onelake catalog
6 TopicsSimplifying secure data access with Delegated OneLake Shortcuts (Preview)
Introduction Data rarely stays in one place. As organizations standardize Microsoft Fabric and OneLake, the same datasets need to be reused across teams, domains, workspaces, and increasingly across tenant boundaries. The challenge is no longer moving data; it is sharing it securely, consistently, and at scale without creating copies, breaking governance, or forcing every consumer to be individually provisioned at the source. OneLake Shortcuts already solve a large part of this problem. A shortcut presents data where people need it while the data stays in its original location, enabling a true zero-copy approach to distribution. By default, OneLake Shortcuts use pass-through authentication: when a user reads a shortcut, Fabric accesses the target data using that signed-in user’s identity, and the data owner controls access directly on the target. Pass-through is the right model for many collaborative scenarios, but customers have consistently told us it does not fit every access pattern. Two points came up frequently: Access management does not scale. When a curated dataset must be served to thousands of downstream users across multiple teams, the data owner becomes responsible for granting and maintaining every individual user’s permission on the source, an operational bottleneck that grows with every new consumer. Cross-tenant sharing is harder than it should be. Multi-tenant organizations told us that they need to access data residing in OneLake across their own tenant. These are not edge cases. They are everyday realities for enterprises building governed, reusable data products on Fabric. The preview of Delegated OneLake Shortcuts — including delegated sharing both within a tenant and across tenants — gives data owners a simpler, governed way to distribute data without compromising on security. Introducing delegated OneLake Shortcuts Delegated OneLake Shortcuts add a second authentication option to the existing shortcut experience you already know. Instead of accessing the target data as each signed-in user, a delegated shortcut accesses the target through a configured connection identity. That identity can be an organizational account, a service principal. This identity is attached to the shortcut, so all access to the shortcut reaches the target as the delegated identity. Delegated authentication is entirely optional and complements the default experience. If a user does not choose delegated authentication when creating a shortcut, the shortcut continues to use pass-through authentication exactly as before. The default flow is unchanged; delegation is simply there when you need it. How it works A delegated shortcut behaves like other external shortcuts in Fabric. When you create one, you sp, and that connection is used to browse and read the target data. This brings a familiar, governed connection model to OneLake-to-OneLake sharing. Identity delegation - Downstream users access the data through the delegated identity rather than their own, so the data owner no longer must provision each individual consumer on the source item. Secure access enforcement with OneLake security - OneLake security roles can be configured on both the data producer and data consumer delegated Shortcuts. At the time of this writing, table level security and column-level security are supported for delegated shortcuts, on both the target (where you are creating the shortcut) and the shortcut source (where data resides). Delegated permissions management - A shortcut can delegate as a fixed identity that represents a business unit. The central data owner controls what that identity can see, while the business unit manages OneLake security for its own end users, all while still honoring the controls applied to the delegated identity. Cross-tenant sharing Delegated shortcuts also work across Microsoft Fabric tenants. A cross-tenant delegated shortcut lets you create a OneLake shortcut to data that lives in another organization’s Fabric tenant. You provide a connection path to the external OneLake data and authenticate with an identity from that tenant; downstream users then access the external data through the configured delegated identity, without each user needing individual cross-tenant permissions. This makes delegated shortcuts a natural fit for multi-tenant enterprises, for example, sharing curated data between an organization’s test and production tenants, or between a parent company and a subsidiary using the same zero-copy, intersection-based security model that applies within a tenant. Difference between External Data Sharing and delegated Shortcuts Microsoft Fabric has External Data Sharing, a feature that enables Fabric users to share data from their tenant with users in another Fabric tenant. External data sharing can be used when the consumer has no identity in the producer's tenant, such as sharing across organizational boundaries with an outside partner or customer. This is ideal when you must share