Column-level security controls which columns someone may read. Warehouses and SQL analytics endpoints implement it via GRANT SELECT on named columns, while OneLake security handles it as part of a role defined on a table.
Also called column-level security.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains CLS in context, with comparison tables and the common traps.
Terms in this definition
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Serverless
Compute tier for single Azure SQL databases that scales automatically, pauses when idle and charges by the second. It is offered in General Purpose and Hyperscale, not Business Critical, and reserved capacity does not apply.
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
- SELECT
A DML command in SQL used to retrieve rows from one table or several.
- OneLake security
Access control for data in OneLake. Lakehouse roles can allow read or read-write access as narrowly as a single folder, schema, table, row or column, and every engine reading the data, from Spark to the SQL analytics endpoint and Direct Lake, applies them.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Event
Table in Log Analytics where entries from Windows event logs are kept.
Related terms
- Fixed identity
With single sign-on off, a Direct Lake model can be bound to one explicit cloud credential, such as a workspace identity or service principal. Permissions, RLS and CLS are then evaluated for that credential, not per viewer, so readers need no rights on the underlying item.
- SQL analytics endpoint access mode
Chooses how security gets enforced on a lakehouse's SQL endpoint. By default (delegated identity), OneLake is read as whoever owns the item, with only T-SQL permissions, RLS, CLS and DDM applying; user's identity instead forwards each caller to OneLake so its security roles take effect.