Head-to-head · updated 13 September 2026

DataShield vs Microsoft Fabric: where does the agent's data actually live?

Microsoft Fabric is a very large, very capable data platform. One capacity meter buys you Data Factory, Spark, a Delta warehouse, KQL streaming, Power BI, and now the Fabric IQ workload with its ontology, graph and agents. OneLake sits under all of it, and shortcuts pull in S3 and Google Cloud Storage without a copy. If your estate is already Microsoft, Fabric is the cheapest decision you will ever make, because it is mostly a decision you already made.

We do none of that. We are a governed data plane for the agents that read your data, and we run where you put us. Datasets are tokenized at ingest; agents query tokenized data over MCP; detokenization is a privileged, audited operation. Every governed tool call is re-checked against the agent's current authority first. Every decision lands in a hash chain you can verify yourself. Here is the split, rows we lose included.

DataShield vs Microsoft Fabric at a glanceEight questions regulated buyers ask us. Scored from each vendor's public docs. DataShield vs Microsoft Fabric at a glance Eight questions regulated buyers ask us. Scored from each vendor's public docs. DataShield Fabric Tamper-evident audit chain you can verify Authority re-checked on every governed tool call Break-glass access for agents Reversible tokenization at ingest Runs on your own infrastructure Lakehouse, streaming, warehouse and BI in one platform OneLake zero-copy shortcuts across clouds Published pricing you can act on shipped partial / roadmap not offered Sources at the bottom of this page.

The short version

Pick DataShield when

  • The data plane has to sit on your own infrastructure. Fabric is SaaS only. There is no on-prem edition, no private build, no exception.
  • Someone will ask you to prove an agent's log was not edited. Not search it. Prove it. Run the verifier and see what that looks like.
  • You need to pull an agent's authority mid-session and have the very next tool call fail closed.
  • The agents that matter are not Microsoft agents, and the values they read should be tokens, not names.

Pick Microsoft Fabric when

  • You need a real lakehouse. Spark, a Delta warehouse, KQL streaming, 200-plus Data Factory connectors, Power BI. We ship none of it and are not pretending to.
  • Your data is scattered across clouds. OneLake shortcuts read Amazon S3 and Google Cloud Storage in place, with no pipeline to build.
  • You want one semantic layer for the whole business. Fabric IQ generates an ontology from semantic models you already run, and a graph you can traverse.
  • The money is already spent. Fabric rides the Azure bill and the Microsoft relationship, and that argument has won more deals than any feature ever will.

Bottom line: Fabric is where the data lives. We are where the agent's authority and the proof live. The split matters most when the data cannot live in someone else's SaaS.

Feature by feature

Competitor cells describe what Microsoft's public docs say as of the date above. If we have mischaracterised something, email support@myorg.ai and we will correct it, credited.