with partners or when ISVs must share data with their customers and don’t want to have the consumer identity in their tenant. Cross-tenant delegated shortcuts are used when the data consumer has an identity, such as an organizational account or service principal, in the producer’s tenant. For example, an organization can share data between its own test and production tenants, with access flowing through the configured delegated identity. Use cases Delegated OneLake Shortcuts are designed for the moments when the default pass-through behavior does not match the access pattern you want for a data product. Common scenarios include: Departmental data sharing at scale - Represent each department with a delegated identity, scope what that identity can see, and let department owners manage access for their own users instead of routing every request through the central data owner. Cross-tenant and subsidiary sharing - Share curated data between tenants — such as test-to-production or parent-to-subsidiary — with no data copies and the same delegated security model. Getting started Open the target Fabric item, such as a Lakehouse, and select Get data > New table shortcut. In New shortcut, select Microsoft OneLake, then choose the source you want to shortcut to. For cross-tenant data, select Enter connection details and provide the external OneLake path. For Connection method, select Delegated identity, then Connect. Choose an existing connection or create a new one by providing the OneLake path, a recognizable connection name, and an authentication kind (organizational account or service principal). Sign in to complete authentication. Browse the source, select the folders or tables to include, then review and create the shortcut. To switch an existing shortcut between pass-through and delegated authentication, delete and recreate it with the desired method. For detailed steps, refer to the OneLake Shortcuts documentation. Conclusion and next steps OneLake shortcuts are a foundational building block for zero-copy data distribution across Microsoft Fabric. Delegated OneLake Shortcuts extend that foundation to the scenarios enterprises care about most: serving curated data to large audiences, delegating access management to the teams closest to the users, and sharing securely across tenant boundaries. Together, pass-through and delegated shortcuts let organizations choose the right balance of control, scale, and simplicity for each data product. Pass-through keeps source-managed authorization per person for collaborative engineering. Delegated mode turns a shortcut into part of a governed publishing architecture: central teams retain ownership of the source, consuming teams avoid copying data, and downstream audiences access a managed experience rather than raw-path access — without ever giving up the governance benefits of unifying data in OneLake. Share your feedback, use cases, and questions in the Microsoft Fabric Community. Your input directly shapes the roadmap.4.3KViews4likes4CommentsFabric data agents in Microsoft Foundry: Easier to connect, easier to trust
Last year, we announced the integration between Fabric data agent and Microsoft Foundry. The idea was simple: build a data agent in Fabric on top of your data in Fabric OneLake, then bring that agent into Foundry so your Foundry agents can answer questions grounded in your enterprise data. That foundation helped teams connect their data to AI agents, and your feedback highlighted two areas where we could make the experience better: simplifying how to connect a Foundry agent to Fabric data agents and improving visibility into how they operate once deployed. Today, we’re introducing a set of enhancements that make Fabric data agents easier to discover, integrate, and monitor in production. This update helps organizations build AI agents that can access trusted business data with greater confidence and transparency. Bringing Fabric data agents into Foundry through Model Context Protocol Fabric data agents now integrate with Foundry through Model Concept Protocol (MCP), an emerging industry standard for agent-to-tool communication. This means your Fabric data agents appear as tools that Foundry agents can invoke when they need access to enterpise data that lives in Fabric OneLake. When your Foundry agent decides it needs data, it calls the Fabric data agent the same way it would call any other tool. MCP provides a standard way to connect Fabric data agents and Foundry agents, making the integration easier to extend over time without requiring changes to how you configure it. Importantly, this means organizations can combine the strengths of both platforms: Fabric provides trusted, governed business context, while Foundry provides the platform for building and orchestrating agents. Together, they enable developers to create AI experiences grounded in enterprise data. Discover and add agents from the OneLake Catalog One of the most common pieces of feedback we received was that connecting a Fabric data agent required too much manual