This time we’re going bigger than ever. Fabric, Power BI, SQL, AI and more. We're covering it all. You won't want to miss it.
Learn moreGet Fabric Certified for FREE during AI Skills Fest. This week only. Secure your voucher now.
In OneLake security, when a user is a member of multiple security groups or roles that apply different access rules to the same object, table, column, or row, conflicting permissions can result in overly restrictive behavior—often blocking access entirely.
This is challenging in enterprise environments where users frequently belong to multiple roles across domains, projects, or departments. Instead of enabling fine-grained access, the current behavior can unintentionally deny access completely, even when there is a valid overlap in permissions.
When multiple roles apply to the same object:
Instead of blocking access completely, the system should enforce the most restrictive valid access.
Introduce a configurable feature (toggle or policy setting) for handling role conflicts:
Allow administrators to choose between:
Strict Mode (current behavior)
Intersection Mode (new option)
The setting could be applied at different levels:
Provide tooling to:
This is especially valuable in organizations where:
A configurable model ensures Fabric can support both:
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.