Forum Discussion
Roadmap for Workspace Identity Support with OneLake Shortcuts Using Delegated Identity
We are evaluating the OneLake Shortcut Delegated Identity (Preview) capability and would like to understand the roadmap for supporting Workspace Identity as an authentication option when creating shortcuts.
Currently, the available authentication choices appear to be Organization Account and Service Principal. In large enterprises with many Fabric workspaces, managing and approving a dedicated Service Principal for each workspace can be operationally challenging and introduces additional governance overhead.
Is there a roadmap or planned enhancement that would allow Workspace Identity to be used with OneLake Shortcut Delegated Identity, similar to how Workspace Identity is supported in other Fabric scenarios?
Specifically:
1.Is Workspace Identity support for OneLake Shortcut Delegated Identity under consideration or currently on the product roadmap?
2.Are there any upcoming preview or GA features that will enable Workspace Identity authentication during shortcut creation?
3.If Workspace Identity support is not planned, what is the recommended enterprise-scale pattern for managing shortcuts across hundreds of workspaces without requiring large numbers of Service Principals?
Any guidance on future direction or recommended architectural patterns would be greatly appreciated
Hi,
At the moment, Workspace Identity is not listed as a supported authentication option for OneLake Shortcuts using Delegated Identity. The currently supported options are Organization Account and Service Principal, and Microsoft has not publicly announced a roadmap, preview, or GA timeline for Workspace Identity support in this specific scenario.
For enterprise-scale implementations, the most common pattern today is to standardize on Service Principals rather than creating one per workspace. Many organizations use a smaller set of centrally managed Service Principals that are governed through security groups, least-privilege access, and automated provisioning processes. This helps reduce administrative overhead while maintaining a scalable and auditable security model.
If Workspace Identity support is important for your architecture, I would recommend submitting or upvoting the request through Microsoft’s Fabric feedback channels and monitoring the Fabric roadmap for future announcements. Product teams often prioritize features based on customer demand and enterprise adoption scenarios.
For now, a centralized Service Principal strategy combined with strong governance, automation, and role-based access controls is generally the recommended approach when managing shortcuts across a large number of workspaces.
Thanks,
Manoj Annavajjala
6 Replies
- GilbertQSuper User
My understanding is that a workspace identity is actually a service principle, the only difference being that they manage the workspace identity kind secret in the fabric service. So the workspace identity is actually still available in Azure, so I don't see why this cannot be used with a OneLake shortcut.
- satishchandranAdvocate I
Thanks for responding GilbertQ . Yes I expected the same. But currently there is no option to use Workspace Identity as delegated identity either through UI or through Fabric API as connection id. For example tried creating cloud connection to OneLake files, but the Authentication Method does not list Workspace Identity (only OAuth and Service Principal are listed), similar to Notebook connection. Not sure if this is the appropriate connection type. Appreciate your help.
- sannavajjalaResolver II
Hi,
At the moment, Workspace Identity is not listed as a supported authentication option for OneLake Shortcuts using Delegated Identity. The currently supported options are Organization Account and Service Principal, and Microsoft has not publicly announced a roadmap, preview, or GA timeline for Workspace Identity support in this specific scenario.
For enterprise-scale implementations, the most common pattern today is to standardize on Service Principals rather than creating one per workspace. Many organizations use a smaller set of centrally managed Service Principals that are governed through security groups, least-privilege access, and automated provisioning processes. This helps reduce administrative overhead while maintaining a scalable and auditable security model.
If Workspace Identity support is important for your architecture, I would recommend submitting or upvoting the request through Microsoft’s Fabric feedback channels and monitoring the Fabric roadmap for future announcements. Product teams often prioritize features based on customer demand and enterprise adoption scenarios.
For now, a centralized Service Principal strategy combined with strong governance, automation, and role-based access controls is generally the recommended approach when managing shortcuts across a large number of workspaces.
Thanks,
Manoj Annavajjala
- satishchandranAdvocate I
Thank you very much for your response and clarifying my question. I hope Workspace Identity finds a place in the future roadmap. As it has a potential to enable workspace scope access to all users using in the workspace similar to service principal, discounting overhead of provisioning of service principal and maintaining it. Also since onelake security allows managing access and sql endpoint also supports delegated access using workspace identity, only one lake shortcuts misses this feature. I assume we can use pipelines to run notebooks using workspace identity but that would be workaround for us and confuses users and creates more overhead for us to train users, why fabric partially supports one feature but not others. It would indeed be a wonderful tool for enterprise orgs maintaining multipe data products and marts to scope access using workspaces and workspace identity. Thanks for suggestion to raise this as a feedback.
- v-csrikanthCommunity Support
Hi satishchandran
We would like to inquire whether have you got the chance to check the solutions provided by sannavajjala GilbertQ in commiunity to resolve the issue. We hope the information provided helps to clear the query. Should you have any further queries, kindly feel free to contact the Microsoft Fabric community.
Thank you.- satishchandranAdvocate I
Thanks v-csrikanth. Like suggested i have added to feedback on ideas. Since Workspace Identity is simlar to Service Principal it will be valuable to have this added as it does not have the overhead of managing Service Principal and also since onelake security already enable usage of Workspace identity.
Enable Workspace Identity for Onelake shortcuts wi... - Microsoft Fabric Community