Microsoft Certified: Fabric Analytics Engineer AssociateGovern and administer Fabric (10-15%)Easy
A company is implementing a new data analytics solution in Microsoft Fabric. They want to ensure that access to sensitive data stored in a Lakehouse is restricted based on the user's department. Specifically, users from the 'Sales' department should only see sales-related data, and users from 'Marketing' should only see marketing-related data, even when accessing the same Lakehouse table. Which security mechanism in Fabric is MOST appropriate for this scenario?
- AMicrosoft Entra ID group assignments
- BWorkspace roles and permissions
- CObject-Level Security (OLS)
- DRow-Level Security (RLS)
Show answer & explanationAnswer & explanation
Correct answer: D. Row-Level Security (RLS)
Row-Level Security (RLS) is designed to restrict access to specific rows in a table based on user identity or attributes (like department). This allows different users to see different subsets of data from the same table, which precisely matches the requirement.
Why the other options are wrong
- A. Microsoft Entra ID group assignments are used to manage user groups, which can then be used in RLS rules, but they are not the mechanism for data filtering itself.
- B. Workspace roles control access to items and capabilities within a workspace but do not filter data within an item based on row-level conditions.
- C. Object-Level Security (OLS) restricts access to entire columns or tables, not specific rows within a table.
Row-Level Security (RLS)
Row-Level Security (RLS) is a data security feature that restricts access to individual rows in a database table based on the execution context of the user, typically their identity or role.
- Filters data at the row level.
- Ensures users only see authorized data subsets.
- Implemented using security predicates or filters.
Memory trick: RLS is like a bouncer at a club, letting only certain 'rows' of people in.