<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lakehouse sharing without workspace access causes 403 in Data Engineering</title>
    <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4916708#M14530</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We opened a support ticket with Microsoft. According to their response, workspace permissions are required to view a Lakehouse from the OneLake Catalog and Explorer UI. To open and view Lakehouse tables in the Fabric UI, a user must have one of the following workspace roles: Contributor, Member, or Admin. So the problem is resolved.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Jan 2026 12:45:29 GMT</pubDate>
    <dc:creator>fatma_akyol</dc:creator>
    <dc:date>2026-01-12T12:45:29Z</dc:date>
    <item>
      <title>Lakehouse sharing without workspace access causes 403</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910212#M14336</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We created a OneLake security role and granted access to specific tables.&amp;nbsp;&lt;BR /&gt;Then we shared the Lakehouse with the same user using &lt;STRONG&gt;Read and ReadAll permissions via&amp;nbsp;&lt;BR /&gt;Lakehouse → Manage permissions.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The user does NOT have any workspace role (Viewer/Contributor).&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;According to the official Microsoft documentation, Lakehouse data can be shared&amp;nbsp;&lt;BR /&gt;without granting workspace access:&lt;BR /&gt;&lt;A title="https://learn.microsoft.com/en-us/fabric/data-engineering/lakehouse-sharing" href="https://learn.microsoft.com/en-us/fabric/data-engineering/lakehouse-sharing" target="_blank" rel="noreferrer noopener"&gt;https://learn.microsoft.com/en-us/fabric/data-engineering/lakehouse-sharing&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, when the user tries to open the from the OneLake Catalog,&amp;nbsp;&lt;BR /&gt;they receive the following error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;"User is not authorized to perform this operation. (403)"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;P&gt;1. Is workspace access still required to open a Lakehouse from OneLake Catalog UI, even when the Lakehouse is shared directly?&lt;/P&gt;&lt;P&gt;2. How can we share lakehouse without workspace-level access?&lt;/P&gt;&lt;P&gt;Any clarification or guidance would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2025 08:19:18 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910212#M14336</guid>
      <dc:creator>fatma_akyol</dc:creator>
      <dc:date>2025-12-30T08:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: Lakehouse sharing without workspace access causes 403</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910223#M14337</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have faced this issue so many times but I could not find any solution except giving viewer acces in workspace. I think there is something a bug or misunderstanding.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Happy new year&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2025 08:34:54 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910223#M14337</guid>
      <dc:creator>ismail_ozturk</dc:creator>
      <dc:date>2025-12-30T08:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: Lakehouse sharing without workspace access causes 403</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910254#M14340</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/1365949"&gt;@fatma_akyol&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;Lakehouse sharing should work without giving the user any workspace role—but a 403 can still happen depending on how OneLake security and the SQL Analytics endpoint are configured.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;OL&gt;&lt;LI&gt;Prerequisite for ReadAll&lt;/LI&gt;&lt;/OL&gt;&lt;UL&gt;&lt;LI&gt;ReadAll is an additional permission that only works on top of either Read (item-level sharing) or a workspace Viewer role. You already granted Read (good), so this prerequisite should be satisfied.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;OL&gt;&lt;LI&gt;OneLake security (preview) changes the access model&lt;/LI&gt;&lt;/OL&gt;&lt;UL&gt;&lt;LI&gt;If you turned on Manage OneLake security (preview) for the lakehouse, users must be in a data access role to see data; users not in a role “see no data in that item.” A default role (DefaultReader) is created to keep existing read access for users who had ReadAll; if you removed ReadAll and didn’t add the user to a role, they may get 403 trying to browse/open via OneLake Catalog.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;OL&gt;&lt;LI&gt;SQL Analytics endpoint identity mode&lt;/LI&gt;&lt;/OL&gt;&lt;UL&gt;&lt;LI&gt;With OneLake table/folder security enabled, the lakehouse’s SQL Analytics endpoint must be set to “User’s identity mode” (Security tab). If it’s still using a fixed/delegated identity, authorization can fail for users without workspace roles, leading to 403.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;How to Fix&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Verify sharing permissions on the Lakehouse&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;In Lakehouse → … → Manage permissions → Direct access, confirm the user/group has Read (not just ReadAll).&lt;/LI&gt;&lt;LI&gt;If you rely on ReadAll for Spark, keep Read as well; ReadAll alone doesn’t grant lakehouse data access.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If OneLake security (preview) is ON, add the user to a data access role&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Go to Lakehouse → Manage OneLake security (preview).&lt;/LI&gt;&lt;LI&gt;Create/choose a role and grant Read (and optionally ReadWrite if needed).&lt;/LI&gt;&lt;LI&gt;Add the user/group to that role and include the specific tables/folders they should access.&lt;/LI&gt;&lt;LI&gt;Ensure they’re not still in the DefaultReader role if you intend to restrict them; otherwise, they keep full read access.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Switch the SQL Analytics endpoint to “User’s identity mode”&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Open the SQL Analytics endpoint → Settings → Security and set User’s identity mode.&lt;/LI&gt;&lt;LI&gt;This is required for OneLake table/folder security scenarios to authorize the actual user, not a fixed owner identity.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope this fixes your problem, kindly appreciate giving a &lt;STRONG&gt;Kudos&lt;/STRONG&gt; or accept as a &lt;STRONG&gt;Solution&lt;/STRONG&gt;!&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 30 Dec 2025 10:38:16 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910254#M14340</guid>
      <dc:creator>deborshi_nag</dc:creator>
