Skip to content
CBT Nuggets
DemoBook a Demo

Implement Security and Governance

The skill focuses on implementing security and governance within Microsoft Fabric, emphasizing the importance of data security and governance in large enterprises. It covers key concepts such as access control, role-based permissions, and the distinction between security and governance. The material also explores the use of semantic models, row-level and column-level security, and the application of sensitivity labels and endorsements to ensure data integrity and compliance.

Full skill from Microsoft Certified: Fabric Analytics Engineer Associate (DP-600). Preview the IT training 23,000+ organizations trust.

53m

Skill 2 of 11 in Microsoft Certified: Fabric Analytics Engineer Associate (DP-600)

Introducing Fabric Security Administration

Let's start working with Fabric by administering access rights and privileges to the data inside of it.

Understanding the Fabric Layout

Let's understand how security can be enforced in Fabric at different layers.

Knowledge Check

What is the primary focus of security in Microsoft Fabric?

Workspace Security

Let's look at the broadest level of permissions, the workspace layer.

Knowledge Check

In the context of workspace permissions in Fabric, which role allows a user to create and edit data but not share it?

Item-Level Security

Let's now look at how to secure items within a workspace.

Knowledge Check

What is the recommended way to grant a user access to a semantic model without giving them access to the entire workspace?

Row Level Security (RLS)

Let's now get into the data layer itself and filter data out for certain users in a semantic model.

Knowledge Check

What is the primary purpose of implementing row-level security in a semantic model?

Column Level Security

Let's now restrict sensitive columns of data from view.

Knowledge Check

What is the purpose of column-level security in data governance?

Object Level Security in Semantic Models

Let's now alter a model's metadata to hide tables from certain roles.

Knowledge Check

What tool is used to implement object level security by editing the underlying semantic model's metadata?

File Level Lakehouse Security

Let's now look at how to control file access in Lakehouse.

Knowledge Check

In a Lakehouse environment, how is file access control typically managed?

Sensitive Data Marking and Endorsements

Let's now explore data governance with sensitivity labels and endorsements. Note: Sensitivity labels are largely governed in Microsoft Purview.

Knowledge Check

What must be done first to enable sensitivity labeling in Microsoft Purview?

CHALLENGE

Let's refresh what we've learned about security and governance in Fabric.

1. A company uses RLS to ensure regional managers only see sales for their assigned state. A manager is currently a Contributor in the workspace.

Knowledge Check

What should you change so RLS is enforced?

2. A semantic model contains an EmployeeSalary table. Regular report users should not be able to see the table or discover that it exists.

Knowledge Check

What should you implement?

3. Your organization has several sales semantic models, but one has been formally reviewed and approved as the trusted model for corporate sales reporting.

Knowledge Check

Which endorsement should it receive?

View Transcript

Introducing Fabric Security Administration

0:00Welcome to the content on security and governance

0:03in Microsoft Fabric.

0:04Look, I wasn't born yesterday.

0:06I know there's a chance you looked at the exam blueprint

0:09and saw security and governance of Microsoft Fabric

0:12and thought that's not the sexiest topic on this exam.

0:15And I'd have a hard time disagreeing with you.

0:18It's definitely not as fun as building things

0:20like ETL pipelines and strong semantic models

0:24with all sorts of nasty queries

0:26that ultimately produce really cool results.

0:28But here's the kicker.

0:30A business's data is arguably their most important asset.

0:35It's what drives every decision from the top to the bottom

0:39about how to move this whole thing forward.

0:41It tells you where you've been and where you're going next.

0:45And that's why it's absolutely critical.

0:47So when you administer Microsoft Fabric,

0:50you're in charge of your enterprise's data.

0:53And Microsoft Fabric is really built for large enterprises

0:56with a lot of data.

0:58So chances are, this is a really critical piece

1:01and high value item that you're in charge of.

1:04So you really need to understand

1:07how to lock down certain parts of your data

1:10so that it's not just out there

1:12for anyone in your enterprise to come along and see

1:15and worse, potentially change.

1:17Microsoft gives you a broad spectrum

1:20from the broadest range of things that you could administer

1:22like a whole workspace down to the individual rows

1:26or columns of data themselves.

1:28So you get to pick everywhere in between.

1:30These people and that person in this group

1:33needs access to these things,

1:34but we always got to keep the principle

1:36of least privilege in mind here.

1:38We don't want to give away too much access rights,

1:41too many privileges over too broad of a spectrum.

1:45And the temptation can be to do that

1:47because you get busy and somebody needs data critically

1:51and they don't have access to it.

1:52So you just go, ah, global admin.

1:54That happens all the time.

1:56So what we're here to talk about is you understanding

2:00what are your options when it comes to administer

2:02the security and governance, not just to Microsoft Fabric,

2:06but your data itself.

2:07So that's what we're exploring in this set of videos.

2:10Without further ado, let's get started.

