Icon Map for Fabric - Vendor Attestation
DRAFT. This attestation is a working draft and has not yet been submitted to Microsoft. Entries marked [confirm] are still being completed. Do not rely on this page until this notice is removed.
Published by Tekantis Ltd. Last updated 11 September 2026. This page is Section III of the Fabric Extensibility Toolkit vendor self-attestation, hosted for customers to reference as Microsoft's process requires.
Publish Workload Requirements Attestation Checklist
We, the vendor, Tekantis Ltd, confirm and attest to reviewing, meeting, and complying with the requirements outlined in the Microsoft Fabric Extensibility Toolkit, specifically the Publish Workload Requirements.
The following sections document details, exceptions, or variances regarding the attestation of adherence to the Publish Workload Requirements.
Workload information
| Description | Value |
|---|---|
| Workload version | 1.0.6 |
| Workload name | Icon Map for Fabric (Tekantis.IconMap; manifest product Tekantis.IconMap.Product) |
| Release date | [confirm] |
Business requirements
Value to customers
Icon Map brings rich, interactive maps to Microsoft Fabric, built directly on the data already in the customer's OneLake, with no separate GIS tools and no data to move. Customers can:
- Build on OneLake data: Lakehouse tables and files, Warehouses and SQL databases, Power BI semantic models, Eventhouse/KQL and live feeds, read in place without copying or moving anything.
- Combine many layers from many sources on one map: points, icons, shapes, lines and routes, 3D scenes, grids, heatmaps, travel-time catchments, imagery and indoor floor plans.
- Add thousands of ready-to-use layers from the Icon Map Catalog, or curate an organizational catalog stored securely in their own OneLake.
- Analyze in place with in-map charts, slicers and panels, plus lasso, radius and drive-time selection that cross-filters everything.
- Publish and embed live maps in Fabric and in the applications, portals and sites their internal and external audiences already use.
Trial
We provide an easy and fast trial experience. The trial is available to the customer without waiting time (less than 5 seconds), and provides a free and easy way to explore the offered workload for a limited time in accordance with Microsoft guidelines for Trials.
- Yes
- No
[confirm: describe the trial and its limits, or state that the workload is licensed without a separate trial]
Monetization
The workload is available on the marketplace for the customer to procure with or without a trial in accordance with the monetization guidelines.
- Yes
- No
[confirm: marketplace offer link once published; licensing today is governed by the End User License Agreement]
Technical requirements
Microsoft Entra access
The workload uses Microsoft Entra authentication and authorization.
- No other authentication and authorization mechanisms are used
- Different authentication and authorization mechanisms are used for stored data in Fabric
All authoring and viewing access inside Fabric is delegated: Icon Map acts as the signed-in user and can only reach data the user is already permitted to see, including row-level security on Power BI semantic models. Every data-plane call to the Icon Map backend requires a valid Microsoft Entra token verified against Microsoft's published signing keys; there is no anonymous data-plane access and no API-key fallback. Microsoft Entra tokens are obtained only through the JavaScript APIs of the Fabric Workload Client SDK. The Entra application inventory is described in the security whitepaper, section 6.2.
OneLake
Workloads integrate with OneLake to store data in the standard formats supported by the Fabric platform so that other services can take advantage of it.
- All data and metadata is stored in OneLake or Fabric data stores
- Not all data and metadata is stored in OneLake or Fabric data stores
Map definitions, data source configuration, published output, write-back edits and source credentials are stored inside the Icon Map item in the customer's OneLake, protected by workspace roles. Tileset Builder output is stored in the customer's Lakehouse as PMTiles; organizational catalogs are stored in the customer's OneLake. The only data held by Tekantis is operational telemetry, described under Privacy below and in the whitepaper, section 12.
Microsoft Entra Conditional Access
- The service works in its entirety even if customers enable this functionality
- The service works with limitations if customers enable this functionality
- The service does not work with Microsoft Entra Conditional Access
Conditional Access policies apply to the Microsoft resources Icon Map calls on the user's behalf (OneLake and Azure Storage, Azure Data Explorer, Power BI). Policy prompts can surface inside the workload; the behaviours and the settings that avoid repeated prompts are documented in Browser and network.
Admin REST API
- Microsoft Fabric Admin APIs are being used (/admin/*)
- No Microsoft Fabric Admin APIs are being used
Customer-facing monitoring and diagnostics
Health and telemetry data needs to be stored for a minimum of 30 days including activity ID for customer support purposes, including trials.