What mattersDataShieldMicrosoft FabricEdge
Audit evidenceSHA-256 hash chain with Ed25519-signed checkpoints that are themselves chained. Verification names the failure: tampering, insertion, deletion or truncation. Try the verifier.Agent interactions flow into Purview Audit and eDiscovery. The data agent doc calls those governance features "currently in preview" and warns that interactions "might be logged and discoverable." We found no cryptographic tamper evidence.
Agent authorizationEvery governed tool call passes a scope ceiling, an authority tier and a revocation re-check before dispatch. The call fails closed.A four-layer precedence model: organizational, role-based, developer, then user intent. It is a real design. It resolves at configuration time, not per call, and the agent runs on the asking user's credentials.
Break-glassScoped, time-boxed emergency access for agents. It auto-revokes and cannot be quietly deleted from the log.Nothing agent-shaped that we could find in the Fabric docs. Emergency access is an Entra and Azure concern.
GDPR erasureCrypto-shred of per-subject key material plus ISO 27560 consent receipts. The chain still verifies after the subject is gone.Purview retention and lifecycle policies over OneLake. That is a workflow, not a cryptographic mechanism.
Tokenization and data handlingDeterministic, join-preserving, vault-reversible tokens at ingest, plus quasi-identifier generalization (dates to year, decade or age band; ZIPs to 3 or 4 digits; partial phones, SSNs and emails) with a measured cardinality-reduction score per column. Detokenization is privileged and logged.Labels and DLP decide who may read a value. The raw value stays in OneLake. We wrote up that gap here.
MCP and agentsMore than 200 MCP tools across Ontology, Auth, Corpus and Lighthouse. Auth issues MCP tool tokens with a scope ceiling and meters every call against the agent.A Microsoft Fabric MCP server exists in public preview, aimed at AI-assisted development over Fabric's public APIs and item definitions. It is a build-time helper. We found no MCP surface that serves governed data at runtime with per-call authority checks.
Deployment and hostingSelf-hosted in your own cloud or data center, or a dedicated single-tenant server we operate. Docker images for Auth, Ontology, Corpus and Lighthouse. Ed25519 audit-signing keys can live in your own KMS or HSM. HMAC tokenization keys sit in your environment today, not in a KMS.SaaS only. Microsoft's own line is "You don't need an Azure account to use Fabric," which is a feature for most buyers and a wall for a few. There is no self-hosted edition.
Platform breadthIngest, catalog, profile, transform, snapshot, tokenize, match, retrieve. No Spark, no streaming engine, no BI tool, no lakehouse.Data Factory with more than 200 connectors, Spark notebooks, a Delta-native warehouse, Real-Time Intelligence, Power BI, mirroring from Snowflake, Databricks and PostgreSQL into OneLake. This is not close.
Semantic and ontology layerEntity types, a materialized glossary, typed lineage with per-hop access gating, and probabilistic record linkage behind masked golden views.Fabric IQ, in preview, with an ontology item, a graph item, planning, and operations agents that act on live data. It generates ontologies from semantic models already in production. Broader than ours, and they got to the word first.
Catalog and discoveryWe scan, profile and classify a live PostgreSQL source in place, no rows leaving it, against 129 field classes covering PII, PHI, financial data and secrets. PostgreSQL today, not your whole estate.The OneLake Catalog covers every item in the tenant, with Purview doing classification and labeling underneath. Far wider than us.
PricingPublished model and a scoped instant quote with no sales call. You still have to answer a few questions to get a number.A clear SKU ladder from F2 to F8192, billed per second, with reservations Microsoft says save about 41%. The dollar figures on the public page render as "$-" and the page states prices "are estimates only and are not intended as actual price quotes."
Maturity signalsAuth, Guardian and Lighthouse are live in production (Guardian and Lighthouse since April 2026). SOC 2 not yet certified, and we say so.Microsoft. Every certification you can name, a global support org, and more Fabric capacity running today than we will see this decade.

◆ DataShield leads◇ Microsoft Fabric leads◈ comparable

Fabric claims are drawn from learn.microsoft.com, the Azure pricing page and the microsoft/mcp repository, last checked 13 September 2026. We link them below rather than work from memory.

Three things you get here that you won't get from a SaaS lakehouse

A data plane you can point at

Fabric has no self-hosted edition. For most buyers that is the whole appeal. For a hospital with a residency rule, or a bank whose contract forbids third-party processing, it ends the conversation. We ship Docker images for Auth, Ontology, Corpus and Lighthouse, and they run on your metal with your keys. How we deploy.

Evidence, not a search box

Purview Audit is a good search box. It is not an artifact. An auditor who asks whether the March records were edited gets an export and your word for it. Ours is a hash chain with signed checkpoints, and the verifier says what broke, not just that something did. That is the property EU AI Act Article 12 and HIPAA §164.312(b) reviewers care about, and we walked through the Fabric version of that problem in this write-up. Try the verifier, no signup.

Authority that can change mid-flight

An analyst leaves on a Friday. Their agent is 20 minutes into a 40-minute job. With DataShield the next governed tool call is re-checked against current authority and fails closed. Fabric's data agent inherits the asking user's permissions, which is sound, but permission changes land on the schedule a token and a cache decide. How Auth does it.

Where Microsoft Fabric is genuinely stronger

Almost everywhere, if you measure by surface area. Fabric is a lakehouse, a warehouse, a streaming engine, a BI tool and a data-integration suite under one capacity meter, and OneLake makes them share storage instead of copying it. Shortcuts read Amazon S3 and Google Cloud Storage in place. Mirroring pulls Snowflake, Databricks and PostgreSQL into OneLake with no pipeline to write. The Fabric data agent is generally available, read-only by design, and routes a plain-English question to NL2SQL, NL2DAX, NL2KQL or Microsoft Graph depending on the source. Then Fabric IQ layers an ontology and a graph over the whole thing so agents reason in business terms. We build none of that, and a buyer who needs it should buy it.

