<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hub Workspace with Centralised Lakehouse in Data Engineering</title>
    <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Hub-Workspace-with-Centralised-Lakehouse/m-p/5189963#M16440</link>
    <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/688040"&gt;@VictorMed&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Checking in to see if your issue has been resolved. let us know if you still need any assistance.&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Thu, 28 May 2026 11:43:24 GMT</pubDate>
    <dc:creator>v-saisrao-msft</dc:creator>
    <dc:date>2026-05-28T11:43:24Z</dc:date>
    <item>
      <title>Hub Workspace with Centralised Lakehouse</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Hub-Workspace-with-Centralised-Lakehouse/m-p/5184538#M16259</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We want to share company-wide data across multiple teams in a centralised lakehouse with schemas.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our current approach has been:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;New Workspace where only the admin security group has a role (admin)&lt;/LI&gt;&lt;LI&gt;Created 3 new security groups that are mutually exclusive (Executive, SLT, Employees)&lt;/LI&gt;&lt;LI&gt;Created a new Lakehouse with a schema created and named after each security group&lt;/LI&gt;&lt;LI&gt;Directly shared the lakehouse with each security group, with only read permissions&lt;/LI&gt;&lt;LI&gt;Deleted DefaultReader role&lt;/LI&gt;&lt;LI&gt;Created a OneLake security role for each security group with only access to their schema&lt;/LI&gt;&lt;LI&gt;Created a custom DB role in SQL security to grant access to their schema and deny select to the other 2 schemas&lt;/LI&gt;&lt;LI&gt;Revoke select to all schemas from public&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the above steps, I have test accounts in each security group, and currently, they can't access the lakehouse or SQL endpoint via portal or SSMS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If sharing the workspace with viewer access, all accounts have access, bypassing SQL security, which defeats the purpose of the solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I missing something?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Victor&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2026 10:52:22 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Hub-Workspace-with-Centralised-Lakehouse/m-p/5184538#M16259</guid>
      <dc:creator>VictorMed</dc:creator>
      <dc:date>2026-05-18T10:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: Hub Workspace with Centralised Lakehouse</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Hub-Workspace-with-Centralised-Lakehouse/m-p/5184649#M16268</link>
      <description>&lt;P&gt;I think that 4.&amp;nbsp; only gives "read" access to semantic data, not the actual data.&amp;nbsp; You need to specifically grant readall for the data.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2026 12:58:26 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Hub-Workspace-with-Centralised-Lakehouse/m-p/5184649#M16268</guid>
      <dc:creator>lbendlin</dc:creator>
      <dc:date>2026-05-18T12:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Hub Workspace with Centralised Lakehouse</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Hub-Workspace-with-Centralised-Lakehouse/m-p/5185467#M16286</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/688040"&gt;@VictorMed&lt;/a&gt;,&lt;BR /&gt;&lt;SPAN&gt;Looks like the issue is the difference between workspace access and SQL security.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Your schema permissions only affect the SQL endpoint, but once users get Viewer access to the workspace, they can access the Lakehouse more broadly through the Fabric portal.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Also worth checking the removal of the DefaultReader role, since that can break normal Lakehouse access.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;From what I have seen, Fabric still does not fully support strict schema isolation inside a single shared Lakehouse in the same way SQL Server does.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Most people end up separating access using different Lakehouses, workspaces, or semantic models instead.&lt;BR /&gt;&lt;BR /&gt;Docs:&lt;BR /&gt;&lt;A title="Data security overview" href="https://learn.microsoft.com/en-us/fabric/onelake/security/get-started-security" target="_self"&gt;Data security overview&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;A title="SQL granular permissions in Microsoft Fabric" href="https://learn.microsoft.com/en-us/fabric/data-warehouse/sql-granular-permissions" target="_self"&gt;SQL granular permissions in Microsoft Fabric&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2026 14:36:19 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Hub-Workspace-with-Centralised-Lakehouse/m-p/5185467#M16286</guid>
      <dc:creator>Olufemi7</dc:creator>
      <dc:date>2026-05-19T14:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: Hub Workspace with Centralised Lakehouse</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Hub-Workspace-with-Centralised-Lakehouse/m-p/5188160#M16351</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/688040"&gt;@VictorMed&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Have you had a chance to review the solution we shared by &lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/100342"&gt;@lbendlin&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/843006"&gt;@Olufemi7&lt;/a&gt;? If the issue persists, feel free to reply so we can help further.&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2026 04:27:58 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Hub-Workspace-with-Centralised-Lakehouse/m-p/5188160#M16351</guid>
      <dc:creator>v-saisrao-msft</dc:creator>
      <dc:date>2026-05-25T04:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Hub Workspace with Centralised Lakehouse</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Hub-Workspace-with-Centralised-Lakehouse/m-p/5189963#M16440</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/688040"&gt;@VictorMed&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Checking in to see if your issue has been resolved. let us know if you still need any assistance.&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2026 11:43:24 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Hub-Workspace-with-Centralised-Lakehouse/m-p/5189963#M16440</guid>
      <dc:creator>v-saisrao-msft</dc:creator>
      <dc:date>2026-05-28T11:43:24Z</dc:date>
    </item>
  </channel>
</rss>

