OneLake Security: A Deep Dive
Proposed session for SQLBits 2026TL; DR
Security in Microsoft Fabric goes beyond locking data. This session dives into OneLake Security, showing how access is unified and enforced across Lakehouses, Warehouses, and Semantic Models using roles, policies, and best practices for governed analytics.
Session Details
Security is no longer just about locking down data—it’s about enabling safe, scalable, and governed access across your entire analytics platform. In this deep dive session, we’ll uncover how OneLake Security operates under the hood and show you what’s really happening when you secure data in Lakehouses, Semantic Models, and Warehouses within Microsoft Fabric.
We’ll start by contrasting the “before Fabric” world—where security was often fragmented and siloed—with the “after Fabric” approach, which unifies access through centralized roles, policy-driven controls, and consistent enforcement across all data experiences.
Expect a technical walkthrough of how OneLake handles access at multiple levels: from workspace roles and OneLake data access roles, to folder and table permissions, row-level filters, and column-level restrictions. We’ll go behind the scenes to show how these mechanisms are enforced internally—whether you're accessing the data via Spark in a Lakehouse, SQL in a Warehouse, or consuming it through a Semantic Model in Power BI.
You’ll also gain insight into how shortcuts behave across domains, how Fabric ensures isolation and inheritance, and what best practices to follow to maintain a secure and compliant data environment.
If you’re responsible for data security, architecture, or governance in Fabric, this session will arm you with both a conceptual understanding and a technical foundation to secure your analytics estate—end to end.
We’ll start by contrasting the “before Fabric” world—where security was often fragmented and siloed—with the “after Fabric” approach, which unifies access through centralized roles, policy-driven controls, and consistent enforcement across all data experiences.
Expect a technical walkthrough of how OneLake handles access at multiple levels: from workspace roles and OneLake data access roles, to folder and table permissions, row-level filters, and column-level restrictions. We’ll go behind the scenes to show how these mechanisms are enforced internally—whether you're accessing the data via Spark in a Lakehouse, SQL in a Warehouse, or consuming it through a Semantic Model in Power BI.
You’ll also gain insight into how shortcuts behave across domains, how Fabric ensures isolation and inheritance, and what best practices to follow to maintain a secure and compliant data environment.
If you’re responsible for data security, architecture, or governance in Fabric, this session will arm you with both a conceptual understanding and a technical foundation to secure your analytics estate—end to end.
3 things you'll get out of this session
Understand OneLake Security internals: Learn how security is designed and enforced across Lakehouses, Warehouses, and Semantic Models in Microsoft Fabric.
Apply unified access controls: Gain practical insight into roles, policies, row- and column-level security, and how access is governed across different data experiences.
Adopt security best practices: Discover recommended patterns for securing, isolating, and managing access in a scalable and compliant Fabric analytics environment.
Speakers
Stijn Wynants's previous sessions
Synapse Q&A with PG
SQLBits' has brought members of the Azure Synapse Program Group to Wales to ask YOUR questions. Bring your questions for: Dedicated SQL Pools, Serverless SQL Pools, Spark Pools, Pipelines, Kusto and everything else Synapse related.
What's New and Cool in Azure Synapse Analytics
Azure Synapse Analytics is a unified platform for end-to-end analytics. Join this session to find out about recently announced updates to Azure Synapse and to see the new features in action and learn in which scenarios and how you can use them.
Reporting on 1.4B rows with Serverless SQL Pools
Building a dashboard using Serverless SQL Pools in a performant way
Azure DW and Power BI, reporting at the speed of light!
In this action-packed demo full session, we will be showing you how to combine Azure DW and Power BI to get optimal performance for running your day to day reports.