Understanding the Fabric Layout

0:00So we are talking about security and governance in Microsoft Fabric. And as you can see,

0:05I'm here in my workspace. We're going to talk about workspaces a lot starting in the very next

0:10video. But first, we kind of need to talk about where we're going. There are two separate topics

0:15here, security and governance. Well, what's the difference between these? Security is who

0:26can access what? This is you as the administrator making a control, making a decision saying that

0:37so-and-so can access the workspace, or so-and-so can access the data flow, or so-and-so can access

0:44data in the lake house. Or maybe specifically, they can only access these columns in the lake

0:49house, or these rows in the lake house. Or maybe specifically, they can only perform these actions

0:55in the lake house. This is you tightening things up and locking down what it is that they're

1:02allowed to do. Governance, if I change colors here just a little bit, governance is all about

1:08sending a message to the people who consume the data. And it usually falls into one of two

1:15categories. There is usually an endorsement, which is where you as the owner of this data

1:25say it is good to go. So other people who use it can see, oh, Knox owns this data and he endorsed

1:33it. Therefore, I can trust the data that I'm connecting to, that it's accurate, that it's

1:40the latest version, that it has gone through this pipeline and this rigor and this standard

1:46that holds it up to a certain value. Simultaneously, governance also lets the end users know

1:54if the data is sensitive in nature. Does it control or contain personally identifiable

2:02information, or health information, or credit card information? So when they connect to it,

2:08they are seeing exactly what kind of data they're accessing. And importantly,

2:13if they should be aware that what they're accessing is sensitive by nature.

2:18You can see how these two, hang on, hang on, hang on, my paint. There we go. I had to fix my

2:25paintbrush here. You can see how these two could be used together. Because we might be in a

2:30situation where John does need access to the lake house, but John also needs to know that they trust

2:42the source of the data, that it is the latest version published by the correct team who

2:47created the data, and that sensitivity may be involved in the mix here. We're just picking

2:55on John there for instance. We might simultaneously say Jane over here needs to be able to administer

3:04things like this data flow because she is an ETL engineer, but she does not have any need to see the

3:12underlying data at all. So Jane, we might restrict her access to what the resulting data set in the

3:19lake house or the warehouse looks like, or the semantic model. Usually in large enterprises,

3:26things are broken down by teams, teams over a certain app or teams over a certain task like

3:36ETL versus semantic modeling. And this kind of makes the talk a little bit bigger here.

3:46When you're a fabric administrator here, let me get this out of the way. When you're a fabric

3:50administrator, you're sitting over the top of your enterprise's entire data ecosystem,

3:57their entire data library. That involves the data source, the ETL pipeline, the bronze,

4:05silver, and gold data stages. We're going to talk about those later. The data warehouse where the

4:12data lives in, the semantic model after it's been modeling. So you have a very large responsibility

4:19in a large enterprise where you then have to keep up with what app creates the data or consumes data

4:26and what task happens as it's moving through this and what teams are attached or responsible for

4:33each of these. So you end up getting a lot of levers and knobs to pull in the form of role

4:41based access control. You'll be able to say at this tier, these groups can perform these actions

4:49because they belong to a specific role. So as we progress through this set of videos,

4:55we're going to focus first and primarily on security and understanding where security happens.

5:02And then at each one of these layers, what roles or permissions do you have to set for other people?

5:11How can you tighten up or expand their permissions at this given level? And we'll walk through

5:17configuration examples on how to pull this off. First, we needed to set up the stage of what is

5:23security versus what is governance. Again, security is controlling access and permissions.

5:31Governance is how we label data so the consumers know what it is that they're actually working with.

5:38On to the next video where we begin security at the workspace level.

Workspace Security

0:00The first thing we're gonna talk about

0:02is workspace permissions.

0:03And as we can see here, I am in my DP 600 workspace.

0:08Now, here's the thing.

0:10What we're gonna do is we're gonna look at

0:12how we can manage access to this workspace.

0:15Because by default, I am the creator of this workspace

0:18and I've created everything in this workspace.

0:23All the content you're about to watch

0:25if you're following this playlist in order.

0:27Things like the pipelines, the semantic model,

0:29the lake house, the data flows,

0:31all of these things are things that I created.

0:33And all of these things,

0:35I am the only person who knows that they exist.

0:38Nobody else in my enterprise or organization

0:42can even see this workspace,

0:44let alone any of the contents or the data inside of it.

0:48So that's a pretty big burden for little old Knox

0:51to handle in a large enterprise, right?

0:53So when we give access to the workspace,

0:55here's the first thing that you understand.

0:57This is different from almost every other security posture

1:03in all of technology and IT and systems today.

1:08Take everything that you've learned about security

1:12and just throw it out the window.

1:15Because it's just gone when it comes to Fabric.

1:18If I make someone an administrator

1:22over this DP 600 workspace,

1:27they then can see and control everything underneath it.

1:32And you might then be thinking,

1:33okay, but what if I don't want them to see

1:37this semantic model?

1:39Can I deny them permissions to this very specific object?

1:44Because in security, the most specific thing wins.

1:49And the answer in Fabric is no.

1:54In Fabric, every one of these objects

1:57gets inheritance from above.

2:01And you cannot supersede it with a specific deny.

2:06So if I make John a workspace administrator

2:10and he gets to control everything in the workspace,

2:13that's it, that's what John gets.

