Join us for an expert-led overview of the tools and concepts you'll need to pass exam PL-300. The first session starts on June 11th. See you there!
Get registeredJoin us at FabCon Vienna from September 15-18, 2025, for the ultimate Fabric, Power BI, SQL, and AI community-led learning event. Save €200 with code FABCOMM. Get registered
1. Can an ADF pipeline outside Fabric (a pipeline created in Azure ADF Service) reference OneLake as a linked service?
2. Can an external app use non-AAD authentication, such as Shared Key authorization or SAS, to access OneLake folders using a SDK, such as Python or Ruby on Falls SDK?
3. To my undestanding, OneLake is married to Power BI workspace security. Please confirm that given that Power BI workspace don't support subfolders, more granular folder-based security is not an option? I understand that tools, such as ADF pipeline, can create subfolders, but I don't see how security can be overwritten from the containing workspace.
4. The launch presentation mentions that OneLake can be georgraphically dispersed to comply with international regulations. Please confirm that the only way this to happen would to buy Power BI capacities, assign capacities to data regions, and allocate workspaces accordingly.
Hi @teolachev ,
Hello!!! You have asked very pertinent and detailed questions about integration with OneLake. I have tried to answer each one separately below:
1. OneLake Connection with ADF Pipeline
Currently, Azure Data Factory (ADF) does not directly recognize OneLake as a Linked Service. However, since OneLake is actually an ADLS Gen2 compliant fabric, it can be accessed indirectly through ADLS Gen2 connectivity. In this case, the endpoint and authorization information required for access must be carefully configured.
2. Non-AAD Authentication (Shared Key / SAS / SDK)
OneLake currently only supports Azure Active Directory (AAD) based authentication.
Alternative authentication methods such as Shared Key or SAS Token are not supported.
On the SDK side, the Azure SDK for Python (for example azure-storage-file-datalake) is available. However, these SDKs also rely on AAD authentication.
3. Power BI Workspace Security and Folder Based Authorization
Yes, that's right: OneLake security is integrated with Power BI Workspace security. Because Workspaces do not offer folder-based security, more granular folder-based access control is not available. This is a limitation in terms of flexibility, especially in multi-user environments.
4. Security Settings in Subfolders
You can create subfolders within OneLake, but security settings are inherited from the root directory and overriding them requires manual intervention. No automated or policy-managed folder-based security is currently deployed.
5. Geo-Distribution and Replication
Yes, OneLake can be geographically distributed. However, this cannot be done directly in the OneLake settings. For this you need to purchase
You need to purchase Power BI Premium capacity.
You must position this capacity as a regional tenant and
You should allocate workspaces according to the relevant regions.
This way, data access and replication delays can be optimized.
Please mark this post as solution if it helps you. Appreciate Kudos.
This is your chance to engage directly with the engineering team behind Fabric and Power BI. Share your experiences and shape the future.
User | Count |
---|---|
70 | |
44 | |
14 | |
12 | |
5 |
User | Count |
---|---|
80 | |
77 | |
27 | |
8 | |
7 |