Skip to main content

What Is OneLake Catalog? Discover, Govern, Secure

Emily Winks, Data Governance Expert, Atlan
Data Governance Expert
Updated:
|
Published:
13 min read

Key takeaways

  • OneLake catalog has three tabs: Explore, Govern, and Secure. Microsoft calls the first one Explore, not Discover.
  • Govern went GA in September 2025 and its admin view in March 2026; the Search API and MCP tool are still in preview.
  • Govern insights skip tables, refresh daily for admins, and cover Fabric items only, which bounds what an agent learns.

What is OneLake catalog?

OneLake catalog is the centralized place in Microsoft Fabric for finding, exploring, and using Fabric items, and for governing the data you own. It has three tabs: Explore for browsing and filtering items, Govern for governance insights and recommended actions, and Secure for workspace roles and OneLake security roles. It is also embedded in Microsoft Teams, Excel, and Copilot Studio, and a catalog Search API, still in preview, exposes the same discovery to code.

The three tabs:

  • Explore: browse, filter, and inspect the Fabric items you can access
  • Govern: governance insights and recommended actions for admins and data owners
  • Secure: workspace roles and OneLake security roles across workspaces

Is your agent context ready?

Check Agent Readiness

OneLake catalog is where Microsoft Fabric lets you find, govern, and secure the items your team builds, across three tabs named Explore, Govern, and Secure. Its admin governance view went GA in March 2026, and a Search API plus a Fabric Core MCP Server tool, both in preview, now let an AI agent query the same catalog from code.

Is Your Catalog Ready for Agents?


Checks whether a catalog is actually ready to serve AI agents at runtime, across interface, enforcement, pricing, and definitions. Read the skill.

Paste into a new chat

Use the skill at https://atlan.com/skills/catalog-ai-readiness-check.md to check whether a data catalog is ready to serve AI agents at runtime. Ask me for whatever it needs.

Run once in a terminal

curl -fsSL --create-dirs \
  -o ~/.agents/skills/catalog-ai-readiness-check/SKILL.md \
  https://atlan.com/skills/catalog-ai-readiness-check.md

For an agent

curl -fsSL https://atlan.com/skills/catalog-ai-readiness-check.md

Discover is the verb most people reach for, but the first tab is called Explore, both in the product and in Microsoft’s OneLake catalog overview (Microsoft Learn, 2026). Get these points straight before the governance sessions at FabCon Europe 2026; the sessions picked by role narrow down which to attend.

You open the catalog from the OneLake icon in the Fabric navigation pane, and it lands on Explore by default. Status varies by feature: Govern is GA, while the Search API, the MCP tool, and AI Auto-Summary are still preview. Agents are now a caller too, because the Catalog Search REST API (Microsoft Learn, 2026) accepts service principals and managed identities as well as users.

Tab or feature Status Since Source
Explore tab No separate status entry November 2024 Fabric blog
Govern tab Generally available September 2025 Microsoft Learn
Govern for Fabric admins Generally available March 2026 Microsoft Learn
Secure tab Preview at launch; no GA entry found September 2025 Fabric blog
AI Auto-Summary for semantic models Preview Not dated Microsoft Learn
Catalog Search API and MCP tool Preview March 2026 Fabric blog
fab find in the Fabric CLI Preview May 2026 Fabric blog
OneLake catalog in Microsoft Foundry Generally available May 2026 Microsoft Learn

What OneLake catalog is, and what it replaced

OneLake catalog succeeded the OneLake data hub in November 2024 and has grown into Fabric’s single place for finding, governing, and securing items. Microsoft announced it as “the next development of the OneLake data hub,” extending coverage from data items such as lakehouses, warehouses, and semantic models to the full range of Fabric item types, according to the launch announcement (Microsoft Fabric Updates blog, 2024).

OneLake and OneLake catalog are two different things. According to Microsoft’s OneLake overview (Microsoft Learn, 2026), every Fabric tenant gets exactly one OneLake, “the single place for all your analytics data.” The catalog is the layer on top, where each item carries descriptions, owners, schema, lineage, and usage metrics.