2:17So we gotta be really, really careful

2:19when we give permissions to the workspace level.

2:23So the workspace sits over everything.

2:28Above the workspace, we then have objects.

2:34This could be like a semantic model.

2:38This could be like the lake house.

2:44And within those, we then have row-level security

2:49and column-level security.

2:51We also have a subset of object-level security,

2:55which can be things like individual files

2:58or individual tables inside of Direct Lake,

3:02Data Lake, and the warehouse itself.

3:06But when you start at the workspace

3:08and you're like, this person has access to the workspace,

3:10they get everything underneath it.

3:12Now, the good news is, is at the workspace level,

3:16there are roles.

3:18We don't just grant everyone administrator privileges

3:22to the workspace and they can control everything.

3:24So we're talking about the workspace now.

3:26And at this point, we're thinking,

3:28someone who genuinely does need to help

3:31manage the entire workspace.

3:34Within the workspace, I'm gonna put WKSPC for workspace,

3:38there are four roles, admin, member, contributor,

3:49and viewer.

3:52The admin is the owner.

3:55They have access to connect to and change everything

3:59in the entire workspace.

4:02And the biggest thing about here

4:04is they can change security settings.

4:07They can give people different permissions.

4:10When you think admin, think security,

4:13think security changes.

4:15It's not just about the data.

4:16It's really about changing the security posture of itself.

4:21When you think member, you start to think data owner.

4:27They can create, edit, which includes delete,

4:33and importantly, share data.

4:38That's what the member of the workspace does.

4:41And again, they're doing it for every piece

4:44of where data lives inside a workspace,

4:47because all of this is scoped to the workspace.

4:50The contributor can create and edit data,

4:56but not share data.

4:58They can't invite people, they can't share data.

5:01And viewer, you guessed it, is read only.

5:07So if we go into manage access,

5:11and I wanna add someone in here,

5:13and I may, let's go ahead and add Jacques Boudreau

5:17into the mix here, and I make them a contributor.

5:21Click add, and it's done.

5:24Jacques is now in this workspace right there

5:27as a contributor, and notice I can change

5:30their permissions anytime.

5:32Can I then go into this semantic model right here

5:37and say Jacques can't access this?

5:41No, Jacques is a contributor.

5:43As a contributor, he can create and edit data

5:46wherever it lives in this workspace.

5:49So that is really important for you to understand.

5:51He can't share, and he can't change the security privileges,

5:55but he can create or edit data

5:58anywhere it lives in this workspace.

6:00But for the workspace itself, it's relatively simple.

6:05Encompasses everything underneath the workspace,

6:07four roles, and you can manage the access right here

6:11on the manage access button.

6:13It's as simple as finding someone in their intra ID

6:16and setting a role that they can use right there.

Item-Level Security

0:00So let's pick on this semantic model

0:02because the semantic model really is

0:04like the end state of your data.

0:07This is ultimately the shape of the data

0:09that we want our report analysts

0:11and report creators to connect to

0:14and build visualizations and dashboards.

0:16This is after ETL has happened.

0:19This is after it's loaded in the warehouse.

0:21Then we've created the complex calculations

0:25and aggregations needed to answer questions

0:28like what is the year over year sales percentage growth?

0:32That's what is in a semantic model,

0:34that number, that math, given whatever years

0:37you're looking at.

0:39That's what the model does.

0:41So if I have people where their whole job

0:44is either creating models or editing models

0:48or connecting to models,

0:50do I want to give them access to the workspace?

0:54No, even with a view only or read only,

1:00even as a viewer role,

1:02I don't want them to be able to look at the lake house,

1:04the data flow, the pipeline, the warehouse.

1:07I don't, they don't need to see that.

1:09They only need to see what's inside the model.

1:14So how do we go about getting, say,

1:17Alice permissions to just the model

1:20such that Alice doesn't get access to the workspace?

1:24Well, what I'll do is I'll go into the model itself

1:28and it will load after a minute.

1:32Here it comes.

1:33Great.

1:35And what I'll then do is I'll go to file

1:38and I'll go to share.

1:40And from here, we just type in the name of the person

1:43that we want to share this to.

1:44Now, I actually don't have an Alice in my environment

1:48and I'm trying to think about all the names

1:49that I do have in my environment.

1:51I think I have a Simon, Simon Simenow.

1:55Yeah, there you go.

1:55There's Simon Simenow right there.

1:57So what do we then allow Simon to do?

2:01This is where we scope the permissions.

2:03Allow recipients to modify this semantic model.

2:07Are they a editor, a contributor, or are they read only?

2:11We'll give them that.

2:13Allow recipients to share this semantic model.

2:16Are they maybe the manager of a team

2:19and then they can then distribute it

2:21and fan it out down to their team from there?

2:23Or are they kind of an end user

2:25and they never need to be able to control

2:27who gets access from there?

2:29Allow recipients to build content

2:32with the data associated with this semantic model.

2:35Maybe they're a report creator

2:37and they are gonna use Power BI

2:39to build visualizations and dashboards on top of it.

2:43That's where we're up to this.

