Home › Glossary › SQL analytics endpoint access mode

SQL analytics endpoint access mode

Chooses how security gets enforced on a lakehouse's SQL endpoint. By default (delegated identity), OneLake is read as whoever owns the item, with only T-SQL permissions, RLS, CLS and DDM applying; user's identity instead forwards each caller to OneLake so its security roles take effect.

Also called user's identity or delegated identity mode.

Read more: Microsoft Learn

In the Ultra Transcenders books

DP-600DP-700

Each book explains SQL analytics endpoint access mode in context, with comparison tables and the common traps.

Terms in this definition

See SQL analytics endpoint access mode in the full glossary