Mourak's avatar
Mourak
New Member
3 days ago
Status:
New

Add an "Explain Effective Access" Experience for OneLake Security

As OneLake Security expands across tables, folders, rows, columns and shortcuts, determining why a specific user can or cannot access data can become difficult.

I would like Microsoft Fabric to provide an "Explain Effective Access" experience for OneLake.

An administrator should be able to select a user, service principal or group and a OneLake path and see:

- workspace and item permissions

- applicable OneLake security roles

- RLS and CLS policies

- shortcut-path permissions

- target-path permissions

- whether passthrough or delegated authentication is being used

- which identity each query engine uses

- the resulting effective access

- the specific rule responsible for allowing or blocking access

The same information should be available through an API for security automation and audit tooling.

This would significantly simplify troubleshooting, security reviews and least-privilege validation in enterprise Fabric environments.

No CommentsBe the first to comment

Recent ideas