Understanding Microsoft Fabric security is one thing. Translating a business requirement into the right permissions, roles, and implementation steps is another.

A requirement might sound simple:

“Our regional analysts need access to sales data through Spark and Power BI, but they should only see their region’s records—and sensitive columns must remain hidden.”

Working out where to enforce those restrictions, which identities need access, and how different engines behave takes careful reading.

That’s why I built OneLake Security Advisor.

It turns a knowledge base drawn from 96 Microsoft documentation articles into guided security-planning recommendations.

Users can:

  • Specify their data, audience, access methods, and restrictions.
  • Get a recommended approach with an explanation of why it fits.
  • Review a permission map and proposed access architecture.
  • Follow implementation steps with “At a glance” explanations.
  • Compare multiple audiences for potential access conflicts.
  • Download the plan as a PDF with Microsoft source links.

I’ve also scheduled weekly documentation checks to help identify changes that may affect the guidance. The site distinguishes source-check dates from recommendation-review dates.

A deliberate design choice: the advisor currently uses explicit selections and documented decision rules. The description box captures business context; it does not use AI to interpret the requirement. It also does not connect to your tenant or change permissions.

This is an independent prototype—not a Microsoft product or a substitute for validating security in your own environment.

My aim is to make OneLake security easier to understand, discuss, and implement.

If you work with Microsoft Fabric, I’d welcome your feedback:

What use case would you test—and what would make the resulting plan more useful?

Try it here: OneLake Security Advisor

#MicrosoftFabric #OneLake #DataSecurity #PowerBI #DataGovernance

← Back to all articlesJoin the discussion on LinkedIn ↗