Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

The Power BI Data Visualization World Championships is back! Get ahead of the game and start preparing now! Learn more

Reply
kchung_msft
Microsoft Employee
Microsoft Employee

Write Access to OneLake folder using RBAC

I'm trying to provide granular permissions for my system-assigned managed identity so that it doesn't have permission to do too many things.

 

At the Lakehouse level, I was able to give it "Read", "ReadAll" permisisons, but there wasn't an option to provide Write.

Within the Lakehouse, using "Manage OneLake Data Access (preview)", I created a role and assigned it to specific folders, but it also only shows Read, ReadAll.

 

How can I get this managed identity to have Write only on a selected set of folders? Workspace contributor seems too broad as it might provide Write to the entire Lakehouse which is undesireable.

2 REPLIES 2
kchung_msft
Microsoft Employee
Microsoft Employee

That looks to be operation-specific but I didn't see anything that suggested it could scope the permission to a subset of resources.
I was using https://learn.microsoft.com/en-us/fabric/onelake/security/get-started-data-access-roles#assign-a-mem... as a reference as it appeared to allow for folder-level scoping of permissions.

Anonymous
Not applicable

Hi @kchung_msft ,

Perhaps you can leverage Azure role-based access control to create custom roles?The following articles may be helpful to you.

Azure custom roles - Azure RBAC | Microsoft Learn

Helpful resources

Announcements
Power BI DataViz World Championships

Power BI Dataviz World Championships

The Power BI Data Visualization World Championships is back! Get ahead of the game and start preparing now!

December 2025 Power BI Update Carousel

Power BI Monthly Update - December 2025

Check out the December 2025 Power BI Holiday Recap!

FabCon Atlanta 2026 carousel

FabCon Atlanta 2026

Join us at FabCon Atlanta, March 16-20, for the ultimate Fabric, Power BI, AI and SQL community-led event. Save $200 with code FABCOMM.