The push-back is narrow and it is about the last mile. Read the data agent limitations page and the shape of the product comes into focus: responses cap at 25 rows and 25 columns, there is no unstructured data, English only, you cannot change the model, and a query simply fails if the source capacity sits in a different Azure region than the agent's capacity. The Purview governance around those agents is, per Microsoft's own words, "currently in preview." None of that is damning. It says this is a conversational analytics feature, well built, inside one vendor's estate. It is not an authorization and evidence layer for whatever agent your team wires up next quarter. When your regulator asks who let the agent read that column, and whether the record of it could have been changed, Fabric hands you a search result. We hand you a chain.

Questions worth asking both of us

These are the questions we would want answered if we were the ones buying. Ask them on every call, ours included.

Can you cryptographically prove an audit log entry wasn't deleted?

DataShield: yes. Each record commits to the one before it, checkpoints are signed and chained, and verification tells deletion apart from truncation and from tampering. Run it at /verify. Fabric: agent interactions go to Purview Audit and eDiscovery, and those controls are marked preview in the data agent doc. We found no tamper-evidence mechanism. Ask Microsoft to show you one.

What happens to a revoked agent mid-session?

DataShield re-checks authority on every governed tool call, so revocation lands on the next call. Fabric's data agent runs on the requesting user's credentials, so the answer depends on Entra token lifetime and how fast policy re-evaluates. Ask how long a compromised session keeps working after you pull access.

How does GDPR erasure interact with the audit trail?

DataShield crypto-shreds per-subject key material and issues an ISO 27560 consent receipt. Actor identities in the chain are HMAC-committed, so the evidence still verifies once the subject is gone. Fabric leans on Purview retention and lifecycle policies. Those are workflows over copies of data. Ask for the mechanism, not the workflow.

Does Microsoft Fabric support MCP, and do we still need DataShield?

Partly, and it depends. Microsoft ships a Fabric MCP server in public preview, and a second one for Real-Time Intelligence. Read what it does: it gives a coding agent access to Fabric's public APIs and item definitions so it can help you build, without touching live environments. That is useful. It is not a runtime data surface with a scope ceiling, a mid-session revocation check and a sealed audit row per call, which is what we ship across Ontology, Auth, Corpus and Lighthouse. Ask Microsoft where the per-call decision point is.

We already bought Fabric capacity. Why add anything?

Usually you shouldn't. If your data belongs in OneLake and your agents are Copilots, keep going. Three things bring people to us anyway. A residency or contract rule that forbids a SaaS data plane, and Fabric has no self-hosted edition. An agent stack that isn't Microsoft. And an auditor who wants proof rather than an export. One more practical note: the Fabric pricing page shows the SKU ladder with the dollar amounts blanked, and the licensing rules bite below F64, where Power BI viewers still need a Pro or PPU seat.

Does DataShield have SOC 2?

Not yet, and we will not imply otherwise. Auth is live with a public threat model and a verifier anyone can run. Guardian and Lighthouse have been in production since April 2026. Design-partner terms include source escrow, so a small vendor is not a single point of failure. Details on the security page.

Other head-to-heads

Same market

DataShield vs Snowflake

DataShield vs Snowflake: Snowflake wins scale, Cortex agents and ecosystem. DataShield adds self-hosting,.

Same market

DataShield vs Dremio

DataShield vs Dremio: Dremio wins on Iceberg lakehouse query speed and scale. DataShield adds PII.

Same market

DataShield vs Databricks

DataShield vs Databricks: Databricks wins scale, Agent Bricks and Lakebase. DataShield adds independent,.

All

Every comparison

One honest scorecard per vendor.

See both mechanisms run in your browser: break a live audit chain, revoke an agent mid-session, then decide what your capacity still owes you. Demo Center access is free with a work email.

Get free Demo Center access

You've seen the proof

Ready for a number? Scope your deployment and we'll price it against your own economics.

Get your quote →