2:45Now, I'm gonna tell you right now,

2:48the average end user who's connecting to a semantic model,

2:52they will probably build dashboards and reports,

2:54but it's also good for them to be able

2:56to create their own measures and their own aggregations

3:00and their own calculation groups.

3:02It is not uncommon.

3:05It is in fact common for a Power BI user

3:09to also be good at modeling data.

3:12So in my head, I'm gonna tell you,

3:15I think it's gonna be most common

3:17that you allow recipients to modify the semantic model

3:20because they'll be creating or changing measures,

3:23calculation groups, and so on, time intelligence analytics,

3:27and they're gonna wanna build reports

3:29on top of it as well.

3:31It will be much less common for them

3:34to need to be able to invite other people

3:36to this semantic model.

3:38Unless they are a manager of a team,

3:41then they, he or she will then be like,

3:45okay, I've got control of this model.

3:47I'll then fan it out to the rest of the team.

3:49And the cool thing about that is let's say

3:51Alice is the manager,

3:53and she has five people reporting to her.

3:57Well, because we're scoping Alice's permissions

4:00to just this model,

4:01she can only invite people to just this model.

4:04They don't get a backdoor access into the workspace itself.

4:08They're not getting access to the lake house

4:11or the warehouse or the data flows

4:15or the pipeline or anything like that.

4:17We're really just talking about the model.

4:19So here we've gone from workspace level permissions

4:23to item, that way I did a capital I,

4:26a capital T, and then a lowercase e,

4:28item level permissions.

4:31In this case, the model is an item.

4:36Now, again, the interesting thing here

4:38is the workspace contain roles.

4:40The model doesn't.

4:41The model just has check boxes

4:43with what they're allowed to do.

4:45So when I click grant access there,

4:47we've just granted Simon access to the semantic model.

4:51Does it have to in there?

4:53No, he may also need access to another thing

4:58in the environment like the lake house

5:01where the model is coming from.

5:03So when I go into the lake house here,

5:07and then from here we think,

5:09okay, well, I probably wanna manage control

5:12and access to this via security.

5:14Well, guess what?

5:15Security to a lake house or a warehouse

5:19works exactly like it's always worked with SQL,

5:22where we actually have SQL-based roles

5:26and we'll grant them access to SQL-based schemas.

5:31So what I'm trying to show you here

5:35is that you're gonna shift out of the fabric administrator

5:37for a second and become a database administrator

5:41when you wanna grant access to a lake house or a warehouse.

5:48And you've got a lot of common things

5:49like the database owner, the security admin

5:53who can only control access rights

5:55and can't read the data itself.

5:57You've got a data writer, a data reader role

6:00and someone who can actually just handle backups.

6:03The point, the real big takeaway here

6:05isn't so much that you need to know

6:08that lake house has built-in database roles

6:09and you grant roles to certain schemas.

6:11It's that when you get to item level access,

6:16it is different from one item to the next.

6:19You've seen how we granted access to a semantic model.

6:23It was just type their name and click a couple check boxes.

6:25When we get into a SQL analytics lake house,

6:29guess what?

6:29We're actually using T-SQL to grant permissions

6:33to certain tables, schemas and so on.

6:37One more for good measure,

6:39let's take a look at a Dataflow Gen 2.

6:42This is actually kind of a gotcha

6:44because there's not really a place

6:46where you can invite someone to collaborate

6:49on a Dataflow Gen 2.

6:51In fact, a lot of Microsoft documentation will tell you

6:54you just need to give them contributor access

6:57to the workspace itself.

6:59Now, that being said, connections are a little squirrely

7:02because the user will also have to have permissions

7:07to the underlying data source too,

7:10to build a connection or connect to the source data as well.

7:14So that's another thing you'll have to keep in mind

7:16is that what kind of connection permissions

7:20and who is connecting in

7:21can also alter what's going on with the Dataflow.

7:25So all of that is to say for item level permissions,

7:28instead of granting someone access

7:30at the whole workspace level,

7:31it's kind of a, you need to look at it

7:34and make sure that they can actually have permissions

7:36to the underlying items first.

7:39A lot of times when it comes to ETL jobs

7:42like Dataflows, pipelines or copy jobs,

7:45there is no invite them to this one specific item

7:49and they will start looking at workspace permissions

7:51to get to that point.

Row Level Security (RLS)

0:00Now we're talking about row-level security.

0:02And when we talk about row-level security,

0:05we're talking about inside the data itself.

0:09If you're thinking about an Excel file

0:11and there are rows of data, you know,

0:14containing records of whatever transactions took place,

0:17and you're thinking to yourself,

0:19I want some of my employees or consumers

0:23to be able to see some of these records,

0:25but not all of them,

0:26that's where row-level security comes into play.

0:29Example, let's say we have a sales territory.

0:33Some people are in Texas, some people are in Louisiana,

0:37some people are in Mississippi.

0:40I may only want my Texas team to see Texas records.

0:45I don't want them to see Louisiana or Mississippi records.

0:48That's the idea here.

0:49We can actually say this user belongs to the Texas group,

0:54therefore make sure that whatever visualizations

0:57they interact with are only specific to Texas.

