The bottom line
In Microsoft Fabric, data residency is set by three separate things: the tenant home region (tenant metadata), the capacity region (compute and OneLake storage), and the region of each source system. As of August 2026, UAE North supports all Fabric workloads; UAE Central and Qatar Central are Power BI only. Put capacity in UAE North and customer data rests in the UAE — but tenant metadata stays in the home region, and Copilot/AI is disabled by default outside the US and EU Data Boundary, so you can have UAE residency or Copilot, not both without a recorded decision. Ten auditor questions map to exact places in your tenant; produce those with screenshots and you pass most assessments.
In This Article
A programme that stalls on one question
The pattern is consistent. A UAE manufacturer has built a working case for a lakehouse on Microsoft Fabric — MES plant data, orders and standard cost from SAP S/4HANA, a supply-chain layer that finally reconciles OTIF against what actually shipped. Then group IT or an external auditor asks: where does our data actually live? And nobody can answer — not because the answer is bad (in most cases it is fine) but because nobody has had to produce it.
This question is answerable. Microsoft documents where data lands, and documents equally clearly what does not stay in your chosen region.
What data residency actually means in Microsoft Fabric
Residency is set by three separate things, configured independently: the tenant home region, which holds tenant metadata (Microsoft notes this metadata "can include customer data"); the capacity region, which determines where compute and OneLake storage sit for workspaces on that capacity; and the region of each external source system.
Three consequences follow. OneLake follows the capacity, not the tenant — each workspace belongs to a capacity tied to a region, and the underlying storage lands there. Direct Lake semantic models must sit in the same region as their source — creating one in a different region is unsupported, with a lakehouse-plus-shortcuts workaround. And Multi-Geo solves less than people assume — it places compute and OneLake in a geography other than the home region, but it does not move the home region, and it constrains where data rests without guaranteeing nothing ever touches another region.
Which Azure regions can a UAE manufacturer run Fabric in?
| Region | Physical location | Power BI | All Fabric workloads | Availability zones |
|---|---|---|---|---|
| UAE North (uaenorth) | Dubai | Yes | Yes | Yes |
| UAE Central (uaecentral) | Abu Dhabi | Yes | No — Power BI only | No |
| Qatar Central | Doha | Yes | No — Power BI only | — |
That single fact resolves most UAE residency conversations. A manufacturer wanting lakehouse, warehouse, Data Factory pipelines, notebooks and Real-Time Intelligence with data resting inside the UAE buys Fabric capacity in UAE North, and evidences it from the Azure portal. Two caveats practitioners get wrong: UAE Central will not run your lakehouse (a group standard or Abu Dhabi preference that pushes you there gets Power BI, not Fabric workloads); and the disaster-recovery position needs checking, because Azure pairs UAE North with UAE Central. Verify the table in Microsoft Learn before you commit — it changes.
What leaves the region: metadata, Copilot and AI processing
With capacity in UAE North and the tenant home region in the UAE, customer data rests in the UAE and tenant metadata sits in the home-region cluster. The material exception is Copilot and AI: for any capacity outside the US and the EU Data Boundary, Copilot in Fabric is disabled by default. Microsoft's position is that data processed by Copilot stays within your capacity's geographic region unless you explicitly allow otherwise — via three admin tenant settings that permit data sent to Azure OpenAI to be processed outside the region, stored outside the region, and conversation history retained outside the region (up to 28 days).
The trade-off is clear: a UAE manufacturer can have residency in UAE North, or it can have Copilot and Fabric Data Agent — but as documented today it cannot have both without an explicit, recorded decision to allow AI processing outside the region. On encryption the answer is simpler and worth having ready: all Fabric data stores are encrypted at rest with Microsoft-managed keys, and data in transit uses at least TLS 1.2.
The UAE regulatory landscape, described accurately
The UAE federal personal-data-protection law is Federal Decree-Law No. 45 of 2021, in force from 2 January 2022, applying broadly to processing of UAE data subjects' personal data including by controllers outside the UAE. DIFC and ADGM are not carve-outs from the federal law — they are separate jurisdictions with their own laws, regulators and live enforcement. Sector rules apply too, health data being the clearest case.
Say this plainly in any assessment: requirements differ by emirate, free zone and sector, and the federal detail is incomplete — the executive regulations have been pending for years. Where your position turns on which zone your entity is licensed in, which regulator supervises it, or how a transfer is characterised, get UAE-qualified legal advice rather than guessing.