work. Previously, builders needed to locate workspace IDs and artifact IDs before they could connect a data agent to their Foundry agent. If you had more than one agent, or you were not the person who built it, tracking down those IDs was cumbersome. The following figures display the previous experience of selecting the Fabric Data Agent tool and filling in the IDs manually. Figure: The old experience: selecting the Fabric Data Agent tool. Figure: The old experience: entering the workspace ID and artifact ID manually. Now, data agents can be discovered directly through the OneLake Catalog experience. You simply add the Fabric IQ (OneLake Catalog) tool, filter for data agents, and pick the ones you want. The following figures display the new experience. Figure: The new experience: adding the Fabric data agent via the Fabric IQ (OneLake Catalog) tool. Figure: The new experience: browsing data agents in the OneLake Catalog and adding them. No more searching for IDs. You see the agents by name, along with their location and sensitivity, and you add them with a click. If you have permission to use an agent, it’s right there in the list. Connect multiple data agents to a single Foundry agent Business questions rarely live within a single domain. The previous integration allowed only one Fabric data agent per Foundry agent. The limitation often forced builders to choose which data source to prioritize. Now, you can connect multiple Fabric data agents to a single Foundry agent, allowing the agent to draw from specialized sources of business knowledge. For example, a Foundry agent can simultaneously leverage a sales analytics agent, a supply chain agent, and a customer support agent, selecting the most relevant source based on the user’s question. Tracing and logs through Foundry Observability Adding a data agent is one thing. Understanding what it does once it is running is another, and that is where the second part of this update comes in. When you add a Fabric data agent to your Foundry agent, you can now view logs and traces through Foundry Observability. This provides insight into how requests move through the agent workflow, including which tools were invoked, how long individual steps took, and what results were returned. Figure: Foundry agent trace with the Fabric data agent's tool calls, input, and output. Observability is important because agents operate as chains of decisions rather than single transactions. When an answer appears incorrect or a workflow becomes slow, builders need visibility into the entire execution path, not just the final output. Traces show you the path a request took and where time was spent, while logs provide detailed records of what occurred during execution. As organizations move agents from experimentation to production, this level of visibility becomes critical. Teams need reliable ways to troubleshoot issues, understand agent behavior, and maintain confidence in the systems they deploy. Foundry Observability helps makes that possible. Figure: Span metadata for a single tool call: timing, status, and data source. Where we’re headed Our goal is simple: help organizations build AI agents they can confidently run in production. That means making enterprise knowledge easier to discover, simplifying how agents connect to trusted business data, and providing the observability needed to understand and troubleshoot agent behavior at scale. With MCP-based integration, OneLake Catalog discovery, support for multiple data agents, and deeper observability, we’re continuing to enhance Fabric and Foundry as a unified foundation for enterprise AI. This update is rolling out to all regions over the coming days. To learn more about connecting Fabric data agents with Microsoft Foundry, explore the Observability for Fabric data agents in Microsoft Foundry documentation.2.2KViews1like0CommentsWhat’s new for Dataverse Fabric Link: More control, stronger security, and fresher data
Every organization runs operational data: customer interactions, sales activity, service cases, finance records, inventory movements, approvals, and custom business processes. Much of that data lives in Microsoft Dataverse, the data platform behind Power Platform and many Dynamics 365 applications. Dataverse Fabric Link connects a Dataverse environment to Microsoft Fabric by creating an analytics-ready representation of selected tables in OneLake. Dataverse shortcuts make that data available across Fabric experiences without requiring customers to build and maintain custom ETL pipelines. Based on customer feedback, recent updates focus on giving administrators more control over linked data, improving authentication options, reducing data latency between Dataverse and Fabric, and making the experience easier to manage. What’s improved Choose only the tables you need What changed: Admins can now manage which Dataverse and finance and operations app tables are linked to Fabric. Instead of bringing every table into the Fabric workspace, teams can add or remove tables based on the analytics scenario they are