1:01That's what row-level security is all about.

1:04So we don't have to make some magical filter query

1:07in the Power BI report itself.

1:09We can actually do it in the model, in DAX,

1:13and that's what we're gonna work through in this video.

1:15This is really important in semantic modeling.

1:18Now, I am in view-only mode right now.

1:21You can see that we're in viewing mode.

1:23If I change this to editing mode,

1:25that will unlock all of the things

1:28that we see right here in the security section

1:31with manage roles and manage permissions.

1:33But what you need to see first is the semantic model

1:37tells you the direction that filters occur.

1:41So if I say I have a salesperson

1:43that's assigned to only one huge enterprise,

1:47and they should only ever be able to see

1:49this one company's sales,

1:52we can see that by selecting a company,

1:56it will then filter out the resulting sales

2:00in this direction.

2:01That is what this arrow means,

2:03is the customer can filter the resulting sales

2:07in the sales table.

2:08So when we understand that direction,

2:10I can then say, okay, John, or let's actually,

2:15let's do this, let's say Simon,

2:16because I actually have a Simon.

2:18Simon is assigned to this customer.

2:21Therefore, Simon should be in that customer's role

2:25where these permissions filter out

2:27and only show them that customer's sales.

2:30That is row level security.

2:32So now that we understand the relationship

2:34going from the customer table to the fact table,

2:37we can build a filter on the customer table,

2:40and it will result in a filter of the fact table,

2:44the sales table, where all the sales records are.

2:46So the first thing we need to do is manage roles.

2:49We need to create a role for this specific filter.

2:52And what we'll do is we'll create a new role,

2:55we'll filter it on the customer table,

2:58and we'll say, what is this new rule?

3:00Well, if the company name equals something,

3:04we got to actually get a company name here.

3:07I'll just run a query real quick

3:09and see what the result is here.

3:10And we'll just grab a company name like A Bike Store.

3:14How simple is that?

3:16A Bike Store.

3:17All right, so with that,

3:19we'll say if the company name equals A Bike Store,

3:24then that is our security role.

3:27Notice you can look at this in DAX

3:29by switching this to the DAX editor,

3:31and if the company name is A Bike Store,

3:34that is the role itself.

3:36Switch it back to the default editor, and it looks good.

3:39Check this box, and we can see

3:41kind of how we're managing this.

3:43I'll click Save, and that'll create the role.

3:46It hasn't created an assignment yet.

3:49In fact, what we might want to do

3:50is we might actually want to rename this

3:52and say A Bike Store role,

3:58and just save it to give it an updated name.

4:00There we go.

4:01So now that I've got this role,

4:04I need to assign it to an end user,

4:07and this is where we'll type in Simon Simino's role again,

4:11or user group.

4:13We'll say we'll add that particular user,

4:15and click Save.

4:17And now Simon, when they access this,

4:21they will only see the Bike Store role.

4:24But again, this is a really important thing to say.

4:28We have answered the question,

4:30what can Simon see inside of this data?

4:34And that is A Bike Store's data inside the semantic model.

4:41But don't forget,

4:43we still have to give Simon access to the semantic model

4:46in the first place so that they can see it.

4:50So if I close this and you go to Manage Permissions,

4:54make sure that Simon has access to this.

4:58In this case, he has read, write, and build access to it.

5:02You can choose which one of these to remove right here.

5:07Now, what is build versus write versus access?

5:12Remember those three checkboxes.

5:14Access is view, read only.

5:21They can see that the semantic model exists

5:23and they can see what's inside of it.

5:25Now, scope to that role.

5:26Write is they can edit the semantic model itself.

5:34Build, reports, and dashboards,

5:40built on top of the semantic model in Power BI.

5:45That's really what we're talking about here

5:48when we think about build.

5:49Dashboards, reports, Excel workbooks,

5:52which can also be built off of this semantic model.

5:56So now we understand row-level security

5:59and how we can say this specific user

6:01should only be able to see this data

6:04inside of this semantic model

6:06and subsequently reports and dashboards.

Column Level Security

0:00Row-level data filtered out what rows a user is supposed to see

0:05so that they only see data that's relevant to them

0:08or their job or their purpose.

0:10Like we said, if you work in Texas,

0:12you may only need to see Texas data.

0:15There's no reason for you to see Louisiana data.

0:17Just focus on your state and your territory.

0:21Column-level data goes,

0:23it kind of asks a different question.

0:25What attributes of this data, of this record,

0:29are relevant to you?

0:30And lots of times you see this filtering out things

0:33like PII.

0:35Maybe we want them to see sales numbers.

0:37We don't want them to see, say,

0:40customer email addresses or phone numbers.

0:42So we can remove the phone column or the email column

0:47from what a report analyst might be able to see.

0:50So we'll go ahead and jump into something like my lake house

0:54and start to look at how to configure this.

0:57We'll jump into the lake house first.

0:59Then from here,

1:00we're gonna look for Manage OneLake Security.

1:02So I'll jump into Manage OneLake Security

1:05and we can see we've got a default access role.

