Forum Discussion
Warehouse security when using Direct Lake models
Hi Everyone,
I have a warehouse that contains 2 schemas, support and finance.
I've built 2 Direct Lake models using the OneLake connector.
I am using item level permissions to ensure security.
It's my understanding that the users can only view the reports if they have 'read' and 'readall' item level permissions on the warehouse.
I'm trying to add granular permissions in T-SQL to prevent one group of users from accessing the finance schema, but it seems that the required item level permission 'readall' negates the rules I've added.
If a user gets access to a fabric capacity and creates a lakehouse, they can create a shortcut to the data that should be restricted.
Has anyone faced this issue and managed to resolve it? Is my only option creating separate warehouses?
I have received information from the OneLake security team stating that they are actively working on a warehouse solution. In the meantime, I'll need to create a separate warehouse for each schema to ensure security.
5 Replies
- v-shchada-msftCommunity Support
Hi wardy912,
Thank you for reaching out to the Microsoft Fabric Community Forum, and thanks to the tayloramy for sharing helpful insights.
Just checking in, were you able to resolve the issue using any of the suggestions provided? If not, please feel free to share an update, and we'll be happy to assist further.
Your feedback will also help others facing similar challenges.
Thank you! - wardy912Super User
I have received information from the OneLake security team stating that they are actively working on a warehouse solution. In the meantime, I'll need to create a separate warehouse for each schema to ensure security.