The archives network's compliance office wants a consolidated, tenant-wide view of Fabric item-access activity across every branch's workspace, exportable into their existing security monitoring system rather than reviewed manually workspace by workspace. What Fabric governance capability supports this?
Select an answer to reveal the explanation.
Short Explanation
This is the difference between checking each branch's guest book by hand and pulling one consolidated report from head office — Fabric's audit logs are built to feed a single, tenant-wide activity trail into whatever monitoring system compliance already relies on.
Full Explanation
Fabric audit logs record activity events across the entire tenant, not per workspace, and are designed to be surfaced through the unified audit log so they can be retrieved and exported into an organization's existing security monitoring or SIEM tooling — exactly the consolidated, tenant-wide view compliance is asking for. This is the governance-across-the-estate capability that ties activity oversight together rather than requiring per-workspace manual review. A OneLake data access role is scoped to a specific item's data access, not a tenant-wide activity feed, and there's no such thing as a role configured 'at the tenant level' for this purpose — it doesn't address exportable monitoring at all. Dynamic data masking changes what values are visible in query results; it produces no activity trail and has nothing to do with centralized monitoring. Sensitivity labels classify items and can trigger export-time protections, but they don't generate or export an access-activity feed either. The operational step is for compliance to configure their monitoring system to ingest Fabric's audit log data through the unified audit log pipeline and confirm events from multiple branches' workspaces are arriving in one consolidated stream.