints that are difficult or impossible to reverse later.
- Location of source data and whether integrations require same-region placement
- Data residency or regulatory requirements
- Whether you need separate capacities to isolate workloads, costs, or departments
- Dataverse Link requires a workspace capacity in the same region as the Dataverse environment.
- Fabric Copilot capacity is only supported in the tenant home region and must meet minimum capacity levels (e.g., F2 or P1). If data capacities live in other regions, plan a separate capacity to bill Copilot usage.
- Some workloads aren't available in all regions. SQL database in Fabric must be available in both tenant home and capacity regions—check region availability for items you plan to build.
Network controls can change tenant-wide behavior and degrade or disable features, so decide tenant-level vs workspace-level controls before content is created.
- Tenant-level inbound protection: Private Link, Block Public Internet Access
- Workspace-level inbound protection: workspace Private Link, workspace IP firewall rules
- Identity-based controls: Conditional Access policies requiring MFA, compliant devices, or specific locations
- Outbound access methods: managed private endpoints (with managed virtual network), gateways, or trusted workspace access
- Whether you need to block the public internet entirely, prevent unauthorized access, or reduce exfiltration risk
- Whether restrictions apply to the whole tenant or just certain workspaces
- The Fabric features your users require
- Enabling Private Link causes the first Spark or Lakehouse operation to allocate a managed virtual network, which disables starter pools and makes Spark sessions slower to start, and prevents region moves for that workspace.
Decide whether content creation and maintenance will be centralized, self-service, or hybrid. This choice affects how many workspaces you need and who administers them.
- Centralized: a central data or BI team builds everything
- Self-service: departments build and maintain their own content
If you allow self-service, define the scope clearly—what activities departments can perform, what central teams must provide, and how shared assets will be governed.