Access control for data in OneLake. Lakehouse roles can allow read or read-write access as narrowly as a single folder, schema, table, row or column, and every engine reading the data, from Spark to the SQL analytics endpoint and Direct Lake, applies them.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains OneLake security in context, with comparison tables and the common traps.
Terms in this definition
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
- OneLake
Built on Azure Data Lake Storage Gen2, it is the one logical data lake for an entire Microsoft Fabric tenant, provisioned automatically, and the place where every Fabric workload keeps its data.
- Lakehouse
Fabric storage item in OneLake that holds structured and unstructured content side by side: managed Delta tables go under Tables, other files under Files. Spark is used for processing, and a read-only SQL analytics endpoint allows T-SQL queries.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Schema
The middle part of a Unity Catalog name (
catalog.schema.table), grouping tables, views, volumes, functions and models inside a catalog. A grant on it covers everything in it now and later, and nothing inside can be reached withoutUSE SCHEMA. - Event
Table in Log Analytics where entries from Windows event logs are kept.
- SQL analytics endpoint
Read-only SQL access in Fabric to the data in a lakehouse. Power BI using DirectQuery through it performs more slowly than Direct Lake.
- Direct Lake
Mode for Fabric semantic models that loads Delta or Parquet files from OneLake straight into VertiPaq, giving almost import-level performance without duplicating data.
Related terms
- CLS
Column-level security controls which columns someone may read. Warehouses and SQL analytics endpoints implement it via
GRANT SELECTon named columns, while OneLake security handles it as part of a role defined on a table. - DefaultReader
Every lakehouse gets this OneLake security role, which lets anyone with ReadAll permission read all of its data. If you add stricter roles without editing it or removing people from it, those people still have full access.
- Direct Lake on OneLake
Recommended choice for new Direct Lake models: it pulls Delta tables from one or several Fabric items via OneLake APIs, with OneLake security applied, allows composite models and never switches to DirectQuery.