The catalog also reaches past the Fabric portal. It is embedded in Teams, Excel, and Copilot Studio, and since May 2026 it is generally available inside Microsoft Foundry, where builders can “turn governed assets into knowledge sources without leaving the project,” per Microsoft’s What’s new archive (Microsoft Learn, 2026). That gives builders of Foundry agents a direct path to OneLake data.

Every surface lists Fabric items. Outside data appears only through an item that holds it, such as a mirrored database or a lakehouse with a shortcut. That scope is the first thing to settle about any data catalog for AI, and it is where a catalog of items and a context layer start to diverge: the catalog knows what exists in Fabric, and an agent’s questions rarely stop there.


What do the Explore, Govern, and Secure tabs actually do?

Each of OneLake catalog’s three tabs answers a different question: Explore covers what exists and who owns it, Govern how well the estate is labeled and curated, and Secure who can reach what.

Explore tab


Explore lists every Fabric item you can access, or can request access to, with columns for Name, Type, Owner, Refreshed, Location, Endorsement, and Sensitivity, according to Microsoft’s Explore tab documentation (Microsoft Learn, 2026). You can scope it to a domain, filter by workspace or tag, or narrow it to endorsed items.

Selecting an item opens a details pane with its metadata, lineage, and permissions. Explore also lists semantic models configured as discoverable even when you can’t open them, so you can request access. That path assumes a person in the UI, one place AI agents and humans differ in data discovery.

Govern tab


Govern gathers governance insights and recommended actions in one view. According to Microsoft’s Govern tab documentation (Microsoft Learn, 2026), admins see “All Data in Fabric” by default, from tenant metadata that refreshes daily via Admin Monitoring Storage. Data owners see their own items, refreshed each time they open the tab.

The tab went GA in September 2025 and the admin experience in March 2026, per the What’s new archive. View more opens a report with three sub-tabs:

  • Manage your data estate: inventory, capacities, domains, feature usage.
  • Protect, secure & comply: sensitivity labels and data loss prevention results.
  • Discover, trust, and reuse: freshness, descriptions, endorsement, sharing.

For data governance teams, the recommended actions carry the most weight: each card names an issue, why it matters, and the steps to fix it. In the split between data governance and AI governance, the Govern tab sits on the data side: it scores the estate’s hygiene and is silent on what agents do with it.

Secure tab


Secure puts workspace roles and OneLake security roles in one place, according to Microsoft’s Secure tab documentation (Microsoft Learn, 2026). On the View users page, Add users and Manage access change role assignments in bulk across workspaces, such as putting every new hire in the Viewer role.

View security roles lets you create, edit, or delete OneLake security roles, including each role’s data and members. Workspace Admins and Members see a workspace’s data; Contributors and Viewers see only their own access. This is where AI agent access control and role-based access control for a context layer meet Fabric’s own model.

Microsoft introduced Secure as a preview in a September 2025 Fabric Updates post; today’s docs carry no preview label, but no GA entry exists either, so treat its status as unconfirmed.

Aspect Explore tab Govern tab Secure tab
Question it answers What exists, and who owns it? How well labeled and curated is it? Who can reach it?
Main audience Anyone with Fabric access Fabric admins and data owners Workspace Admins and Members
What it shows Items, with lineage and permissions Insights, recommended actions, reports Workspace and OneLake security roles

Together, the tabs answer what a Fabric admin asks. An agent asks something narrower, far more often: can I trust this table right now? The Govern tab docs state plainly that it does not report on tables.


How can AI agents query OneLake catalog programmatically?

The OneLake Catalog Search API, a matching tool in the Fabric Core MCP Server, and a fab find command in the Fabric CLI make Explore’s discovery callable from code, and all three are in preview. Microsoft first listed the API and MCP tool in its Fabric March 2026 feature summary (Microsoft Fabric Updates blog, 2026); a May 1, 2026 post covered all three.