What a UAE manufacturer is actually protecting
For most industrial businesses, personal data is the smaller half — the plant estate holds some HR and shift data, contractor records, CRM contacts. What it does hold is the commercially sensitive core: standard cost and margin by SKU, supplier pricing, yield by line. None of that is regulated by PDPL; all of it is regulated by customer contracts and group information-security policy.
So read the group policy and the customer contracts before you read the law. The answer follows the tighter constraint, and it usually is not the statutory one — the same failure mode as governance retrofitted rather than built in.
Read the group security policy and the big customer contracts before you read the law. The binding constraint on residency is usually contractual, not statutory.
The controls that satisfy most assessments
Five controls carry most of it. Region pinning — buy Fabric capacity in UAE North and assign every production workspace to it. Sensitivity labelling — apply Microsoft Purview labels to Fabric items so classification travels with the artefact. Access control — workspace roles, item permissions and OneLake data-access roles, reviewed quarterly against a named list. Audit logging — Fabric activity in the Purview audit log plus SQL audit logs on the warehouse holding sensitive tables (a log nobody reviews is not a control). And documented data flows — a one-page register: source system, what data, which region it enters Fabric in, who consumes it, whether anything crosses a border.
The question the auditor asks, and where the answer lives
| The auditor asks | Where to find it in your tenant |
|---|---|
| Which country is our data stored in? | Fabric Help → About → "Your data is stored in" — the tenant home region |
| Is that where the reports and lakehouse run? | Admin portal → Capacity settings (region per capacity), then each workspace → License info |
| Does any data leave the UAE? | Tenant metadata sits in the home-region cluster; if Multi-Geo is on, check the home-region metadata list |
| Does AI processing stay in region? | Admin portal → Tenant settings → Copilot/Azure OpenAI — the three "outside your region" settings, and whether they are on |
| Who can read cost and pricing data? | Workspace roles, item permissions, OneLake data-access roles, SQL GRANTs — export the list |
| How would you know who read them? | Purview audit log for Fabric activity; SQL audit logs on the Warehouse item |
| How is sensitive data classified? | Purview Information Protection labels; the sensitivity-label column in the item list |
| Where does this data come from and go? | Fabric lineage view per workspace, plus your data-flow register (lineage alone misses non-Fabric sources) |
| Is it encrypted? | Microsoft-managed keys at rest; TLS 1.2+ in transit — cite the Fabric security docs |
| What if the region fails? | Capacity DR setting; the paired region for UAE North is UAE Central — confirm what is offered |
Produce those ten answers with screenshots and you will pass most assessments a mid-market manufacturer faces. If you can produce none, the problem is documentation, not architecture.
Where this breaks, and what it does not fix
Region pinning does not cover your source systems — Fabric in UAE North is irrelevant if your SAP instance, MES historian or 3PL portal sits elsewhere and you pull from it. Multi-Geo does not give a clean single-country answer — permissions, credentials, report metadata and Purview Data Map metadata stay in the home region, and data in transit may cross geographies. Choosing residency today can cost you AI tomorrow — Copilot and Fabric Data Agent on a UAE North capacity require enabling cross-region processing.
Two more: moving a workspace later is not free — workspaces containing non-Power BI Fabric items cannot be moved between regions, and source data may remain in the old region for up to 30 days. And evidence decays — a pack assembled for one audit is stale within two quarters as capacities, workspaces and tenant settings change.
What to do first
Five questions to answer this week, before anyone opens the Azure portal:
- Where is your tenant home region today? Fabric Help → About → read the line
- Which capacities do you hold, in which regions, and which workspaces sit on each? A workspace on Pro or trial capacity has a region you did not choose
- What do the group security policy and your three largest customer contracts require on data location — and is that stricter than UAE law?
- Which datasets would cause real commercial damage if they left the business — standard cost, supplier pricing, yield by line — and are they in workspaces with a defensible access list?
- Are the three Copilot cross-region tenant settings on or off right now, and who decided?
We build Microsoft Fabric estates for manufacturers across the UAE, Saudi, India and the UK with region design, Purview labelling and the residency evidence pack treated as part of the build, not a retrofit.
The residency question is answerable — Microsoft documents where data lands and what leaves. Produce the ten auditor answers with screenshots and you pass most assessments; if you can produce none, the gap is documentation, not architecture. Book a diagnostic with Amit — no slides, no pitch deck, no obligation to proceed. Happy to build the evidence pack alongside the estate rather than after it.
Free Assessment
Where does your operation sit on the data maturity curve?
8 questions. 3 minutes. You get a scored breakdown across data infrastructure, analytics readiness, and automation potential — with a specific next step for your industry.