Join us at FabCon Atlanta from March 16 - 20, 2026, for the ultimate Fabric, Power BI, AI and SQL community-led event. Save $200 with code FABCOMM.
Register now!Get Fabric certified for FREE! Don't miss your chance! Learn more
Good afternoon!
The Workspace-level private links documentation says that it doesn't support Item sharing or OneLake Security (https://learn.microsoft.com/en-us/fabric/security/security-workspace-level-private-links-support). Is there any way to enforce RLS/CLS on access to Lakehouse data in a scenario where workspace-level private links are in use?
Thanks
Kim
Solved! Go to Solution.
Hi @KimMW,
Right now there is no nice way to enforce RLS with private links.
It does appear that the private link will work with the SQL Endpoint:
Supported scenarios for workspace private links - Microsoft Fabric | Microsoft Learn
But that would not work when working in Notebooks or anything that accesses the data through OneLake.
Proud to be a Super User! | |
Hello @KimMW
Yes, however, OneLake Security cannot be applied directly within the Lakehouse when using workspace-level private links.
RLS/CLS enforcement at the Lakehouse storage layer is not possible in this scenario, as OneLake Security is unsupported with workspace-level private links.
Microsoft has highlighted this restriction as you rightly mention:
Consequently, OneLake Security RLS/CLS will not be effective if your configuration relies on private links.
Nonetheless, RLS at the model layer remains fully operational, as:
This aligns with Microsoft’s guidance for implementing RLS in supported Fabric engines, including SQL Analytics Endpoint and semantic models.
Row-level security - Microsoft Fabric | Microsoft Learn
Hope this helps - please appreciate by leaving a Kudos or accepting as a Solution!
Hello @KimMW
Yes, however, OneLake Security cannot be applied directly within the Lakehouse when using workspace-level private links.
RLS/CLS enforcement at the Lakehouse storage layer is not possible in this scenario, as OneLake Security is unsupported with workspace-level private links.
Microsoft has highlighted this restriction as you rightly mention:
Consequently, OneLake Security RLS/CLS will not be effective if your configuration relies on private links.
Nonetheless, RLS at the model layer remains fully operational, as:
This aligns with Microsoft’s guidance for implementing RLS in supported Fabric engines, including SQL Analytics Endpoint and semantic models.
Row-level security - Microsoft Fabric | Microsoft Learn
Hope this helps - please appreciate by leaving a Kudos or accepting as a Solution!
Hi @KimMW,
Right now there is no nice way to enforce RLS with private links.
It does appear that the private link will work with the SQL Endpoint:
Supported scenarios for workspace private links - Microsoft Fabric | Microsoft Learn
But that would not work when working in Notebooks or anything that accesses the data through OneLake.
Proud to be a Super User! | |
Thank you for confirming @tayloramy
Given that item sharing isn't supported with Workspace Private Link, how can one use the SQL Endpoint in these scenarios to give access in this way? Does the user have to have been granted access directly to the workspace the lakehouse is in?
Hi @KimMW,
Yes, I do believe that workspace access needs to be granted.
Proud to be a Super User! | |
If you love stickers, then you will definitely want to check out our Community Sticker Challenge!
Check out the January 2026 Fabric update to learn about new features.
| User | Count |
|---|---|
| 24 | |
| 4 | |
| 3 | |
| 3 | |
| 2 |
| User | Count |
|---|---|
| 59 | |
| 13 | |
| 10 | |
| 7 | |
| 7 |