Rights granted on one particular Fabric item, through sharing or the Manage permissions page, that can stand alone or add to whatever workspace role a person holds. Read, ReadData, ReadAll, Write and Reshare are typical examples.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Item permissions in context, with comparison tables and the common traps.
Terms in this definition
- MANAGE
A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of
ALL PRIVILEGES. - AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Architecture Definition Document
A key deliverable bringing together the main architecture artifacts across the four domains for every relevant state: baseline, transition and target. It sets out, in qualitative terms, what the architect intends.
- Workspace
Teams in Power BI and Microsoft Fabric collaborate in this folder-style container, which groups items such as reports, semantic models and lakehouses, controls who can access them and is assigned a capacity.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- ReadData
A Fabric item permission, comparable to db_datareader, that allows T-SQL reads of all tables and views in a warehouse or SQL analytics endpoint. With only Read, a user can connect but not query.
- ReadAll
Grants access to lakehouse or warehouse data through Spark, OneLake APIs and the explorer pane. Querying with T-SQL is a separate permission, ReadData.
Related terms
- Secure embed
Places a report in an internal website or portal without code: File > Embed report > Website or portal produces an iframe or link. Signing in is required, RLS and item permissions still hold, and every viewer needs Pro or PPU unless the content lives on P capacity or F64 and above.