building. Customer benefit: This gives administrators more control over cost, workspace complexity, and downstream data model design. Only selected tables consume storage for the Fabric link, and removing a table stops synchronization and removes the shortcut without deleting the source table in Dataverse. How to get started: In Power Apps, open Azure Synapse Link, select the Link to Fabric profile, and use Manage tables to add or remove tables. During new Link to Fabric setup, use the Select Entities step to choose the tables you want to sync. Review downstream reports, semantic models, and pipelines after changing table selection. For more information, refer to the Link to Fabric documentation. Use Workspace Identity and Service Principals for production deployments What changed: Dataverse Fabric Link now supports Workspace Identity and Service Principal authentication in addition to organizational account credentials. Workspace Identity uses a managed identity associated with a Fabric workspace, while Service Principal supports customer-managed application identities. Customer benefit: These options reduce dependency on individual user credentials and make Dataverse-to-Fabric integrations easier to operate in production. They help avoid failures when employees change roles, passwords expire, or interactive credentials are no longer appropriate for automated analytics workloads. How to get started: For new links, choose Workspace Identity or Service Principal during the Link to Fabric wizard connection setup. For existing connections, create or identify the workspace identity or service principal, add it as an application user in Dataverse with the required role, then update the Dataverse connection in Fabric under Settings > Manage connections and gateways. Get fresher data with low-latency sync What changed: Previously, syncing data could take up to two hours. With low-latency sync, times are reduced to under 15 minutes for most observed cases, enabling near real-time reporting and analytics. This helps organizations use more current operational data for reporting, monitoring, and decision-making. Customer benefit: Fabric users get fresher Dataverse data, faster initial sync, faster incremental updates, and better throughput for large finance and operations app workloads. This reduces the gap between an operational transaction in Dataverse or Dynamics 365 and its availability in Fabric reports, lakehouses, and AI workloads. How to get started: Low-latency sync is now enabled in selected regions. For more details on getting started and regions where low-latency sync is enabled, refer to Announcing Low-latency sync for Dataverse to Fabric (Generally Available). What this means for Fabric users For Fabric users, these improvements make Dataverse data feel more like a first-class analytics source. You can bring operational data into OneLake with less custom integration work, manage table scope with more precision, rely on stronger authentication options, and reduce the delay between business activity and analytical insight. Most importantly, these changes help customers move from isolated operational reporting to unified business analytics. Dataverse data can be combined with data from Warehouses, Lakehouses, SharePoint, OneLake shortcuts, and other enterprise sources in Fabric, enabling richer reporting and more intelligent applications. Next Steps If you already use Dataverse Fabric Link: Review your current profile and decide whether you should refine table selection. Move to Workspace Identity or Service Principal authentication. Enable low-latency sync when it becomes available in your region. If you are new to integration, start with a focused scenario and choose the tables, workspace, and authentication model that best match that workload. To learn more, refer to the documentation Link to Fabric Create a Dataverse shortcut Dataverse overview2.1KViews0likes0CommentsSharePoint and OneDrive Shortcuts in OneLake (Generally Available)
For most enterprises, the largest and fastest-growing repository of business-critical information is SharePoint and OneDrive. Contracts, financial models, project plans, meeting notes, presentations, and compliance documentation accumulate across every team and department, rich with context that rarely makes it into an analytics workflow. This content has traditionally been invisible to data platforms. Bringing it into a data lake meant building pipelines, scheduling exports, managing duplicates, and reconciling governance across two separate systems. The result: valuable knowledge stayed locked in productivity tools while analytics teams worked with an incomplete picture. Now, SharePoint and OneDrive Shortcuts in Microsoft Fabric OneLake is now generally available. With this capability, organizations can now surface this data directly inside OneLake, without requiring traditional data movement pipelines in many common scenarios. Files stay exactly where they are in SharePoint or OneDrive, and Fabric workloads see them as a native part of the data lake. This