mourakshit's avatar
mourakshit
New Member
14 hours ago
Status:
New

Add Cross-Engine Effective Access Trace for OneLake Security

OneLake Security is designed to provide centralized security across Fabric experiences and query engines. As more workloads rely on the same security model, administrators need an easy way to understand why a specific user can or cannot access a specific table, row, or column. Please add an Effective Access Trace experience to OneLake Security. An administrator should be able to select a user or service principal, a OneLake object, and an access path, then see the complete security evaluation that produced the final result. The trace should show applicable OneLake roles, inherited permissions, table permissions, row filters, column restrictions, group membership, sensitivity or policy restrictions, and the final Allow or Deny decision. It should also show the effective result across supported access paths such as Spark, SQL analytics endpoint, Direct Lake, OneLake APIs, shortcuts, and authorized external engines. If access differs between engines, Fabric should clearly identify which rule or unsupported security behavior caused the difference. This would make centralized OneLake Security much easier to validate, troubleshoot, and operate in large enterprise environments.

No CommentsBe the first to comment

Recent ideas