Forum Discussion

dpombal's avatar
dpombal
Icon for Post Partisan rankPost Partisan
9 months ago
Solved

OneLake security problem creating a new role with write permissions

Hi all, 

I have a Lakehouse and I need to create a role for enabling some users to Read and Write some files in a input folder

Path Files/Input

 

For this task I enabled OneLake security in preview and I am trying to create a  new role.

 

 

But in this step I cannot find where can I add Write Permissions

 

It is easy to add users to this role, but I can not find how to add extra permissions.

Viewing the old user interface was easy to add permissions.

 

So I am stuck because  the only similar option is in Advanced configuration Adding permission groups but not sure is what I am looking for.

 

 

Need help

 

Regards

  • Hi dpombal

     

    I believe the only way to have write permissions is for the user to be a contributor or higher on the workspace. 

     

    I wish more granular permissions existed, and have hope that one day OneLake Security will be able to achieve this, but right now I don't think there's another solution other than granting workspace level roles. 

     

    If you found this helpful, consider giving some Kudos. If I answered your question or solved your problem, mark this post as the solution. 

5 Replies

  • v-hashadapu's avatar
    v-hashadapu
    Icon for Community Support rankCommunity Support

    Hi dpombal , Thank you for reaching out to the Microsoft Community Forum.

     

    The reason you can only assign Read to the Input folder in the new OneLake security preview is because that feature is designed only for controlling data visibility, not for granting Write capability. The UI intentionally limits folder level permissions to Read because Fabric does not support folder level Write inside a Lakehouse.

     

    Write access is still handled the old way, at the Lakehouse item level, not at the folder level. So, if someone needs to upload, edit or delete files in Files/Input, you must give them Write permission on the entire Lakehouse through Manage permissions. Once they have that, they automatically have Write access to every folder. The new roles simply can’t override that model. They can restrict or organize Read access but Write remains an item wide permission.

  • dpombal's avatar
    dpombal
    Icon for Post Partisan rankPost Partisan

    Hi I am checking Lakehouse Manage permissions and it only appears the possibility of assigning read permissions

    For the user not included in this workspace this is only option I see

    Can you help me

    regards

    • tayloramy's avatar
      tayloramy
      Icon for Super User rankSuper User

      Hi dpombal

       

      I believe the only way to have write permissions is for the user to be a contributor or higher on the workspace. 

       

      I wish more granular permissions existed, and have hope that one day OneLake Security will be able to achieve this, but right now I don't think there's another solution other than granting workspace level roles. 

       

      If you found this helpful, consider giving some Kudos. If I answered your question or solved your problem, mark this post as the solution. 

  • v-hashadapu's avatar
    v-hashadapu
    Icon for Community Support rankCommunity Support

    Hi dpombal , Thank you for reaching out to the Microsoft Community Forum.

     

    We find the answer shared by tayloramy  is appropriate. Can you please confirm if the solution worked for you. It will help others with similar issues find the answer easily.

     

    Thank you tayloramy for your valuable response.

    • dpombal's avatar
      dpombal
      Icon for Post Partisan rankPost Partisan

      I accept the solution but it is a limitation to have to add a user as contributor, Item level permissions must allow in future to create write permission users,thanks