Forum Discussion
SELECT permissions or external policy action error. OneLake Security issue
- 8 months ago
Hi mkjit256,
Despite the Fabric documentation clearly supporting this scenario in principle, configuring access in SQL Endpoint via OneLake Security is still maturing. For your use case, it would be best to limit user access in:
- Lakehouse: using OneLake Security
- SQL Endpoint: Grant/Deny T-SQL statements (switch back to Delegated Identity mode)
This approach works like a charm!
Hi mkjit256
Thank you for reaching out to the Microsoft Fabric community forum.
The behavior you are experiencing is normal for Microsoft Fabric. OneLake security works at the storage layer, controlling access to files and folders in Delta tables, but it doesn't affect SQL permissions for the Lakehouse SQL analytics endpoint.
The SQL endpoint manages its own authorization separately. With User’s identity access mode, the SQL engine checks each user's identity, and OneLake table-level roles don’t map to SQL permissions or metadata visibility. This means a user might be able to read a table in Lakehouse (Spark/OneLake), but still see an empty schema or get a “SELECT permissions or external policy action was denied” error when using the SQL endpoint.
Power BI enforces the same rules. Direct Lake semantic models and Power BI Desktop depend on SQL metadata and authorization, so visuals or connections will fail if the user lacks the necessary SQL access, even if they have OneLake storage access. This reflects the current Microsoft Fabric security design and isn't due to a bug or configuration issue.
For more details, please refer to the Microsoft official documentation on
https://learn.microsoft.com/en-us/fabric/onelake/security/get-started-security
https://learn.microsoft.com/en-us/fabric/data-engineering/lakehouse-sql-analytics-endpoint#security
https://learn.microsoft.com/en-us/fabric/data-engineering/lakehouse-sql-analytics-endpoint.
If you have any more questions, please let us know and we’ll be happy to help.
Regards,
Microsoft Fabric Community Support Team.
- mkjit2568 months ago
Helper IV
Thanks for your reply, so if the developer wants to connect the table he is permitted to see in his onelake security role from power bi desktop (to create a report), who would he be able to do that? This is really the aim.