Chooses how security gets enforced on a lakehouse's SQL endpoint. By default (delegated identity), OneLake is read as whoever owns the item, with only T-SQL permissions, RLS, CLS and DDM applying; user's identity instead forwards each caller to OneLake so its security roles take effect.
Also called user's identity or delegated identity mode.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains SQL analytics endpoint access mode in context, with comparison tables and the common traps.
Terms in this definition
- Lakehouse
Fabric storage item in OneLake that holds structured and unstructured content side by side: managed Delta tables go under Tables, other files under Files. Spark is used for processing, and a read-only SQL analytics endpoint allows T-SQL queries.
- SQL warehouse
Compute dedicated to running SQL queries, dashboards and BI tools, available as serverless, pro or classic. Serverless is the recommended type where offered, and every type runs Photon by default.
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
- OneLake
Built on Azure Data Lake Storage Gen2, it is the one logical data lake for an entire Microsoft Fabric tenant, provisioned automatically, and the place where every Fabric workload keeps its data.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- T-SQL
The dialect of SQL that Microsoft uses for Azure SQL and SQL Server. Azure Monitor logs are queried with KQL instead.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- RLS
Row-level security: filtering the data each person can see down to permitted rows. Power BI models apply it through DAX rules on roles, which bind just Viewers and anyone holding Read or Build; Fabric Warehouse instead uses a T-SQL policy that calls a predicate function.