Onboarding & setup overview

This section is a runbook for administrators. Working through it once means your users get a clean experience — Icon Map loads, reads their data, and publishes maps without repeated consent popups or "access denied" prompts.

It's written for two roles, which may be the same person:

  • A Microsoft Entra (Azure AD) administrator — grants tenant-wide consent to the two Icon Map workload applications.
  • A Microsoft Fabric administrator — enables the workload and the required tenant settings.
Private preview

Icon Map for Fabric is in private preview. Your onboarding contact will confirm the exact application identifiers and any tenant-specific steps. If anything below doesn't match what you see, check with them before changing tenant-wide settings.

What you'll set up

Step Who Why
Enable the workload Fabric admin Makes the Icon Map item types available in your tenant.
Prepare your tenant Entra admin One command, only in tenants that have never used Azure Storage through a third-party app - so Lakehouse sources can be consented.
Grant admin consent Entra admin Consents to both workload applications (frontend and backend) once, so users aren't prompted and backend features work.
Enable tenant settings Fabric admin Allows the data access Icon Map relies on.
Set up publishing Fabric admin Lets published maps be embedded outside Fabric.
Browser & network IT / desktop Avoids popup-blocker and cookie issues.

Prerequisites

  • A Microsoft Fabric tenant, with workspaces backed by a Fabric capacity (a trial capacity is fine for evaluation). OneLake operations run on capacity-backed workspaces.
  • Administrator access: Global Administrator or Privileged Role Administrator in Entra ID for the consent step, and Fabric Administrator for workload and tenant settings.
  • The Icon Map workload made available to your tenant (arranged with your onboarding contact during the preview).

Recommended order

  1. Enable the Icon Map workload - send us your tenant ID, allow partner workloads, add Icon Map from the Workload hub.
  2. Prepare your tenant if it has never used Azure Storage through a third-party app, then grant tenant-wide admin consent — the key step for a popup-free experience.
  3. Enable the required tenant settings.
  4. If you'll publish maps outside Fabric, set up publishing.
  5. Share the browser & network notes with anyone who hits sign-in issues.

Changes to Entra consent and tenant settings can take 10–30 minutes to take effect across your tenant.

If one person holds both the Fabric administrator and an Entra administrator role, steps 1 to 3 collapse into adding the workload, opening a map and accepting three prompts on behalf of the organization - see the short version.

Next steps