Microsoft Certified: Fabric Analytics Engineer AssociateGovern and administer Fabric (10-15%)Hard

A data platform team is managing a critical production Lakehouse in Microsoft Fabric. They need to implement a security measure that ensures data within the Lakehouse can only be accessed by specific service principals and users, even if they have broader permissions at the workspace level. This access control must be granular, applying directly to tables and files within the Lakehouse, and should respect column-level and row-level security definitions. Which security model should the team leverage?

  1. ARole-level security (RLS) and object-level security (OLS) within the Lakehouse
  2. BSensitivity labels from Microsoft Purview
  3. CMicrosoft Entra ID (formerly Azure Active Directory) security groups for workspace access
  4. DWorkspace roles and permissions
Show answer & explanation

Correct answer: A. Role-level security (RLS) and object-level security (OLS) within the Lakehouse

Role-level security (RLS) and object-level security (OLS) are implemented directly within the Lakehouse (typically through SQL endpoints or Spark tables) to provide granular access control to rows and columns, respectively. This overrides broader workspace permissions and is the correct approach for securing data within the Lakehouse itself.

Why the other options are wrong

  • B. Sensitivity labels apply classification and protection policies, but don't inherently define direct data access rules like RLS/OLS.
  • C. Microsoft Entra ID security groups are used to assign users to workspace roles, but don't provide the granular, in-Lakehouse security required.
  • D. Workspace roles provide access at the item level (e.g., Lakehouse), but not granularly within the Lakehouse (tables, rows, columns).

Lakehouse RLS and OLS

Role-level security (RLS) and object-level security (OLS) in a Fabric Lakehouse allow for granular control over who can see which rows and columns of data, respectively, within tables.

  • RLS filters rows based on user identity.
  • OLS restricts access to specific columns or tables.
  • Applied at the data model or query level.
  • Overrides broader workspace permissions for data access.

Memory trick: To secure your Lakehouse data, use RLS for rows and OLS for objects.

More Govern and administer Fabric (10-15%) questions