- Minimum 30 days requirement is adhered to
- Vendor stores the data beyond the minimum requirement
Raw telemetry events are retained for up to 25 months; aggregated, non-identifiable statistics are retained thereafter. Diagnostics can be disabled for a tenant on request; usage metering is always on. See the whitepaper, section 12.
B2B
- Cross-tenant B2B collaboration supported
- Workload item access only within the tenant
Icon Map relies entirely on Fabric's own workspace permissions. Guest users a tenant has admitted to a workspace are treated as Fabric treats them; Icon Map adds no cross-tenant sharing of its own. Maps published for use outside Fabric are a separate, opt-in feature that an organization can disable for its tenant or per workspace (whitepaper, section 4).
Business continuity and disaster recovery
Customer content is stored in the customer's own OneLake and inherits Fabric's own resilience and backup posture; Tekantis holds no customer map data at rest. Tekantis services are hosted in Microsoft Azure behind Azure-managed TLS with static assets cached at the edge. [confirm: link to Tekantis BCDR summary or the terms of service]
Performance
- Performance metrics on workload performance are available via the Monitoring Hub
- Workload includes a separate monitoring UI to test and track performance
- Performance tracking is not currently available to the end user; vendor support personnel can monitor, test and track performance via internal instrumentation and monitoring systems
Long-running jobs (tileset generation for Tileset Builder and the Icon Map Catalog) report to the Fabric Monitoring Hub. Interactive map performance is monitored by Tekantis through its operational telemetry.
Presence
- Service availability and colocation in the following Fabric regions
The workload is published for the Fabric public cloud and is available to tenants in every Fabric public-cloud region. Customer content stays in the customer's Fabric tenant, in the region of their capacity. The Tekantis services involved are listed below by role, with the Azure region each runs in.
Workload services (used whenever the workload runs inside Fabric)
| Service | Role | Region |
|---|---|---|
Workload frontend (app.iconmap.ai) |
The editor code loaded into the Fabric iframe; static files only, no server-side identity | East US 2 (Azure Static Web Apps, served from a global edge network) |
Workload backend (api.iconmap.ai) |
Data plane: OneLake access token minting, CORS fallback fetch for author-configured external sources, telemetry intake, organizational-catalog discovery | North Europe |
| Tenant policy settings | Resolves the tenant, capacity and workspace policies described under Workspace settings; receives identifiers only | UK South |
| Usage metering | Aggregated usage events written by the backend; see Privacy | UK South |
| Certificate store | Key Vault holding the certificate with which the published-map service authenticates to Microsoft Entra | East US |
Publishing outside Fabric (only when an author publishes a map for viewers without Fabric access)
| Service | Role | Region |
|---|---|---|
Published-map service (embed.iconmap.ai) |
Reads the published files from the customer's OneLake at view time and serves them to the viewer; transit-only, nothing retained | North Europe |
Embed host (org.iconmap.ai) |
Static files for the user-owns-data embedding mode; holds no data and has no server-side identity | East US 2 (Azure Static Web Apps, global edge network) |
Content services (read-only reference data supplied by Tekantis; a request names only the public dataset or tile being viewed and carries no customer data)
| Service | Role | Region |
|---|---|---|
Map asset CDN (styles.iconmappro.com) |
Basemap styles and tiles, fonts, sprites, terrain, routing tiles and the client-side geocoding index | Stored in North Europe, cached at the edge by Azure Front Door |
Icon Map Catalog API (catalogapi.icon-map.com) |
Catalog search (receives the author's search phrase) and catalog access tokens | North Europe |
| AI-assisted catalog search | Processes only the search phrase and catalog metadata | West Europe |
Catalog layer tiles (catalog.icon-map.com) and 3D mesh tiles (mesh.iconmap.ai) |
Catalog datasets | Stored in North Europe, cached at the edge by Azure Front Door |
Other Tekantis systems (the icon-map.com website, the Power BI visual licensing service, Icon Map Desktop telemetry, and internal tooling) are not called by the workload and are outside its boundary.
- All or part of the service does not reside in Azure
Every service above runs in Microsoft Azure. The one component outside Azure is the private GitHub repository that receives user-submitted support reports; see Data residency.
