Implements row-level security for Fabric warehouses or SQL analytics endpoints by attaching an inline table-valued function, acting as filter predicate, onto a table. Excluded rows vanish quietly from reads, updates and deletes.
Also called CREATE SECURITY POLICY.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Security policy in context, with comparison tables and the common traps.
Terms in this definition
- RLS
Row-level security: filtering the data each person can see down to permitted rows. Power BI models apply it through DAX rules on roles, which bind just Viewers and anyone holding Read or Build; Fabric Warehouse instead uses a T-SQL policy that calls a predicate function.
- Serverless
Compute tier for single Azure SQL databases that scales automatically, pauses when idle and charges by the second. It is offered in General Purpose and Hyperscale, not Business Critical, and reserved capacity does not apply.
- Inline table-valued function
A single SELECT statement packaged as a T-SQL function that returns rows. Fabric Warehouse and SQL analytics endpoints use one as the filter predicate when CREATE SECURITY POLICY sets up row-level security on a table.
- Filter predicate
An inline table-valued function used for row-level security; once a security policy binds it to a table, users simply don't see rows they aren't entitled to when they SELECT, UPDATE or DELETE. Block predicates are unsupported in Fabric warehouses, so this is the only type available.
- Event
Table in Log Analytics where entries from Windows event logs are kept.
Related terms
- Account protection
Covers Windows LAPS, local user group membership, Credential Guard and Windows Hello for Business in a single Intune endpoint security policy type for Windows. Since July 2024 it has replaced the Identity protection template.
- LSA
Local Security Authority. Running as LSASS, it verifies sign-ins made locally or over the network and applies local security policy; its stored secrets can be shielded with Credential Guard and LSA protection.
- Microsoft Foundry resource
Azure resource at the top of the Foundry hierarchy (
Microsoft.CognitiveServices/accounts, kindAIServices). It governs model deployments, networking, security, policy and shared connections, while child projects keep teams isolated. - Predicate function
The logic behind row-level security. Written as an inline TVF, it yields a row only when the user should see or change the data; tables are bound to it through a security policy, which applies it either to filter rows out or to block writes.
- Security Admin
Built-in Azure role whose holders manage security policy, alerts and recommendations in Microsoft Defender for Cloud. Role assignment and the creation of general policy definitions fall outside what it allows.
- User rights
Privileges like logging on locally, connecting via Remote Desktop or backing up files, granted to accounts through security policy and distinct from the permissions set on individual objects.