How to use Microsoft Purview Protection Policies so a Fabric workspace Admin can still fully administer the workspace… but is completely blocked from seeing any of the sensitive data inside it.

You keep the person as Admin (so they can manage items, permissions, capacity, etc.) while the protection policy + sensitivity label combination simply removes their ability to open or view the protected Lakehouses, Notebooks, etc.

I show the full end-to-end config in the video — sensitivity label, protection policy, the slightly confusing “except for” access control wording, and live results with an Admin account.

Really useful pattern for regulated or highly sensitive environments.