Nadav Schachter, Senior Product Manager at Microsoft, wrote in the May 2026 post: “With OneLake Catalog Search API, MCP and CLI tools, that same discovery experience is now available programmatically, making it possible to build search directly into scripts, internal tools, and agentic workflows.”

The API reference (Microsoft Learn, 2026) spells out what an agent gets back:

  • One request, every workspace. A single POST searches names and descriptions, filters by item type or workspace, and pages up to 1,000 results.
  • Permission-trimmed results. Callers only discover items they are authorized to access.
  • No data access. Entries “do not grant access to underlying data or item content.”

Inside the Fabric Core MCP Server, catalog search ships as a built-in tool, so an agent can locate an asset and then continue with follow-up actions through other tools. The wider set of Fabric MCP servers covers what those other tools do, and the Model Context Protocol and its client-server architecture explain how those calls work. Adding the Core server also raises the choice between an MCP registry and ad hoc MCP usage.

At a terminal, fab find 'sales report' searches every workspace you can access, with type filters, -l for IDs, and JMESPath for reshaping output.

What comes back is a name, a description, a type, a workspace, and an ID. It does not say what a column means or which revenue definition finance signed off on. Finding the item is step one of using a data catalog as an LLM knowledge base; everything after it is context engineering.


Is OneLake catalog the same as Microsoft Purview?

No. OneLake catalog is part of Microsoft Fabric and lists Fabric items; Microsoft Purview is a separate product with its own documentation. The two meet inside the Govern tab.

According to Microsoft’s Govern tab documentation (Microsoft Learn, 2026), the View more report now includes “security insights previously available in the Microsoft Purview Hub.” Its Protect, secure & comply sub-tab reports sensitivity label coverage and data loss prevention policy results across workspaces. The Explore tab docs show the same link from the other side: Explore lists Power BI reports whose semantic model violates a data loss prevention policy that restricts access, so users can request it.

So the Govern tab surfaces Purview signals for Fabric items. It does not turn OneLake catalog into Purview. If your question reaches past Fabric, Microsoft’s Purview Unified Catalog is the product to compare, and the questions to ask about governing Fabric AI agents apply either way.


What are OneLake catalog’s limitations and open questions?

Microsoft documents OneLake catalog’s limits across separate docs; collected in one list, they show where the catalog stops.

Area Documented limit Source
Govern Subitems such as tables aren’t supported and don’t appear in insights Govern docs
Govern No cross-tenant scenarios or guest users; unavailable when Private Link is activated Govern docs
Govern Admin insights refresh once a day; “It takes a day to get an updated view” Govern docs
Govern Third-party workload items are left out of the View more charts Govern docs
Govern The admins semantic model is read-only and can’t be used with Fabric data agents Govern docs
Search API Entries cover items and workspaces only, and grant no access to data API reference
External shortcuts Always delegated authentication; OneLake security on the shortcut decides what users see Shortcut security docs

For data that starts outside Fabric, the shortcut row matters most. According to Microsoft’s shortcut security documentation (Microsoft Learn, 2026), shortcuts to external systems such as Amazon S3 “always use delegated authentication,” so users reach external data “without direct access to the external system.” Per-user limits come from OneLake security roles on the shortcut, not the external system.

For an agent builder, the sharpest line is the admins semantic model: a Fabric data agent can’t read the tenant-wide picture behind the Govern tab. That doesn’t settle whether the data catalog is finally dead, but it does mean a Fabric-only catalog can’t be the whole of an agent’s guardrails checklist.

The Secure tab’s status stays open. The larger question is grain: an agent decides at the table and column level, sometimes minutes after a change, while Govern’s admin view reports on items once a day. That gap is what an AI-ready data checklist and AI-ready data lineage exist to close.


Where does OneLake catalog’s governance end, and where does an agent’s context begin?