1:09There is a default reader

1:11who is granted the read permission.

1:14Let's create a new role and call it Sales Analyst

1:18because they wanna analyze sales,

1:20but we don't necessarily want them to be able to see

1:23customer-specific details.

1:25So saying this is Sales Analyst,

1:27we're gonna give them read permissions.

1:28They don't need to edit data.

1:30So we'll leave the read checkbox selected and click Next.

1:34Now what?

1:36The next question is what data can this role access?

1:40Not necessarily specific person.

1:41We'll give the role to a person later.

1:44Do they need to see all data

1:46or maybe just a subset of this data?

1:48Yeah, subset.

1:48We're gonna do selected data right here

1:50and we don't have any selected data yet.

1:53So we'll click Edit and we'll start browsing

1:55for the data that we want to look for.

1:57Let's make our way to that customer table.

2:00We'll go into Sales LT

2:02and I'll grab the customer delta table

2:04that lives right there.

2:08Maybe we'll take a look at customer address too

2:10and see if there's anything we want them to have

2:12or lock down.

2:13So I'll click Add Data right here and it brings them in

2:16and you can expand it out and see what all did we choose.

2:19We see the table and the data permissions are set to read.

2:24But that just gives them full access to these full tables.

2:28No, we need to go back in and edit this,

2:31make our way back.

2:32Hang on, don't check the whole tables.

2:34Go back into the schema

2:36and let's grab say this customer table for a second.

2:40With the customer table, give it a click

2:43and now we can kind of see a group of files

2:46that exist related to this customer table

2:48but then go to data access.

2:50Here we can say row level security or column level security.

2:56And from here we can start to specify the things

2:58that we want to take out.

3:00For instance, I don't want them to have read access.

3:03We're gonna hide the email address and the phone number.

3:08We should probably also hide anything related

3:11to their passwords too, shouldn't we?

3:14So having hidden the email address, the phone number,

3:17the password hash and the password salt,

3:20I'll click add data now.

3:22And when we expand this and look at the customer,

3:26we see there are some data access permissions,

3:29one or more CLS constraints,

3:31column level security constraints are applied to this table.

3:35So click next and then we add members to this specific role.

3:41So I'll add Simon in here.

3:43They can now work with this table

3:46but they won't be able to see those specific columns.

Object Level Security in Semantic Models

0:00The next thing we're talking about is object level security.

0:03And here I've got something on the screen.

0:05It's an application called Tabular Editor.

0:11You haven't seen this application

0:13or work with this application yet.

0:15This actually comes at the very end of this course

0:18when we start using an external third-party tool

0:21to edit the underlying semantic model.

0:25Now, here's the thing.

0:26In Fabric, you get to work with the data

0:29in the semantic model.

0:30And you get to build aggregations and build relationships,

0:34but you don't get to work with every single thing

0:37that the model exposes in Fabric, in the website.

0:41To get to the underlying properties

0:45of the semantic model itself

0:49and the metadata that's stored in the semantic model itself,

0:53that's when you need a tool like Tabular Editor.

0:56And Tabular Editor is where object level security

0:59right there lives.

1:02The idea with object level security,

1:04we enforced row level security in our semantic model,

1:08but we might want to enforce things

1:11like column level security or remove tables entirely

1:16from the view of someone in this role.

1:18And that is what object level security is all about.

1:21All of these things, all of these tables are objects.

1:26So sure, we can write a query,

1:28a DAX query that filters out rows,

1:30but we can't really do anything

1:32that stops them from seeing tables.

1:34So from here with Tabular Editor open,

1:37and again, you're gonna learn more about Tabular Editor

1:39at the end of this series.

1:40We're just talking about object level security here.

1:43I can choose my role.

1:44So look, if I click on each one of these things,

1:46you can see Tabular Editor shows me

1:49all sorts of properties here.

1:52And I can say things like,

1:55no one should ever need to see the customer ID column.

1:59And I can change that to be a hidden column

2:02by changing this dropdown to true.

2:05And then when I click the save button right here,

2:08that ships this change from this local computer

2:12up to Fabric.

2:14But if I want to get into this role right here

2:16where I can see I've got some row level security enabled

2:19on one of these six tables.

2:21If I want to add some object level security on these tables,

2:24I'll expand this and I can say, you know what?

2:27They don't really need to see the sales channel either.

2:30So I can change this to be none.

2:34And now I've created a hidden sales channel table rule

2:38for that specific role.

2:40When I click the save button again, there it goes.

2:44So a very quick video on what object level security is here

2:50when we can change what a role sees as a table as a whole

2:55is altering the object and not just the individual roles.

2:58But again, this is something that really needs to be done

3:01in a tool like Tabular Editor.

3:03It's challenging or tricky to get to the TM.

3:08Let me get the TMDL.

3:10It's basically a metadata data language file,

3:14a tabular metadata data language,

3:16say that three times fast,

3:17file where you can edit the underlying metadata

3:21in these objects to secure it by hiding specific objects.

File Level Lakehouse Security

0:00Within a Lakehouse, we not only have tables that we query like a SQL Analytics endpoint,

0:06we also have data lake storage where we can store files of all sorts, not just CSVs, but JSON,

0:14Parquet, whatever it is. It's very likely that we can store it, query it, and process it here.