Public APIs
- The workload uses Fabric Public APIs
Design and UX requirements
Common UX
The workload and all item types comply with the Fabric UX guidelines, verified against the Fabric UI kit, the Fabric visuals kit and the Fabric UX System in September 2026. The following variances exist:
- The Icon Map item icon uses the Icon Map brand mark, which is multi-colour with a dark outline, inside the standard Fabric filetype container. The visuals kit describes filetype glyphs as single-colour; the mark is retained for brand recognition across Icon Map products. A single-colour variant is available if required.
Item creation experience
The item creation experience is in accordance with the Fabric UX System, using the platform's create dialog for every item type.
- Yes
- No
Monitoring Hub
All long-running operations integrate with the Fabric Monitoring Hub.
- Yes
- No
Trial experience
- Trial supported
- Trial not supported
[confirm]
Monetization experience
- The monetization experience is integrated with the marketplace and compliant with the guidelines
- Bring Your Own License (BYOL)
- Free / Freemium
- Other
[confirm: current model is licensed under the EULA with license keys issued to the organization]
Accessibility
The user experience is in compliance with the Fabric UX design guidelines for Accessibility.
- The user experience is compliant with the guidelines
- The following limitations exist
Icon Map is built on Fluent UI React v9, so dialogs, menus, forms, tabs and tables carry Fluent's keyboard handling, focus management and ARIA semantics. All interactive elements have accessible names, and every user-facing and accessible-name string is localized. Decorative motion respects the operating system's reduced-motion preference; data-driven motion such as live vehicle tracking continues, with a per-layer "Freeze movement" setting to snap rather than animate updates. The workload follows the Fabric host theme (light, dark and high contrast).
Limitations disclosed:
- Selecting individual features by keyboard directly on the map canvas (WebGL) is not supported. The data tables pane provides the keyboard-accessible equivalent for inspecting and selecting features, and MapLibre's keyboard pan and zoom remain available.
- Map controls drawn on the canvas keep their own colours for map readability and do not follow the Fabric theme; application chrome (ribbon, panels, dialogs) does.
- Windows High Contrast (forced-colors) rendering of custom map chrome, and the dark theme, have been implemented but not yet verified in every surface; a verification pass is scheduled.
- Some panel and control positions are adjusted by dragging; keyboard alternatives exist for panel move and resize, but a single-pointer alternative to every drag (WCAG 2.2 criterion 2.5.7) is not yet complete.
Target standard: WCAG 2.2 AA. Issues can be reported to support@icon-map.com.
World readiness / internationalization
- English is the only supported language
- The following languages are supported
English (US) is the default. The workload and its manifest are also provided in German, Spanish, French, Italian, Japanese, Dutch, Polish, Portuguese (Brazil) and Portuguese (Portugal).
Item settings
Item settings are implemented as part of the ribbon as outlined in the UX guidelines.
- Yes
- No
Samples
- Samples not provided
- Samples for preconfiguration of items provided
The Icon Map Catalog offers thousands of ready-to-use reference layers that can be added to a new map in a few clicks, which serves the same purpose; preconfigured sample items are not shipped.
Custom actions
- Custom actions are not implemented
- Custom actions implemented as part of the workload
Workspace settings
- Supported
- Not supported
Fabric does not yet offer a workspace-level settings surface for workloads, so this platform capability is not available to Icon Map or any other partner workload.
Icon Map provides its own policy settings instead. Each is a tenant-wide policy that can also be narrowed to a capacity or a workspace:
- Disable publishing maps for viewing outside Fabric (removes the Embed action and stops the embed service serving affected maps, including maps published before the change).
- Disable external data providers (map data can only come from Fabric sources).
- Restrict which basemap providers can be used.
- Disable diagnostic telemetry for the tenant (usage metering stays on).
Settings are not yet self-service in the Tekantis customer portal. An administrator requests a change by emailing support@icon-map.com from the tenant's domain; Tekantis applies it and confirms. The settings are described in Security and permissions.
Global search
- Supported
- Not supported
The Fabric top search bar does not index partner workload item types, so Icon Map items are not returned by it. Icon Map items can be found by name in workspace lists, the object explorer's keyword filter and the OneLake catalog's keyword filter. The workload does not add a search provider of its own.
Security and compliance requirements
Security general
Vendor attests that the security posture described here is reviewed whenever a release changes what the workload processes, where it runs or which services it calls, and that security issues which could have a detrimental impact on customers are addressed promptly and customers notified where applicable.
