Don't miss your chance to take exam DP-600 or DP-700 on us!
Request nowFabric Data Days Monthly is back. Join us on March 26th for two expert-led sessions on 1) Getting Started with Fabric IQ and 2) Mapping & Spacial Analytics in Fabric. Register now
Good afternoon!
The Workspace-level private links documentation says that it doesn't support Item sharing or OneLake Security (https://learn.microsoft.com/en-us/fabric/security/security-workspace-level-private-links-support). Is there any way to enforce RLS/CLS on access to Lakehouse data in a scenario where workspace-level private links are in use?
Thanks
Kim
Solved! Go to Solution.
Hi @KimMW,
Right now there is no nice way to enforce RLS with private links.
It does appear that the private link will work with the SQL Endpoint:
Supported scenarios for workspace private links - Microsoft Fabric | Microsoft Learn
But that would not work when working in Notebooks or anything that accesses the data through OneLake.
Proud to be a Super User! | |
Hello @KimMW
Yes, however, OneLake Security cannot be applied directly within the Lakehouse when using workspace-level private links.
RLS/CLS enforcement at the Lakehouse storage layer is not possible in this scenario, as OneLake Security is unsupported with workspace-level private links.
Microsoft has highlighted this restriction as you rightly mention:
Consequently, OneLake Security RLS/CLS will not be effective if your configuration relies on private links.
Nonetheless, RLS at the model layer remains fully operational, as:
This aligns with Microsoft’s guidance for implementing RLS in supported Fabric engines, including SQL Analytics Endpoint and semantic models.
Row-level security - Microsoft Fabric | Microsoft Learn
Hope this helps - please appreciate by leaving a Kudos or accepting as a Solution!
Hello @KimMW
Yes, however, OneLake Security cannot be applied directly within the Lakehouse when using workspace-level private links.
RLS/CLS enforcement at the Lakehouse storage layer is not possible in this scenario, as OneLake Security is unsupported with workspace-level private links.
Microsoft has highlighted this restriction as you rightly mention:
Consequently, OneLake Security RLS/CLS will not be effective if your configuration relies on private links.
Nonetheless, RLS at the model layer remains fully operational, as:
This aligns with Microsoft’s guidance for implementing RLS in supported Fabric engines, including SQL Analytics Endpoint and semantic models.
Row-level security - Microsoft Fabric | Microsoft Learn
Hope this helps - please appreciate by leaving a Kudos or accepting as a Solution!
Hi @KimMW,
Right now there is no nice way to enforce RLS with private links.
It does appear that the private link will work with the SQL Endpoint:
Supported scenarios for workspace private links - Microsoft Fabric | Microsoft Learn
But that would not work when working in Notebooks or anything that accesses the data through OneLake.
Proud to be a Super User! | |
Thank you for confirming @tayloramy
Given that item sharing isn't supported with Workspace Private Link, how can one use the SQL Endpoint in these scenarios to give access in this way? Does the user have to have been granted access directly to the workspace the lakehouse is in?
Hi @KimMW,
Yes, I do believe that workspace access needs to be granted.
Proud to be a Super User! | |
Share feedback directly with Fabric product managers, participate in targeted research studies and influence the Fabric roadmap.
Check out the February 2026 Fabric update to learn about new features.
| User | Count |
|---|---|
| 17 | |
| 5 | |
| 4 | |
| 3 | |
| 3 |