0:20And as such, we can create roles around these data files and folders on top of that.

0:27So back in manage one lake security, we have our sales analyst item right here.

0:34And of course, we granted permissions to specific tables with column level security from here.

0:42But we can also hit edit data and take a look at what we can do with files too.

0:46So maybe I want them to see the business data file. Great.

0:51So what I'll do is I will check off the files button here and then hit add data.

0:57And now we've given them the ability to explore certain files in the file structure.

1:03Now, the kicker here is it doesn't work at the individual file level.

1:08It works at a folder level. So if we wanted to try and grant them permissions in one folder,

1:13but not the other, we'd have to restructure well in one file, but not the other.

1:17We'd have to restructure this to actually be in folders.

1:22So first, let's create a new subfolder and we'll call it public.

1:27And then we'll create another new subfolder and we'll call it private, like so.

1:36So to clean this up, what I'll do is I'll delete both of these files, get rid of them entirely.

1:44And then in the private folder, we'll upload the raw source that I was working with.

1:49I'll just do upload files and we can see I've already seen where a

1:53recent upload was. I'll grab the file from the folder,

1:57hit upload, and there it goes. Now we've got this item in the private folder.

2:03Simultaneously, I'll go back to the copy job where I got that data

2:09and I'll put this copy job landing in the public folder.

2:14So what I'll do is I'll wait for the resolution on the screen to adjust itself,

2:20because that's what happens in Safari sometimes when working with fabric.

2:24Here it comes. Maybe.

2:26Maybe what I'll do is I'll just click on the edit mapping button

2:29and then wait for that resolution to adjust here.

2:31There we go. Now I've got the edit mapping button brought up.

2:34We'll change the data destination to be in the public folder.

2:38And it's clicking OK. It's got it saved.

2:40Now we've got the file name and everything else is ready to rock and roll.

2:45I'll just make sure I edit the map. Mapping looks good.

2:48We've got all the columns and I'll run the job to make sure the copy takes place.

2:55We see it's in the queued state after about 10 to 15 seconds.

2:59We'll see it actually be successfully completed and we'll then have the data

3:04cleaned up where we'll have the folders and the files and we'll have the original source

3:09as well as potentially let's pretend it was a cleaned up one that went through an ETL pipeline.

3:14So there it goes. It succeeded.

3:17So now when I jump back to my lake house,

3:20we'll wait again for the resolution to adjust.

3:23I'll hit public and now I see the data is in the public folder,

3:26but I can't really do much until the resolution adjusts.

3:29So we'll just wait. There we go.

3:31After about 30 seconds, it's back.

3:33So now when I manage my one lake security,

3:37because I've got a folder structure in place, I'll go into sales data analyst.

3:41I'll edit the data and instead of granting access to all files,

3:46I'll grant access to only public. We'll say add here.

3:50And now that role has access to the public folder and not the private one.

3:55So it's another way to do file level security and file level object storage selection.

Sensitive Data Marking and Endorsements

0:00You as an administrator have the ability to allow people to attach their own security

0:07sensitivity settings or labels. You can kind of think about them as really nothing more than a

0:13label or a tag to a data set like a lake house or a semantic model or a Power BI report. But first,

0:22you have to actually enable this feature. Well, let's start from the very beginning. First of all,

0:27you don't get a pre-built set of sensitivity labels for data. You have to create them yourself

0:34in Purview. So you might create something like private or internal. You might create something

0:43like PII to label it with. You might create something as PHI. You might create something

0:49as PCI. Whatever compliance thing that you're trying to identify here, you'll go into Purview

0:58and create these data labels. And then once you enable the ability for Fabric users to attach

1:07a sensitivity label to data or Power BI content or downstream content, notice you'll see all of

1:16these things are disabled by default. So that's what you need to know is that nobody can do this

1:24to begin with. So you have to create your own labels in Purview. Then you have to go into your

1:29global administration settings. Let me show you how to get here. Gear again, admin portal,

1:36then on tenant settings, scroll all the way down until you get to information protection.

1:40Then you'll want to flip these on and we'll say apply. And well, we can't do this right now

1:49because it'll also be applied. Something went wrong. Okay. Oh yeah. It tells you that you

1:54have to have sensitivity labels already created in Purview. I don't have the licensing to do that.

2:02I don't have the security licensing to do Purview, but like I say, it's relatively simple.

2:08You will just create internal private, whatever labels you want, and then come here and turn it on.

2:16Once you've got those created, let me hit discard all and show you, you'll come into something like

2:22your lake house right here. And in your lake house, right at the top in this section, there

2:28will be a fan out button with a dropdown where you can set a sensitivity label at this point.

2:35That way it alerts people who are working with this data. They then know, oh, this has a

2:42sensitivity classification attached to it. So I shouldn't just download it as a CSV and put it on

2:49a thumb drive and take it home. Now it doesn't just stop there within Purview. They do have

2:55something called fabric protection policies. This is outside the scope of the DP 600,

3:05but I want you to know that it exists. If you go into Purview and create a fabric protection policy,

3:12you can then say, if this label like sensitive, PHI, PII, then these users don't get access to it.