Security-relevant changes are reviewed internally against a written threat model before release, with findings tracked to closure. No external security assessment or penetration test of Icon Map for Fabric has been commissioned to date. The following measures are in place:
- Security review before release. Changes that touch authentication, tokens, the publishing and embedding paths, or anything reachable without a signed-in user are reviewed against a written threat model for that surface, not only for correctness. Reviews are recorded and each finding is tracked to closure. Where Microsoft publishes guidance for a surface - for example the authentication contract for a workload's backend endpoints - the implementation is checked against it directly. The anonymous, internet-facing publishing path is re-examined end to end at intervals and after significant change.
- Customer content never leaves the customer's tenant. Map data, query results and item definitions stay in the customer's Fabric workspace and OneLake. The Tekantis services in the path are transit-only and hold no customer map data at rest. The security whitepaper lists every network endpoint, who initiates each connection and what crosses it.
- Encryption in transit. Every Tekantis service is HTTPS-only with TLS 1.2 as the minimum protocol, behind Azure-managed certificates; static map assets are served through Azure Front Door. Communication between the browser, Fabric and the Icon Map backend is authenticated with Microsoft Entra tokens, and the control-plane calls Fabric makes to the backend are validated on every request.
- Encryption at rest. The little that Tekantis does store, operational telemetry, usage metering and licensing records, sits in Azure Storage and Azure SQL with Microsoft-managed 256-bit AES encryption at rest (storage service encryption and Transparent Data Encryption).
- Secrets. Held in Azure App Service configuration and Azure Key Vault, read through managed identities; never in source code or client bundles. Client-side code receives only short-lived, scoped tokens.
- Dependencies. A maintained list of third-party components and licenses is published.
npm auditis run across the dependency tree at each release, and releases do not ship with known unresolved vulnerabilities in runtime dependencies. - Posture. The Tekantis Azure subscription is continuously assessed by Microsoft Defender for Cloud's cloud security posture management.
- Verification by customers. Source code can be made available under NDA for a customer's security review, and penetration testing of a customer's own tenant usage can be arranged.
Privacy
Tekantis reviewed the workload's data handling when preparing the security whitepaper and the Data and privacy page, and repeats that review whenever a feature changes what data is processed. No external privacy audit has been commissioned.
- Publisher attests that only essential HTTP-only cookies are used by the workload and only after positively authenticating the user. The workload and its backend set no cookies of their own; the only cookies in play belong to Microsoft's identity platform.
- Publisher attests that it is not using or relying on third-party cookies as part of the solution.
- Publisher attests that it obtains any Microsoft Entra token using the JavaScript APIs provided by the Fabric Workload Client SDK. The workload contains no other token-acquisition library.
Telemetry never contains map data, query results, coordinates, addresses, search terms, file contents or free text, and never stores names, emails or raw user identifiers; the per-user identifier is a keyed hash held only by Tekantis. Raw events are retained for up to 25 months, then only aggregated, non-identifiable statistics. No third-party analytics SDK is embedded and no telemetry goes to third parties. See the whitepaper, section 12, and the privacy policy.
Data residency
Customer content stays in the customer's Fabric tenant and OneLake, in the region the customer chose for their capacity; Icon Map does not copy it elsewhere.
Where the Tekantis services are. Every Tekantis service the workload uses runs in Microsoft Azure; the full list by role and region is under Presence. Two of them handle customer content in transit and hold none at rest: the backend's CORS fallback fetch (North Europe), which retrieves an author-configured external resource and returns it unchanged when the external host does not send CORS headers, and the published-map service (North Europe), which reads published files from the customer's OneLake at view time. The operational data Tekantis does hold, usage metering and telemetry (UK South), tenant policy settings (UK South) and the published-map service's Microsoft Entra certificate (East US), consists of identifiers, counts and credentials, never map content. The workload's own code is served as static files from Azure Static Web Apps (East US 2, global edge network) and holds no data. Content services hold only Tekantis' reference data, in North Europe and West Europe, cached at the global edge.
One user-initiated exception. When a user chooses to send a support report from within Icon Map, the description they type and any screenshot they attach are filed in a private Tekantis repository on GitHub, which is hosted in the United States, and the screenshot is first scanned by Azure AI Content Safety in the East US region so that nothing inappropriate is stored. Nothing is sent unless the user submits the report.
