Forum Discussion

NotebookEnjoyer's avatar
NotebookEnjoyer
Advocate II
5 months ago
Solved

Options for non-personalized external data sharing

Hello,

we are using external data sharing to have shortcuts cross-tenant. When you create a share, you enter one (and only one!) mail address. Apparently, this mail address must be associated with a Fabric account for the sharing to work. This arrangement seems highly counterproductive for us: First, we would need to create several shares for every team member to have access; second, the shares would then be tied to personal accounts instead of the security group that we have for exactly this kind of situation.

Is there a better way? This current mode of external sharing seems to be not very well designed.

9 Replies

  • OnurOz's avatar
    OnurOz
    Resolver III

    Hi,

    Why not using Azure AD B2B with Security Groups?


    Instead of sharing directly to individual emails:

    - Invite the external users into your tenant via Azure AD B2B.

    - Add those users to a security group.

    - Grant Fabric workspace or item access to that security group.


    This way you manage access centrally and no need to create multiple shares per person.

    This is the most scalable pattern.

    Best

    Onur


    😊 If this post helped you, feel free to give it some Kudos! 👍

    And if it answered your question, please mark it as the accepted solution.


  • OnurOz's avatar
    OnurOz
    Resolver III

    Do you want Shared access to the same data or Independent copy of the data in Tenant B?

    These are very different architectures.

    • NotebookEnjoyer's avatar
      NotebookEnjoyer
      Advocate II

      I don't want an independent copy; I want the kind of access in tenant B that a shortcut would provide: read it as if it's just another table in the lakehouse.

  • Hello NotebookEnjoyer 

     

    For Fabric External Data Sharing (OneLake shortcuts):

    • You must specify one recipient email per share
    • That email must correspond to a Fabric‑capable identity
    • There is no support for multiple emails per share
    • No security groups
    • No aliases

    This is a known limitation today. External data shares are user‑bound, not group‑bound.

     

    Workaround: Entra B2B guest + Fabric permissions

    • Invite users via Entra B2B
    • Add them to an Entra security group
    • Grant Fabric workspace / Lakehouse access to the group

    Change the Fabric tenant settings -

    - Allow external guest users to access Fabric
    - Allow sharing with external users
     
    • NotebookEnjoyer's avatar
      NotebookEnjoyer
      Advocate II

      How would I get the data to the other tenant with the workaround approach?