3:23You can restrict access based on a Purview label in fabric, but this is configurable

3:30in the Purview side of things. Now, that's the first thing I want you to know about governance,

3:35of course, is sensitivity labeling and just signaling to end users what kind of data they're

3:39working with. There's another thing that's also kind of a complex one to wrap your head around,

3:43unless you work for a very large environment. And that is endorsements. If you work with a

3:50very, very large enterprise and they have lots of data and you may have report writers

3:59on one team, semantic modelers on another team, ETL pipeliners on another team,

4:08or maybe there's even multiple teams within these sections because they're app specific.

4:13How do you connect these people together? How does the modeler say, hey, I've just created this new

4:21model that's really good. You report writers should know about it and you ETL people should

4:26build to help me flow into this model and keep that pipeline going. This is where endorsements

4:32come into play. And it's not just you, the creator, who gets to endorse your own work.

4:38Team members who also have write permissions can also endorse your work and help your other teams

4:46discover your data or your product, the thing that you created, and by signaling the degree

4:52of which you endorse it. Now on almost every single one of these resulting data things,

4:57like a lake house, a warehouse, a model, if we go into the settings, eventually somewhere in here,

5:04you will find an endorsement and discovery button. And it tells you,

5:08help coworkers find your quality content by endorsing this semantic model and making it

5:14discoverable. By default, none is selected everywhere. This semantic model will appear

5:20in search results, but it won't show up as endorsed. Promoted is when you're ready to

5:25distribute the semantic model to your coworkers, promote it to let them know. Basically let them

5:30know it's done. It's production. We can just feed into it now. It's not a work in progress.

5:36Then you have a layer above this where you have certified. This is where we're really saying like

5:41the whole organization has put their stamp on this product and you should know about it.

5:47Now, master data is grayed out and it even comes with a link. How do I get my semantic

5:53model endorsed as master data? Are you ready to see the funniest thing? If it says the link here

5:57is how do I get my semantic model endorsed as master data? I give it a click and the link tells

6:03you if you click this link, you'll find out how to get your item endorsed. Even though it takes

6:10you to this page where I go to learn about it. It's like a loop. You could click this link forever

6:16and maybe one day it'll get. The idea here is ultimately, this is actually a global tenant

6:23wide setting that is disabled by default. The actual tenant administrator has to enable the

6:30master data feature and then assign a master data certifier, a person that they will say,

6:37this person is the master data certifier. This becomes like the whole enterprise runs on this

6:43data. When you select one of these, it then signals it to the rest of the users. This product is

6:50endorsed and is good to go in your environment. This is what governance is all about. It's about

6:57signaling what kinds of data lives underneath and whether or not you can trust it, as well as

7:03if it's sensitive to begin with. Now we've talked about security and governance in Microsoft Fabric.

7:09I hope this has been informative for you and I'd like to thank you for viewing.

CHALLENGE

0:00Let's refresh what we've learned about security and governance with Microsoft Fabric.

0:06A company uses row-level security to ensure regional managers only see sales for their

0:13assigned state. A manager is currently a contributor in the workspace. What should you

0:20change so row-level security is in force? Change them to a viewer. Here's one of the catches

0:27in Microsoft Fabric and you might see this on the DP 600. The moment somebody has right-level access

0:35to the underlying data, row-level security is tossed out. You have to have a read-only access,

0:43view-only access to a semantic model in order for row-level security to be enforced. So contributor,

0:51member, or admin, row-level security is not enforced. They get to see all the data because

0:57they're in there editing it. A semantic model contains an employee salary table.

1:04Regular report users should not be able to see the table or discover that it even exists. What

1:11should you implement? Column-level security, object-level security, right there. We saw this

1:16with Tabular Editor, where we can not only hide columns, which is clever and useful, but we can

1:22also hide whole tables or objects themselves in the metadata. Your organization has several sales

1:30semantic models, but one has been formally reviewed and approved as the trusted model for corporate

1:38sales reporting. Which endorsement should it receive? A little tricky because it could be

1:43different from one organization to the other. But the idea here is if it's gone through a

1:48formal review and approval process to be used for reporting, then the answer here is certified.

1:57Master data is where it is not necessarily used for reporting, but it is the golden standard of

2:03the data itself that report models can be derived from. It can be forked and derived.

2:10Promoted means someone is endorsing it to be used publicly, but it hasn't been formally reviewed

2:17and approved. Certified is where the company itself is saying this is the one that we want

2:25to use for internal reporting. So that's been refreshing what we know about security and

2:30governance in Fabric.

What's next?

Ready to keep going?

For your team

Bring this training to your team

See how CBT Nuggets helps IT teams close skills gaps, hit compliance targets, and prove training ROI.

Book a Demo
Just need Microsoft Certified: Fabric Analytics Engineer Associate (DP-600)?

Learning on your own? Browse individual plans ($49/month, billed annually)

Not ready to buy?
with no purchase required. Already have an account?
Book a Demo