Skip to content

Setting per-workspace defaults for OneLake storage

OneLake is the unified, tenant-wide data lake automatically provisioned for every Microsoft Fabric tenant, with one OneLake instance per tenant and data organized by workspaces and items. Workspace settings control how OneLake data is governed, accessed, and integrated with external tools, including domain assignment, storage region, and access via APIs or Azure Storage Explorer-compatible endpoints. Configuring these settings correctly is essential for enforcing governance, security boundaries, and data discoverability across the organization.

Must-know

  • Every Fabric tenant gets exactly one OneLake automatically; you do not create or provision OneLake yourself, only configure workspace-level settings within it.
  • Each workspace maps to a container in OneLake, and each item (lakehouse, warehouse, etc.) within that workspace gets its own folder structure following a fixed path convention.
  • Workspaces can be assigned to a Fabric domain and subdomain to organize data ownership and apply governance policies at scale across the tenant.
  • OneLake data access can be governed via workspace roles (Admin, Member, Contributor, Viewer) combined with item-level permissions, and OneLake data access roles allow more granular folder-level security within a lakehouse.
  • OneLake supports shortcuts, which create references to data in other workspaces or external sources (like ADLS Gen2) without duplicating data, and workspace settings/permissions affect what shortcuts can be created or accessed.
  • Tenant-level admin settings (configured in the Fabric admin portal) can restrict or enable certain OneLake capabilities, such as external data sharing or specific workspace features, so workspace-level configuration is often bounded by tenant policy.
Check this objectiveFree · always available

A workspace contains a single lakehouse with two folders: one holding HR compensation tables and another holding sales pipeline tables. The HR security group must be able to read only the HR folder, and the sales security group must have full read/write only on the sales folder. No group should see the other team's data, and the engineer must avoid splitting the data into separate workspaces. Which workspace setting should the engineer configure to meet this requirement?

Your objective map0 tried · 0 right · 54 untouched

What you have tried across DP-700's objectives, not a readiness score.

Coverage checked against the published exam guide on Aug 11, 2026.

These are independent practice questions, written against this certification's published exam guide. They are not the certification vendor's own questions, and not the real exam.