is more than a connectivity feature. It is the bridge between the world where work happens and the world where data is analyzed. Sales forecasts stored in Excel can be joined with CRM transactions. Legal documents can be indexed and grounded in AI agents. Financial trackers can feed Power BI reports the moment they are updated. This helps reduce the boundary between collaboration content and enterprise analytics workflows. Customer Use Cases Organizations across industries are already finding practical, high-value ways to connect their Microsoft 365 content with Fabric analytics and AI. Below are example scenarios that illustrate potential use cases. Data Lake Unification Without Migration Many organizations maintain structured data in their Lakehouse alongside a parallel, untouched archive of unstructured content in SharePoint. Shortcuts eliminate the need to choose between the two. Data engineering teams can now create a unified view across both sources inside OneLake, enabling joins, aggregations, and AI workflows that span the full breadth of enterprise knowledge, without moving a single file. Combine SharePoint-hosted reference tables with Lakehouse transactional data in a single Spark notebook. Surface operational documents alongside structured metrics in a single Power BI semantic model. Avoid costly migration projects by referencing content in place and retiring redundant sync processes. Self-Service Analytics on Shared Documents Finance, HR, and operations teams frequently maintain planning workbooks, trackers, and reports in OneDrive and SharePoint. These files are updated regularly by business users who have no need or desire to interact with a data platform directly. Shortcuts let analysts consume this content without asking anyone to change how they work. Finance teams can surface quarterly budget workbooks directly in Power BI without any export step. HR can connect headcount trackers and org charts to workforce analytics dashboards. Operations teams can make procurement logs and vendor documents queryable alongside ERP data. Microsoft Fabric and Foundry: AI at Enterprise Scale For organizations building production-grade AI solutions on Azure, the combination of Fabric OneLake and Microsoft Foundry creates a powerful foundation. Shortcuts ensure that the rich, unstructured knowledge stored in SharePoint and OneDrive is available as a live, governed data source for Foundry-based agents and copilots. Connect SharePoint document libraries to Foundry knowledge stores without a separate ingestion pipeline. Keep AI knowledge grounding current automatically as SharePoint content is updated by business teams. Apply Fabric data transformations to prepare document content for structured AI consumption at scale. Features Supported in General Availability The following capabilities are generally available and supported for production use as of this release: Core Shortcut Capabilities Create shortcuts from any Fabric Lakehouse directly to OneDrive folders or SharePoint document libraries. Access files in place, without requiring explicit data duplication in many scenarios. Files remain governed by their existing SharePoint and OneDrive permissions. Live synchronization ensures that as content is added or updated in SharePoint or OneDrive, Fabric workloads see the latest version automatically. Shortcut Transformations Beyond simple file access, OneLake shortcuts include an optional transformation step that converts supported file types directly into Delta tables. This can reduce or eliminate the need for a separate ETL pipeline in supported scenarios, making document-resident data queryable by analytics engines. Supported file formats for transformation at GA: CSV, Parquet, and JSON. Transformed tables are kept in sync as new files arrive in the connected SharePoint or OneDrive folder. Transformed output integrates natively with Fabric warehouses, notebooks, and Power BI, enabling immediate analytics without additional data engineering. This capability fundamentally changes how customers are working with file-based data. A SharePoint folder containing hundreds of CSV exports from a business application can be transformed into a queryable Delta table in minutes, with minimal pipeline code required in most scenarios. General Availability Improvements In addition to the core shortcut capability, this GA release introduces two significant platform-level improvements that make shortcuts enterprise-ready for automation, scale, and cross-organizational scenarios. Service Principal and Workspace Identity Authentication OneDrive and SharePoint Shortcuts now support Service Principal (SPN) and Workspace Identity (WI) authentication, in addition to organizational account sign-in. This is a critical capability for production deployments. Reduces dependency on individual user credentials, preventing pipeline failures when team members change roles or leave the organization. Authentication is managed through Microsoft Entra ID, enabling consistent security governance and audit trails. SPN and WI