OneLake catalog governs what an agent can see and touch inside Fabric, but an agent’s context rarely stops at OneLake’s edge. All three tabs are scoped to Fabric items, plus whatever mirroring and shortcuts bring in.

A Fabric-scoped catalog was built to stop at that boundary. The same three questions come back for every system outside Fabric: what exists, how well it’s governed, and who can reach it. They also come back at a finer grain, because what makes data AI-ready is known column by column, not item by item.

That is the job of an enterprise context layer: one context graph across systems, carrying the definitions a semantic layer holds and the AI agent identity rules for who sees what. Atlan’s version is the Enterprise Data Graph; through Atlan’s MCP server, an agent checking a column gets lineage, quality, policy, and owner in one call.

The layer can sit beside an MCP gateway or inside an AI agent harness, and can start from the inventory OneLake catalog already provides. The question for FabCon: when your agent finds a Fabric table, where does it learn whether to trust it?


FAQs about OneLake catalog

1. What is the difference between OneLake and OneLake catalog?


OneLake is the data lake itself: every Fabric tenant gets exactly one, and it stores the analytics data. OneLake catalog is the interface on top of it for finding, governing, and securing the Fabric items that hold that data.

2. How do I access the OneLake catalog in Microsoft Fabric?


Select the OneLake icon in the Fabric navigation pane, and the catalog opens on the Explore tab. It is also embedded in Microsoft Teams, Excel, and Copilot Studio.

3. Is OneLake catalog the same as Microsoft Purview?


No. OneLake catalog is part of Microsoft Fabric and lists Fabric items, while Microsoft Purview is a separate product. They meet in the Govern tab, which now includes security insights previously available in the Microsoft Purview Hub.

4. What are the three tabs in the OneLake catalog?


Explore, Govern, and Secure. Explore lists and filters the items you can access, Govern shows governance insights and recommended actions, and Secure shows workspace roles and OneLake security roles across workspaces.

5. How does OneLake catalog help with data governance?


The Govern tab gives admins tenant-wide insights and data owners insights on their own items, with recommended actions for each issue it finds. Admin insights refresh once a day, and the tab does not cover subitems such as tables.

6. Can I see data from outside Fabric in the OneLake catalog?


Only through a Fabric item that holds it, such as a mirrored database or a lakehouse with a shortcut to external storage. The catalog itself lists Fabric items only.


Sources

  1. OneLake catalog overview, Microsoft Learn
  2. Discover and explore Fabric items using OneLake catalog’s explore tab, Microsoft Learn
  3. Govern your Fabric data with the OneLake catalog, Microsoft Learn
  4. Secure your data, Microsoft Learn
  5. What’s new? archive, Microsoft Learn
  6. Catalog - Search - REST API (Core), Microsoft Learn
  7. OneLake, the unified data lake, Microsoft Learn
  8. Secure and manage OneLake shortcuts, Microsoft Learn
  9. Introducing the new OneLake catalog: Your central hub for data discovery, management, and governance, Microsoft Fabric Updates blog (November 2024)
  10. View and manage security in the OneLake catalog (Preview), Microsoft Fabric Updates blog (September 2025)
  11. Fabric March 2026 Feature Summary, Microsoft Fabric Updates blog (March 2026)
  12. Discover items across workspaces with the OneLake Catalog Search API, MCP and CLI tools (Preview), Microsoft Fabric Updates blog (May 2026)

Share this article

signoff-panel-logo

Atlan is the Context Layer for AI. It translates business knowledge, including data definitions, working procedures, and governance policies, into context AI can actually use. This knowledge lives in a single Enterprise Data Graph that every team and AI agent can reach.

In Atlan's AI Labs benchmark, adding this context improved AI's text-to-SQL accuracy by 38%.

Atlan is recognized as a Leader across multiple Gartner reports and Forrester Waves, and is trusted by over 400 enterprises representing $10T+ in market cap, including Mastercard, Workday, General Motors, CME Group, HubSpot, FOX, Virgin Media O2, and Elastic.

Bridge the context gap.
Ship AI that works.