Forum Discussion
OneLake security problem creating a new role with write permissions
Hi all,
I have a Lakehouse and I need to create a role for enabling some users to Read and Write some files in a input folder
Path Files/Input
For this task I enabled OneLake security in preview and I am trying to create a new role.
But in this step I cannot find where can I add Write Permissions.
It is easy to add users to this role, but I can not find how to add extra permissions.
Viewing the old user interface was easy to add permissions.
So I am stuck because the only similar option is in Advanced configuration Adding permission groups but not sure is what I am looking for.
Need help
Regards
Hi dpombal,
I believe the only way to have write permissions is for the user to be a contributor or higher on the workspace.
I wish more granular permissions existed, and have hope that one day OneLake Security will be able to achieve this, but right now I don't think there's another solution other than granting workspace level roles.
If you found this helpful, consider giving some Kudos. If I answered your question or solved your problem, mark this post as the solution.
5 Replies
- v-hashadapu
Community Support
Hi dpombal , Thank you for reaching out to the Microsoft Community Forum.
The reason you can only assign Read to the Input folder in the new OneLake security preview is because that feature is designed only for controlling data visibility, not for granting Write capability. The UI intentionally limits folder level permissions to Read because Fabric does not support folder level Write inside a Lakehouse.
Write access is still handled the old way, at the Lakehouse item level, not at the folder level. So, if someone needs to upload, edit or delete files in Files/Input, you must give them Write permission on the entire Lakehouse through Manage permissions. Once they have that, they automatically have Write access to every folder. The new roles simply can’t override that model. They can restrict or organize Read access but Write remains an item wide permission.
- dpombal
Post Partisan
Hi I am checking Lakehouse Manage permissions and it only appears the possibility of assigning read permissions
For the user not included in this workspace this is only option I see
Can you help me
regards
- tayloramy
Super User
Hi dpombal,
I believe the only way to have write permissions is for the user to be a contributor or higher on the workspace.
I wish more granular permissions existed, and have hope that one day OneLake Security will be able to achieve this, but right now I don't think there's another solution other than granting workspace level roles.
If you found this helpful, consider giving some Kudos. If I answered your question or solved your problem, mark this post as the solution.
- v-hashadapu
Community Support
- dpombal
Post Partisan
I accept the solution but it is a limitation to have to add a user as contributor, Item level permissions must allow in future to create write permission users,thanks