authentication support higher API limits, directly reducing throttling in high-throughput scenarios. Cross-tenant access: service principals can be configured to access SharePoint and OneDrive content across organizational boundaries, enabling configurable partner and subsidiary data sharing scenarios, subject to tenant policies and security configurations. Metadata Caching and Performance OneLake now caches SharePoint metadata internally, reducing the frequency and impact of calls to the SharePoint API during query execution. This improvement can deliver the following benefits: Reduced throttling under high query volumes, particularly in multi-user or scheduled workload scenarios. Improved query performance for workloads that enumerate or filter large SharePoint folder structures. These improvements make shortcuts viable for production-grade pipelines and scheduled refresh scenarios that would previously have encountered reliability issues at scale. How to Get Started Creating a SharePoint or OneDrive shortcut in Fabric takes less than five minutes. The following steps apply to any Fabric workspace with at least one Lakehouse: Open a Lakehouse in your Fabric workspace. In the Explorer pane, right-click any folder and select New shortcut. In the New Shortcut dialog, select OneDrive or SharePoint tile from the list of external sources. Choose your authentication method: Organizational account for interactive scenarios, or Workspace Identity / Service Principal for automated and production workflows. Provide the SharePoint site URL and select or create a connection. If you don’t have root level access and prefer to provide the path directly, change the view to Path View by navigating to the top right corner. Browse to the folder or library you want to connect. Select one or more target locations and select Next. On the Transform page, choose whether to apply a transformation to convert supported file types (CSV, Parquet, JSON) into Delta tables. Select Skip if you only need file access. Select Create to finalize. Your shortcuts will appear immediately in the Lakehouse Explorer. From there, you can reference them in Spark notebooks, build Power BI reports directly on the data, run SQL queries through the Lakehouse SQL endpoint, or include them in Fabric pipelines and AI workflows. Learn more by exploring Create a OneDrive or SharePoint shortcut (Microsoft Learn documentation). We are excited to see what you build SharePoint and OneDrive Shortcuts in OneLake represent a step toward a world where every document in your organization is an active participant in your data and AI strategy. As the boundary between productivity and analytics continues to dissolve, Fabric is designed to be the platform that connects them. Share your feedback, use cases, and questions in the Microsoft Fabric Community forums. Your input directly shapes the roadmap.4.2KViews1like2CommentsCross-workspace role management in the OneLake catalog (Preview)
We’re introducing cross-workspace role assignment in the Secure tab of the OneLake catalog. This new capability builds on the Secure tab’s unified view of workspace roles and OneLake security roles, making it easier for security administrators and data owners to manage access consistently across large Fabric estates. Instead of updating role memberships one workspace at a time, you can now assign people and groups to workspace roles across multiple workspaces in one streamlined workflow. What’s new Assign members to compatible OneLake security roles across multiple workspaces from a single experience in the Secure tab. Edit and remove role memberships across multiple workspaces without navigating to each workspace individually. How it works From the Secure tab in the OneLake catalog, admins can filter to the workspaces they manage and select workspace roles across those workspaces for bulk membership updates. This makes it easier to onboard new teams, align access for existing groups, and keep security policy implementation consistent as projects expand. Because the workflow is centralized in the catalog, teams can move from discovery to governance to access management without losing context. le workspaces in the OneLake catalog This capability is especially valuable for quarterly access reviews, environment rollouts, and standardized data product deployments. By managing role membership centrally, organizations can more easily enforce least-privilege access patterns, reduce configuration drift, and respond faster when access needs change. Get started Open the OneLake catalog in Microsoft Fabric and switch to the Secure tab to try cross-workspace role assignment. If you’re already using the Secure tab to view users, inspect security roles, and manage row-level or column-level protections, this enhancement extends that same centralized experience to broader access administration across workspaces. We’re excited to see how teams use it to simplify governance and secure their data estate at scale. Learn more about the OneLake catalog or the secure tab.2.7KViews4likes1Comment