      <dc:date>2025-12-30T10:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: Lakehouse sharing without workspace access causes 403</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910258#M14341</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/1445078"&gt;@deborshi_nag&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;The user has &lt;STRONG&gt;Read, ReadAll, and SubscribeOneLakeEvents&lt;/STRONG&gt; permissions.&lt;BR /&gt;We assigned the user to a OneLake security role and granted access to specific tables within this role.&lt;BR /&gt;Additionally, "&lt;STRONG&gt;User’s identity mode is enabled&lt;/STRONG&gt;" on the SQL Analytics Endpoint.&lt;/P&gt;&lt;P&gt;We have already applied all of the recommendations mentioned above; however, the issue still persists.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2025 10:49:11 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910258#M14341</guid>
      <dc:creator>fatma_akyol</dc:creator>
      <dc:date>2025-12-30T10:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Lakehouse sharing without workspace access causes 403</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910272#M14342</link>
      <description>&lt;P&gt;Have you removed the user from the&amp;nbsp;&lt;STRONG&gt;DefaultReader&amp;nbsp;&lt;/STRONG&gt;role?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2025 11:19:33 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910272#M14342</guid>
      <dc:creator>deborshi_nag</dc:creator>
      <dc:date>2025-12-30T11:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: Lakehouse sharing without workspace access causes 403</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910287#M14343</link>
      <description>&lt;P&gt;Yes. We removed&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2025 11:33:31 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910287#M14343</guid>
      <dc:creator>fatma_akyol</dc:creator>
      <dc:date>2025-12-30T11:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: Lakehouse sharing without workspace access causes 403</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910309#M14346</link>
      <description>&lt;DIV&gt;The user should open the lakehouse from &lt;STRONG&gt;Browse → Shared with me&lt;/STRONG&gt; and from &lt;STRONG&gt;OneLake Catalog&lt;/STRONG&gt;. The item appears when sharing is configured correctly.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Let me know if you're getting the error here.&lt;/DIV&gt;</description>
      <pubDate>Tue, 30 Dec 2025 12:00:18 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910309#M14346</guid>
      <dc:creator>deborshi_nag</dc:creator>
      <dc:date>2025-12-30T12:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: Lakehouse sharing without workspace access causes 403</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910363#M14351</link>
      <description>&lt;P&gt;The user can see the Lakehouse in the &lt;STRONG&gt;Shared with me&lt;/STRONG&gt; section of the OneLake Catalog.&lt;BR /&gt;However, when the user tries to open the Lakehouse from the catalog, a &lt;STRONG&gt;403 – Not authorized&lt;/STRONG&gt;&amp;nbsp;error is returned.&lt;BR /&gt;Despite this, the user can access the&lt;STRONG&gt; SQL Analytics Endpoint&lt;/STRONG&gt; without any issues from catalog.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2025 13:28:11 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4910363#M14351</guid>
      <dc:creator>fatma_akyol</dc:creator>
      <dc:date>2025-12-30T13:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: Lakehouse sharing without workspace access causes 403</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4913632#M14456</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/1365949"&gt;@fatma_akyol&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you for reaching out to Microsoft Fabric Community.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/1445078"&gt;@deborshi_nag&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/1258378"&gt;@ismail_ozturk&lt;/a&gt;&amp;nbsp;for the prompt response.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is expected behaviour in microsoft fabric. While Lakehouse data access can be shared without workspace roles using item level sharing but the lakehouse UI still requires workspace permissions.&lt;/P&gt;
&lt;P&gt;Currently there is no supported way to open the lakehouse UI without granting at least Viewer access to the workspace. Your configuration is correct and the 403 error is expected.&lt;/P&gt;
&lt;P&gt;I recommend submitting your detailed feedback and ideas through Microsoft's official feedback channels. Feedback submitted through these channels is frequently reviewed by the product teams and can contribute to meaningful improvements.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.fabric.microsoft.com/t5/Fabric-Ideas/idb-p/fbc_ideas/ideas/search-ideas" target="_blank"&gt;Fabric Ideas - Microsoft Fabric Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and regards,&lt;/P&gt;
&lt;P&gt;Anjan Kumar Chippa&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2026 05:56:25 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4913632#M14456</guid>
      <dc:creator>v-achippa</dc:creator>
      <dc:date>2026-01-07T05:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: Lakehouse sharing without workspace access causes 403</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4916336#M14516</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/1365949"&gt;@fatma_akyol&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As we haven’t heard back from you, we wanted to kindly follow up to&amp;nbsp;check if your issue is resolved? If not have you raised this in the ideas forum?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and regards,&lt;/P&gt;
&lt;P&gt;Anjan Kumar Chippa&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 04:32:36 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4916336#M14516</guid>
      <dc:creator>v-achippa</dc:creator>
      <dc:date>2026-01-12T04:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: Lakehouse sharing without workspace access causes 403</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4916708#M14530</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We opened a support ticket with Microsoft. According to their response, workspace permissions are required to view a Lakehouse from the OneLake Catalog and Explorer UI. To open and view Lakehouse tables in the Fabric UI, a user must have one of the following workspace roles: Contributor, Member, or Admin. So the problem is resolved.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 12:45:29 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4916708#M14530</guid>
      <dc:creator>fatma_akyol</dc:creator>
      <dc:date>2026-01-12T12:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: Lakehouse sharing without workspace access causes 403</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4917299#M14548</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/1365949"&gt;@fatma_akyol&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for confirming that the issue is resolved now. Thank you for being part of&amp;nbsp;&lt;SPAN&gt;Microsoft Fabric Community.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and regards,&lt;/P&gt;
&lt;P&gt;Anjan Kumar Chippa&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 10:58:59 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Lakehouse-sharing-without-workspace-access-causes-403/m-p/4917299#M14548</guid>
      <dc:creator>v-achippa</dc:creator>
      <dc:date>2026-01-13T10:58:59Z</dc:date>
    </item>
  </channel>
</rss>

