JonBFabric's avatar
JonBFabric
Helper I
7 months ago
Status:
New

Using Column Level Security with Shortcuts

The introduction of column level security, as part of the OneLake security model, is a massive leap forward in terms of effective security administration. However, it is an apparently known limitation that CLS does not work if used via an internal shortcut. I administer a centralised data repository, and my users wish to be able to shortcut from this and work with all their data as if it was local to their workspace. Are there any current plans to support this?

3 Comments

  • MadhuviGupta's avatar
    MadhuviGupta
    Microsoft Employee
    We have a similar request within our team to support CLS with shortcuts, and we’re keen to hear any updates on this.
  • We currently operate a hub-and-spoke architecture across multiple Fabric/Power BI workspaces. The Hub serves as the central data engineering and ingestion layer, while the Spokes serve as the downstream analytics workspaces for reporting and semantic modeling. Please provide this feature to support shortcuts transformation with Column-Level Security (CLS) applied, as it is critical for us to cross-share data between these workspaces while enforcing OneLake security policies.
  • Today, one could add OneLake Security roles on the lakehouse (assuming it's a lakehouse) in the hub. When a user is accessing content in the spoke workspaces, via the shortcut, their identity can "flow" to the lakehouse in the central workspace, where OneLake Security (and its CLS) would be applied. Right? Wouldn't this solve it?

Recent ideas