Reitse
1 year agoMost Valuable Professional
Status:
Completed
Fabric SQL Database dynamic data masking doesn't work
I've been doing some testing with Dynamic Data Masking to try and find out if/how it works.
To do that, I'm running a script that works perfectly fine in SQL Server and Azure SQL Server.
But it fails to mask the data in Fabric SQL Database. I got some confirmation yesterday at SQL Konferenz that this really looks like a bug and therefore I'm sharing the full code with you to reproduce and hopefully find a solution.
DROP TABLE IF EXISTS dbo.MaskingTable;
CREATE TABLE dbo.MaskingTable (
ID int IDENTITY(1,1),
FirstName varchar(20) MASKED with (FUNCTION = 'Partial(3,"AbC",1)') NOT NULL,
LastName varchar(30) MASKED with (FUNCTION = 'default()') NOT NULL,
Email varchar(40) MASKED WITH (FUNCTION = 'email()') NOT NULL,
SecretDate datetime MASKED WITH (FUNCTION = 'datetime("Y")')NOT NULL,
TopSecretNumber int MASKED with (FUNCTION = 'RANDOM(1,1000)')
)
INSERT INTO dbo.MaskingTable (FirstName, LastName, Email, SecretDate, TopSecretNumber)
VALUES
SELECT *
FROM dbo.MaskingTable
CREATE USER NoUnMask WITHOUT LOGIN;
GRANT SELECT ON dbo.MaskingTable TO NoUnMask;
EXECUTE AS USER = 'NoUnMask'
SELECT *
FROM dbo.MaskingTable
REVERT;
5 Comments
- sukkaurMicrosoft EmployeeHi Reitse, Just want to let you know that masking works fine. Please try it with an actual user by giving your user connect access to the SQL database artifact in fabric. You are not seeing the result because you using execute as user for this. Thanks Sukhwant
- ReitseMost Valuable ProfessionalHi Sukhwant, So to test this functionality I can't use a method that's been in use for ages? If execute as doesn't work in Fabric SQL (and it does in Azure SQL and SQL Server), it should return an error instead of an unwanted result. I've seen the execute as clause being used in stored procedures as well in the past. If people assume this will work in Fabric SQL too, they might be in for a surprise after migrating. I hope this one can be fixed or that there will be clear documentation on the fact that this doesn't work.
- JakubSzymaszekMicrosoft EmployeeStatus changed:NewtoPlanned
- sukkaurMicrosoft EmployeeStatus changed:PlannedtoCompleted
Recent ideas
Support Fabric SQL Database with workspace-level inbound Private Link
Fabric SQL Database supports tenant-level Private Link but not workspace-level Private Link. Securing a small number of databases therefore requires enabling Private Link across the entire tenant, in...WorkFull221 hour agoAdvocate INew2Views0likes0CommentsImprove Relationship UI Wording to Better Reflect Filter Propagation Direction
The current relationship dialog can be confusing because the UI labels "From" and "To" do not always align with users' linguistic expectations regarding filter propagation. As per document : Relation...v-varunvv2 hours agoMicrosoft EmployeeNew12Views4likes0CommentsDynamic ADLS-Gen2 path input for Spark Jobs Main definition file
I would like the ability to add a dynamic input box on a spark job definition's "Main Definition File" "ADLS-Gen2 path". this would be useful to set base and variable paths across all spark jobs...mfink_db2 hours agoNew MemberNew223Views2likes1CommentTenant and/or App/Workspace Banner messages- alerts
As a tenant admin - would like to publish banner messages or alerts as needed for the organization in the event of a data load failure, or other messaging that needs to be show to the end user on l...sue_yerly2 hours agoNew MemberNew378Views18likes3Comments