Forum Discussion

Luigia-Costabil's avatar
Luigia-Costabil
Advocate I
2 months ago
Solved

Roles needed for Dataverse shortcut from Fabric

Hi everyone,

I'm evaluating different options to integrate Dataverse with Microsoft Fabric and I'm looking for clarification regarding Dataverse Shortcuts and Service Principals.

According to the documentation, Dataverse Shortcuts support delegated authorization using either an Organizational Account or a Service Principal. However, I also found documentation stating that the account used to access Dataverse Managed Lake must have the System Administrator role.

My question is:

Has anyone successfully configured a Dataverse Shortcut using a Service Principal mapped to a Dataverse Application User with a custom security role (for example, a read-only role with access only to specific tables), instead of assigning the System Administrator role?

More specifically:

  • Is System Administrator strictly required for Dataverse Shortcuts?

  • Does Dataverse Managed Lake bypass the standard Dataverse security model?

  • Can a custom role with Read permissions on the required tables be used successfully with a Service Principal?

  • If not, is Link to Fabric the only recommended approach when following least-privilege principles?

I'd appreciate hearing about any real-world implementations or Microsoft guidance on this topic.

Thanks in advance!

  • Hello Luigia-Costabil 

    Microsoft documentation clearly states , "The account must have the system administrator permission to access data in Dataverse Managed Lake"

     

    Create a Dataverse shortcut - Microsoft Fabric | Microsoft Learn

     

    So, regardless you choose to use an organisational account or a service principal, you will need a system administrator role for Dataverse shortcuts. 

    Q: Is System Administrator strictly required for Dataverse Shortcuts?

    A: Yes


    Q: Does Dataverse Managed Lake bypass the standard Dataverse security model?

    A: Yes, it does not allow fine grained permissions - an admin level access is a hard requirement.

     

    Q: Can a custom role with Read permissions on the required tables be used successfully with a Service Principal?

    A: No


    Q: If not, is Link to Fabric the only recommended approach when following least-privilege principles?

    A: When you use Fabric Link, data is exposed into a Fabric Lakehouse + SQL endpoint, and access is governed by workspace/item permissions, not Dataverse roles. You choose this option when you have appropriate security design on your Fabric platform. 

     

1 Reply

  • Hello Luigia-Costabil 

    Microsoft documentation clearly states , "The account must have the system administrator permission to access data in Dataverse Managed Lake"

     

    Create a Dataverse shortcut - Microsoft Fabric | Microsoft Learn

     

    So, regardless you choose to use an organisational account or a service principal, you will need a system administrator role for Dataverse shortcuts. 

    Q: Is System Administrator strictly required for Dataverse Shortcuts?

    A: Yes


    Q: Does Dataverse Managed Lake bypass the standard Dataverse security model?

    A: Yes, it does not allow fine grained permissions - an admin level access is a hard requirement.

     

    Q: Can a custom role with Read permissions on the required tables be used successfully with a Service Principal?

    A: No


    Q: If not, is Link to Fabric the only recommended approach when following least-privilege principles?

    A: When you use Fabric Link, data is exposed into a Fabric Lakehouse + SQL endpoint, and access is governed by workspace/item permissions, not Dataverse roles. You choose this option when you have appropriate security design on your Fabric platform.