Every conference keynote now has an obligatory wall of agent announcements, and FabCon 2025 — back in Las Vegas at the start of April — dutifully delivered one under the banner of "fuelling tomorrow's AI with agentic capabilities." I'll get to the agents, because some of it genuinely matters. But I want to lead with the announcement that made me actually sit up, because it's the least glamorous and, for anyone who builds real data platforms, the most important: OneLake security. Fabric is finally growing up in the one area where it most needed to.
Define it once, enforce it everywhere
Here's the problem OneLake security solves, and it's a problem I've lived. In a platform with many engines — Power BI, Spark notebooks, the SQL analytics endpoint, Excel, direct file access, API calls — securing your data has meant securing it repeatedly, once per engine, each with its own model, hoping you got them all consistent. That inconsistency is exactly where data leaks live: you lock the front door in Power BI and leave a window open in the Spark endpoint, and someone sees what they shouldn't. I wrote years ago about getting row-level security right in Power BI, and the whole anxiety of that post was that security bolted on per-surface is security you can't fully trust.
OneLake security (in preview) takes direct aim at that. You define row-level and column-level security once, at the data, using standard T-SQL, and Fabric enforces it consistently across every engine — Power BI, Spark, the SQL endpoint, Excel, the file explorer, the API. Define access once; have it hold everywhere. That is precisely the model I've argued for over and over: govern at the data, not at each report. If it works as described — and "preview" means verify before you trust it in production — this is the single most consequential thing to happen to Fabric governance since GA. It's the difference between a platform you can defend to an auditor and one you can only hope about.
Make it concrete. Picture a sensitive salary column. Before, you'd hide it in the Power BI model, restrict it in the SQL endpoint, and then quietly pray nobody queried the underlying files through a Spark notebook or pulled them via the API, because those were separate battles you might have lost. With security enforced at OneLake, the column is protected once, at the source, and every engine that touches the data inherits the restriction automatically. The number of places you can accidentally leave a door open drops from many to one. For anyone who's ever had to prove to an auditor that a restriction actually holds everywhere, that's not a convenience — it's the difference between a claim you can make honestly and one you were bluffing.
The agents, and the part I actually like
Now the agents. The headline was Fabric data agents, which go beyond the earlier AI skills: they don't just retrieve data from OneLake, they reason over it — understanding what the data means, how it's structured, and when it's relevant — and they integrate with Azure AI Foundry so you can build custom conversational agents grounded in your enterprise data.
I'm more interested in this than I expected to be, and the reason is the phrase "grounded in your enterprise data." The failure mode of every generic AI assistant is that it doesn't know your business — your definitions, your structure, your meaning. An agent that reasons over a governed semantic understanding of your actual data is a fundamentally more useful and more trustworthy thing than a chatbot guessing. But notice the dependency, because it's the whole game: an agent that reasons over your data is only as good as how well that data is understood and governed. Which is exactly why OneLake security and data agents shipping at the same conference isn't a coincidence — the second one needs the first one to be safe.
Copilot comes down the price ladder
The other announcement worth flagging, quieter but practically significant: Microsoft is opening Copilot and Fabric data agents to all Fabric SKUs from F2 upward, rather than reserving them for the expensive capacities. Democratising access is genuinely good — it lets smaller shops actually try this stuff. It also, let's be honest, seeds AI consumption across a far wider base, which is smart business as well as generosity. Both things can be true.
What the community made of it
The forum reaction this year was noticeably warmer on the governance news than the agent news, which tells you something about who actually runs this platform. OneLake security landed as a long-overdue relief — the "finally" energy of people who'd been stitching per-engine security together by hand for two years. The data agents got the more measured reception the whole industry now gives anything with "agent" in the name: interested, but show me. And underneath, the perennial Fabric worry hadn't gone anywhere — every new capability is another way to consume capacity, and the cost conversation remains the one Microsoft is least forthcoming about and the community is most anxious about.
The through-line
FabCon 2025 fit the pattern I keep seeing: the loud announcements were about agents, and the quietly important one was about giving those agents a governed, securable foundation to stand on. OneLake security is the unfashionable plumbing that makes the fashionable AI safe, and I'm glad it's finally arriving — because the agent future everyone's selling is only as trustworthy as the governance underneath it, and this is Microsoft, at last, building some of that governance into the platform itself. Agents grab the headlines. Security decides whether you can sleep. This year, for once, both showed up — and I'd spend my time on the one that lets you sleep.