Compliance
Tekantis Ltd is a UK company and acts as a data controller for operational telemetry under UK GDPR. Tekantis does not currently hold an ISO 27001 or SOC 2 certification of its own; the services the workload depends on are Microsoft Azure and Microsoft Fabric, which carry those certifications, and the compliance boundary for customer data is the customer's own Fabric tenant. AI-assisted features are governed under a risk-based process aligned with the EU AI Act and the NIST AI Risk Management Framework; see AI Act compliance.
Support
Live site
| Contact | Value |
|---|---|
| Contact name / team | Tekantis support |
| Email alias | support@icon-map.com |
| Self-service portal | Help and support |
Supportability
- Vendor attests that support information is published to the marketplace offering and available to users directly via the workload
Support information is linked from the workload page in Fabric and from every Icon Map item's Help menu. [confirm marketplace listing once published]
Service health and availability
Service health dashboard: Service status. The page probes every Tekantis service the workload depends on and shows current availability; it is linked from the Help and support page.
Fabric features
Application lifecycle management (ALM)
- Supported
- Not supported
Application Life Cycle Management is supported through Fabric Git integration and deployment pipelines. Every Icon Map item type carries its configuration in its item definition, so Fabric commits it to Git and deploys it between pipeline stages. A reference to another Fabric item can be bound to a Variable Library variable of type Item reference: a data source's item, a layer's OneLake file, a Tileset Builder's source and output, or an Organizational Catalog's repository. The item resolves its variables every time it opens, so a deployed copy reads its own stage's items. If a variable doesn't resolve, the item keeps its last resolved items and shows a warning.
Limitations:
- A reference that isn't bound to a variable stays absolute, so a deployed copy reads the same item as the source.
- Deployment pipelines don't copy job schedules, so a deployed Tileset Builder arrives unscheduled.
- Files an item keeps in its own OneLake folder, such as uploaded GTFS static feeds and published embed snapshots, aren't carried by Git integration or deployment pipelines. Upload or publish them again in the target stage.
- A Floor Plan Importer plan larger than 10 MB is kept only in the item's OneLake files and isn't carried.
- Published embeds belong to the stage they were published from. A deployed map has none until it's published there.
CI/CD
- CI/CD is supported via the Fabric CI/CD manifest section
- CI/CD is not supported
Microsoft has not specified a CI/CD manifest section, so the workload declares none. Git integration and deployment pipelines, described above, work without one.
Item definition portability
- Items can be restored with their definition in other workspaces
- Items cannot be restored in other workspaces
An Icon Map item's definition holds its whole configuration: for a map, its layers, data sources, charts, slicers, panels, bookmarks and tours; for a Floor Plan Importer, its converted plan, up to 10 MB. Fabric stores the definition with the item, so Git integration and deployment pipelines recreate the item in another workspace, and Icon Map's Save a copy does the same. References to other Fabric items are absolute unless they're bound to a Variable Library variable, which the item resolves again each time it opens (see Application lifecycle management above).
Private links
- Supported
- Not supported
Data hub
- Supported
- Not supported
All four Icon Map item types are registered as OneLake catalog items and appear in the catalog's item list, with the platform-provided details pane: overview (description, owner, location, sensitivity label, tags and endorsement), permissions, and the Monitor tab for Organizational Catalog and Tileset Builder, whose jobs report to the Monitoring Hub. The Fabric platform does not expose schema, refresh status or lineage integration to partner workloads, so the details pane does not show a data schema, a last-refresh time or lineage for Icon Map items.
Of the four item types, Organizational Catalog is catalogued as a data item: it holds a customer-owned catalog of map layers in OneLake that Icon Map items and the Icon Map Power BI visuals consume. Icon Map is catalogued as an insight item. Tileset Builder and Floor Plan Importer are catalogued as process items; their output is written to a Lakehouse the user chooses, where it is catalogued as Lakehouse data. Items can be found with the catalog's keyword filter and type category selector.
Data lineage
- Supported
- Not supported
Sensitivity labels
Sensitivity labels from Microsoft Purview Information Protection on items can guard sensitive content against unauthorized access and leakage.
- Supported
- Not supported
Labels are honoured in two ways: Fabric's own handling of the Icon Map item, and, from workload version 1.0.6, Icon Map's own check on every path that moves data out of the item. What remains outside our reach is carrying a label into an exported file, which no format the workload produces supports and which Microsoft's own consent text for the Fabric.Extend permission states is not available to partner items.
