Securing Microsoft Fabric workspaces and items
For this chapter, we will be looking at security in the context of access to data stored in OneLake. There is a broader security story as it relates to Power BI reports, semantic models, SQL row-level security and dynamic data masking, SQL object-level security, and more. Additionally, Fabric’s OneSecurity model is not available at the time of writing and will serve as an extension, not a replacement, to the foundational topics covered in this section.
To begin, let’s look at how different workspace-level permissions affect data access.
Workspace-level permissions
The most common method for granting access to data in Fabric will be through workspace-level permissions. This gives blanket access to the items within the workspace and the data within OneLake that is associated with the items within the workspace.
Four roles can be assigned to a user at the workspace level:
- An Admin can perform all actions...