<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Warehouse security when using Direct Lake models in Data Warehouse</title>
    <link>https://community.fabric.microsoft.com/t5/Data-Warehouse/Warehouse-security-when-using-Direct-Lake-models/m-p/5160865#M4503</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="475583" data-lia-user-login="wardy912" class="lia-mention lia-mention-user"&gt;wardy912&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You shouldn't need to grant readall if you have granted grnaular item level security on the tables in your warehouse.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note that if the permissions are applied on the TSQL level, then you will need to use DirectLake on SQL, not DirectLake on OneLake.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Apr 2026 13:52:55 GMT</pubDate>
    <dc:creator>tayloramy</dc:creator>
    <dc:date>2026-04-29T13:52:55Z</dc:date>
    <item>
      <title>Warehouse security when using Direct Lake models</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Warehouse/Warehouse-security-when-using-Direct-Lake-models/m-p/5160750#M4500</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I have a warehouse that contains 2 schemas, support and finance.&lt;BR /&gt;I've built 2 Direct Lake models using the OneLake connector.&lt;/P&gt;
&lt;P&gt;I am using item level permissions to ensure security.&lt;/P&gt;
&lt;P&gt;It's my understanding that the users can only view the reports if they have 'read' and 'readall' item level permissions on the warehouse.&lt;/P&gt;
&lt;P&gt;I'm trying to add granular permissions in T-SQL to prevent one group of users from accessing the finance schema, but it seems that the required item level permission 'readall' negates the rules I've added.&lt;BR /&gt;&lt;BR /&gt;If a user gets access to a fabric capacity and creates a lakehouse, they can create a shortcut to the data that should be restricted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone faced this issue and managed to resolve it? Is my only option creating separate warehouses?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 09:55:22 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Warehouse/Warehouse-security-when-using-Direct-Lake-models/m-p/5160750#M4500</guid>
      <dc:creator>wardy912</dc:creator>
      <dc:date>2026-04-29T09:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: Warehouse security when using Direct Lake models</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Warehouse/Warehouse-security-when-using-Direct-Lake-models/m-p/5160865#M4503</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="475583" data-lia-user-login="wardy912" class="lia-mention lia-mention-user"&gt;wardy912&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You shouldn't need to grant readall if you have granted grnaular item level security on the tables in your warehouse.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note that if the permissions are applied on the TSQL level, then you will need to use DirectLake on SQL, not DirectLake on OneLake.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 13:52:55 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Warehouse/Warehouse-security-when-using-Direct-Lake-models/m-p/5160865#M4503</guid>
      <dc:creator>tayloramy</dc:creator>
      <dc:date>2026-04-29T13:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: Warehouse security when using Direct Lake models</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Warehouse/Warehouse-security-when-using-Direct-Lake-models/m-p/5160885#M4505</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="1340679" data-lia-user-login="tayloramy" class="lia-mention lia-mention-user"&gt;tayloramy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;That makes sense, it's too late to go back to SQL endpoint now.&lt;BR /&gt;ReadAll seems to be essential to use onelake connection.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 14:10:54 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Warehouse/Warehouse-security-when-using-Direct-Lake-models/m-p/5160885#M4505</guid>
      <dc:creator>wardy912</dc:creator>
      <dc:date>2026-04-29T14:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: Warehouse security when using Direct Lake models</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Warehouse/Warehouse-security-when-using-Direct-Lake-models/m-p/5161086#M4506</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="475583" data-lia-user-login="wardy912" class="lia-mention lia-mention-user"&gt;wardy912&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yeah, security on warehouses leaves something to be desired for sure.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For this reason I tend to use Lakehouses for all my stuff, then you can use OneLake Security and everything is fairly consistent.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 22:22:35 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Warehouse/Warehouse-security-when-using-Direct-Lake-models/m-p/5161086#M4506</guid>
      <dc:creator>tayloramy</dc:creator>
      <dc:date>2026-04-29T22:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: Warehouse security when using Direct Lake models</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Warehouse/Warehouse-security-when-using-Direct-Lake-models/m-p/5177452#M4515</link>
      <description>&lt;P data-start="582" data-end="587"&gt;&lt;FONT&gt;Hi&amp;nbsp;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="475583" data-lia-user-login="wardy912" class="lia-mention lia-mention-user"&gt;wardy912&lt;/a&gt;,&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="589" data-end="718"&gt;&lt;FONT&gt;Thank you for reaching out to the Microsoft Fabric Community Forum, and thanks to the&amp;nbsp;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="1340679" data-lia-user-login="tayloramy" class="lia-mention lia-mention-user"&gt;tayloramy&lt;/a&gt;&amp;nbsp;&amp;nbsp;for sharing helpful insights.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="720" data-end="897"&gt;&lt;FONT&gt;Just checking in, were you able to resolve the issue using any of the suggestions provided? If not, please feel free to share an update, and we'll be happy to assist further.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="899" data-end="974"&gt;Your feedback will also help others facing similar challenges.&lt;BR data-start="961" data-end="964" /&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2026 12:14:13 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Warehouse/Warehouse-security-when-using-Direct-Lake-models/m-p/5177452#M4515</guid>
      <dc:creator>v-shchada-msft</dc:creator>
      <dc:date>2026-05-04T12:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: Warehouse security when using Direct Lake models</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Warehouse/Warehouse-security-when-using-Direct-Lake-models/m-p/5179195#M4522</link>
      <description>&lt;P&gt;I have received information from the OneLake security team stating that they are actively working on a warehouse solution. In the meantime, I'll need to create a separate warehouse for each schema to ensure security.&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2026 09:00:18 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Warehouse/Warehouse-security-when-using-Direct-Lake-models/m-p/5179195#M4522</guid>
      <dc:creator>wardy912</dc:creator>
      <dc:date>2026-05-07T09:00:18Z</dc:date>
    </item>
  </channel>
</rss>