What Fabric applies today. Icon Map items are ordinary Fabric items: users can apply a sensitivity label from the item's create dialog, its header flyout or its settings, default-label policies apply at creation, and Purview protection policies associated with a label control access to the item exactly as they do for native items. Icon Map reads all source data as the signed-in user, so a user who is blocked from a labelled Lakehouse, Warehouse, Eventhouse or semantic model by a protection policy cannot see that data in a map either. Labels are not propagated by lineage onto an Icon Map item from the items it reads, because workloads cannot declare data lineage (see Data lineage above); authors apply the label to the map item themselves.
Export functionality. The Icon Map item can move data out of the item in the following ways. None of the output formats can carry a Purview sensitivity label, so labels and their protection settings are not applied to exported files, which is the same position as native non-Power BI Fabric items. Every path below is nevertheless checked against the label before it runs, as described under Label-aware export gating.
| Export path | What leaves the item | Format and destination |
|---|---|---|
| Download from the data tables pane | The full row set of a bound data source, including geometry | CSV to the user's computer; tab-separated text to the clipboard |
| Save from the data tables pane | The full row set of a bound data source | CSV or GeoParquet file written to a Lakehouse the user chooses, inside the tenant |
| Download or save drawn shapes | Shapes the user drew on the map | GeoJSON or GeoParquet to the user's computer or to a Lakehouse |
| Copy SQL workspace results | Results of a query the user ran over bound sources | CSV or tab-separated text to the clipboard |
| Camera tour video | A video rendering of the map, no rows | MP4 or WebM to the user's computer |
| Publish for embedding outside Fabric | A frozen copy of the rendered features and their attributes, chart rows, photos and map assets, or live query access in live mode | Files written to a Lakehouse in the tenant and served to the published map's viewers by the Tekantis embed service |
| Floor Plan Importer downloads | Converted floor plan shapes and room data | GeoJSON or CSV to the user's computer |
| Support report (opt-in) | A screenshot of the map and, if the user chooses, the map configuration | Sent to Tekantis support |
Downloads to the user's computer go straight from the browser to the user's device. The workload's iframe runs with Fabric's sandbox relaxation (allow-downloads), consented through the Fabric.Extend.IframeSandbox permission, so no Tekantis service is in the path and no copy of the file exists outside the tenant.
Controls available to administrators. Publishing for viewing outside Fabric, the export path that moves data furthest, can be disabled for the tenant or for individual workspaces (see Workspace settings). Two further settings govern the label check itself: export.labelGate chooses whether a label blocks an export, only warns, or is ignored, and export.blockedLabelIds lists labels without protection settings that should nevertheless block. Both can be scoped to a tenant, a capacity or a workspace. Paths not covered by a label are available to any user who can already read the data in Fabric.
Label-aware export gating (from workload version 1.0.6). Before any of the paths above moves data, Icon Map reads the sensitivity label of the map item and of every Fabric item the map reads, acting as the signed-in user, and for labels that carry protection settings checks that user's usage rights under the label in Microsoft Purview.
- A user without the label's Export right cannot download the data or save it to another Lakehouse, and without the Extract right cannot copy it to the clipboard.
- Data under a protected label cannot be published for viewing outside Fabric, because the viewers of a published map are not the user whose rights were checked.
- A map that reads any labelled data cannot be shared through an anonymous link, whatever the label's settings.
- Labelled data without protection settings produces a warning that names the label and lets the user continue, matching Fabric's own behaviour for its non-Power BI items.
- A live published map stops serving a data source whose label changes after publishing, until the author publishes it again.
The publishing service and the support-report service re-apply the same decision on the server, so the check is not only a prompt in the browser. Screenshots attached to a support report are treated as an export of whatever the map shows.
The check needs the Icon Map backend application's Microsoft Graph SensitivityLabel.Read permission, which only an administrator can grant. Until it is granted, exports of labelled data are refused with a message naming the permission, and maps that read no labelled data are unaffected. Purview's label APIs are available in the global cloud only; elsewhere the workload can see that data is labelled but not what the label enforces, so it warns instead of blocking.
Extra notes
Icon Map for Fabric consists of four item types: Icon Map, Icon Map Catalog (organizational catalog), Tileset Builder and Floor Plan Importer. The Icon Map Pro and Icon Map Slicer custom visuals for Power BI are separate products with their own security whitepaper.
Several Fabric features above are marked "Not supported" because the Fabric platform does not yet expose them to partner workloads (application lifecycle management, private links, data lineage, workspace settings and label propagation on export). Tekantis will adopt each as Microsoft makes it available to workloads.