<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Granular lakehouse data security with Workspace Private Links in Data Engineering</title>
    <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Granular-lakehouse-data-security-with-Workspace-Private-Links/m-p/4920947#M14630</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/1381761"&gt;@KimMW&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Right now there is no nice way to enforce RLS with private links.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;OneLake Security&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;isn't currently supported when a workspace-level private link is enabled for a workspace.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;It does appear that the private link will work with the SQL Endpoint:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/en-us/fabric/security/security-workspace-level-private-links-support?tabs=fabric-portal-1%2Cfabric-portal-2%2Cfabric-portal-3%2Cfabric-portal-4%2Cfabric-portal-5%2Cfabric-portal-6%2Cfabric-portal-7%2Cfabric-portal-8%2Cfabric-portal-9%2Cfabric-portal-10%2Cfabric-portal-11%2Cfabric-portal-12%2Cfabric-portal-13%2Cfabric-portal-14#sql-endpoint-support" target="_blank"&gt;Supported scenarios for workspace private links - Microsoft Fabric | Microsoft Learn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But that would not work when working in Notebooks or anything that accesses the data through OneLake.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jan 2026 14:34:04 GMT</pubDate>
    <dc:creator>tayloramy</dc:creator>
    <dc:date>2026-01-19T14:34:04Z</dc:date>
    <item>
      <title>Granular lakehouse data security with Workspace Private Links</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Granular-lakehouse-data-security-with-Workspace-Private-Links/m-p/4920885#M14627</link>
      <description>&lt;P&gt;Good afternoon!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Workspace-level private links documentation says that it doesn't support Item sharing or OneLake Security (&lt;A href="https://learn.microsoft.com/en-us/fabric/security/security-workspace-level-private-links-support" target="_blank" rel="noopener"&gt;https://learn.microsoft.com/en-us/fabric/security/security-workspace-level-private-links-support&lt;/A&gt;).&amp;nbsp;Is there any way to enforce RLS/CLS on access to Lakehouse data in a scenario where workspace-level private links are in use?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kim&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jan 2026 13:33:07 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Granular-lakehouse-data-security-with-Workspace-Private-Links/m-p/4920885#M14627</guid>
      <dc:creator>KimMW</dc:creator>
      <dc:date>2026-01-19T13:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: Granular lakehouse data security with Workspace Private Links</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Granular-lakehouse-data-security-with-Workspace-Private-Links/m-p/4920947#M14630</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/1381761"&gt;@KimMW&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Right now there is no nice way to enforce RLS with private links.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;OneLake Security&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;isn't currently supported when a workspace-level private link is enabled for a workspace.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;It does appear that the private link will work with the SQL Endpoint:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/en-us/fabric/security/security-workspace-level-private-links-support?tabs=fabric-portal-1%2Cfabric-portal-2%2Cfabric-portal-3%2Cfabric-portal-4%2Cfabric-portal-5%2Cfabric-portal-6%2Cfabric-portal-7%2Cfabric-portal-8%2Cfabric-portal-9%2Cfabric-portal-10%2Cfabric-portal-11%2Cfabric-portal-12%2Cfabric-portal-13%2Cfabric-portal-14#sql-endpoint-support" target="_blank"&gt;Supported scenarios for workspace private links - Microsoft Fabric | Microsoft Learn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But that would not work when working in Notebooks or anything that accesses the data through OneLake.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jan 2026 14:34:04 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Granular-lakehouse-data-security-with-Workspace-Private-Links/m-p/4920947#M14630</guid>
      <dc:creator>tayloramy</dc:creator>
      <dc:date>2026-01-19T14:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: Granular lakehouse data security with Workspace Private Links</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Granular-lakehouse-data-security-with-Workspace-Private-Links/m-p/4920950#M14632</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/1381761"&gt;@KimMW&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, however, OneLake Security cannot be applied directly within the Lakehouse when using workspace-level private links.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;RLS/CLS enforcement at the Lakehouse storage layer is not possible in this scenario, as OneLake Security is unsupported with workspace-level private links.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Microsoft has highlighted this restriction as you rightly mention:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Workspace-level private links do not support OneLake Security (which includes RLS and CLS), meaning item-level and table-level access controls are not enforced at this layer.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Consequently, OneLake Security RLS/CLS will not be effective if your configuration relies on private links.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nonetheless, RLS at the model layer remains fully operational, as:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;RLS within Semantic Models (Direct Lake / Import / DirectQuery) is managed by the Power BI engine, rather than OneLake.&lt;/LI&gt;&lt;LI&gt;This approach is recommended when OneLake Security is unavailable or not preferred, such as when workspace private links are in use.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This aligns with Microsoft’s guidance for implementing RLS in supported Fabric engines, including SQL Analytics Endpoint and semantic models.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="https://learn.microsoft.com/en-us/fabric/onelake/security/row-level-security" href="https://learn.microsoft.com/en-us/fabric/onelake/security/row-level-security" target="_blank" rel="noreferrer noopener"&gt;Row-level security - Microsoft Fabric | Microsoft Learn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps - please appreciate by leaving a &lt;STRONG&gt;Kudos&lt;/STRONG&gt; or accepting as a &lt;STRONG&gt;Solution&lt;/STRONG&gt;!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jan 2026 14:38:00 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Granular-lakehouse-data-security-with-Workspace-Private-Links/m-p/4920950#M14632</guid>
      <dc:creator>deborshi_nag</dc:creator>
      <dc:date>2026-01-19T14:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Granular lakehouse data security with Workspace Private Links</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Granular-lakehouse-data-security-with-Workspace-Private-Links/m-p/4920951#M14633</link>
      <description>&lt;P&gt;Thank you for confirming&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/1340679"&gt;@tayloramy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given that item sharing isn't supported with Workspace Private Link, how can one use the SQL Endpoint in these scenarios to give access in this way? Does the user have to have been granted access directly to the workspace the lakehouse is in?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jan 2026 14:38:27 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Granular-lakehouse-data-security-with-Workspace-Private-Links/m-p/4920951#M14633</guid>
      <dc:creator>KimMW</dc:creator>
      <dc:date>2026-01-19T14:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: Granular lakehouse data security with Workspace Private Links</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Granular-lakehouse-data-security-with-Workspace-Private-Links/m-p/4920953#M14635</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/1381761"&gt;@KimMW&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I do believe that workspace access needs to be granted.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jan 2026 14:40:27 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Granular-lakehouse-data-security-with-Workspace-Private-Links/m-p/4920953#M14635</guid>
      <dc:creator>tayloramy</dc:creator>
      <dc:date>2026-01-19T14:40:27Z</dc:date>
    </item>
  </channel>
</rss>

