An inline table-valued function used for row-level security; once a security policy binds it to a table, users simply don't see rows they aren't entitled to when they SELECT, UPDATE or DELETE. Block predicates are unsupported in Fabric warehouses, so this is the only type available.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Filter predicate in context, with comparison tables and the common traps.
Terms in this definition
- Inline table-valued function
A single SELECT statement packaged as a T-SQL function that returns rows. Fabric Warehouse and SQL analytics endpoints use one as the filter predicate when CREATE SECURITY POLICY sets up row-level security on a table.
- RLS
Row-level security: filtering the data each person can see down to permitted rows. Power BI models apply it through DAX rules on roles, which bind just Viewers and anyone holding Read or Build; Fabric Warehouse instead uses a T-SQL policy that calls a predicate function.
- Security policy
Implements row-level security for Fabric warehouses or SQL analytics endpoints by attaching an inline table-valued function, acting as filter predicate, onto a table. Excluded rows vanish quietly from reads, updates and deletes.
- Event
Table in Log Analytics where entries from Windows event logs are kept.
- SELECT
A DML command in SQL used to retrieve rows from one table or several.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.