Governed tags drive this kind of Unity Catalog rule: when a table or column has tags that satisfy its WHEN and MATCH COLUMNS conditions, a row filter or column mask UDF is put on it automatically. Policies are written with CREATE POLICY and can sit on a metastore, catalog, schema or table.
Also called attribute-based access control policy.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains ABAC policy in context, with comparison tables and the common traps.
Terms in this definition
- Governed tags
Tags defined at account level and controlled by a tag policy that sets permitted values and who can apply them. Catalogs and schemas pass them down to child objects (columns do not inherit them), and ABAC policies use them as the attributes to match.
- Unity Catalog
Azure Databricks' governance solution covering both data and AI in one place, with centralised permissions, auditing, data discovery and lineage.
- Event
Table in Log Analytics where entries from Windows event logs are kept.
- Image tagging
An Image Analysis feature producing single-word tags, each with a confidence score, for actions, scenery, objects and living things in an image.
- MATCH
Used in WHERE when querying SQL Graph, it describes how to walk from node to node through edge tables, with patterns written like p1-(f1)->p2.
- Row filter
Limits which rows each user sees: a SQL function returning true or false is evaluated per row once bound to the table through
SET ROW FILTERorWITH ROW FILTER. - Column mask
A SQL function registered in Unity Catalog that, each time a query runs, hands back either the genuine value of a column or a disguised one. You attach it to a single column with
SET MASKin anALTER TABLEstatement, or to many tables at once through an ABAC policy. - UDF
Custom logic written in JavaScript and registered with a Cosmos DB container, callable only from queries. Calling one raises the request unit charge.
Related terms
- DENY policy
A Beta ABAC policy type that takes a privilege away rather than granting one; at the moment it can only block
MANAGE ACCESS CONTROL. It applies wherever governed tags match and beats every grant, ownership too, though it never restricts metastore admins. - GRANT policy
An ABAC policy that hands out a Unity Catalog privilege automatically whenever governed tags on an object satisfy its condition. It can only add access, never take away a privilege granted directly.