Setting per-workspace defaults for OneLake storage
OneLake is the unified, tenant-wide data lake automatically provisioned for every Microsoft Fabric tenant, with one OneLake instance per tenant and data organized by workspaces and items. Workspace settings control how OneLake data is governed, accessed, and integrated with external tools, including domain assignment, storage region, and access via APIs or Azure Storage Explorer-compatible endpoints. Configuring these settings correctly is essential for enforcing governance, security boundaries, and data discoverability across the organization.
Must-know
- Every Fabric tenant gets exactly one OneLake automatically; you do not create or provision OneLake yourself, only configure workspace-level settings within it.
- Each workspace maps to a container in OneLake, and each item (lakehouse, warehouse, etc.) within that workspace gets its own folder structure following a fixed path convention.
- Workspaces can be assigned to a Fabric domain and subdomain to organize data ownership and apply governance policies at scale across the tenant.
- OneLake data access can be governed via workspace roles (Admin, Member, Contributor, Viewer) combined with item-level permissions, and OneLake data access roles allow more granular folder-level security within a lakehouse.
- OneLake supports shortcuts, which create references to data in other workspaces or external sources (like ADLS Gen2) without duplicating data, and workspace settings/permissions affect what shortcuts can be created or accessed.
- Tenant-level admin settings (configured in the Fabric admin portal) can restrict or enable certain OneLake capabilities, such as external data sharing or specific workspace features, so workspace-level configuration is often bounded by tenant policy.
A workspace contains a single lakehouse with two folders: one holding HR compensation tables and another holding sales pipeline tables. The HR security group must be able to read only the HR folder, and the sales security group must have full read/write only on the sales folder. No group should see the other team's data, and the engineer must avoid splitting the data into separate workspaces. Which workspace setting should the engineer configure to meet this requirement?
What you have tried across DP-700's objectives, not a readiness score.
Implement and manage an analytics solution
- Tuning a workspace's Spark compute defaults and pool sizing
- Grouping and governing workspaces with a Fabric domain
- Setting per-workspace defaults for OneLake storage
- Standing up an Airflow job runtime inside a workspace
- Connecting a workspace to a Git repository
- Managing schema changes with a database project
- Promoting Fabric items across environments with a deployment pipeline
- Granting and restricting access at the workspace level
- Locking down who can open a single Fabric item
- Layering row, column, object, and file-level security rules
- Hiding sensitive column values behind a dynamic mask
- Classifying Fabric items with a sensitivity label
- Marking a trusted item as promoted or certified
- Reading a Fabric audit log to see who did what
- Securing data at the OneLake storage layer
- Picking the right build tool among a dataflow, a pipeline, and a notebook
- Kicking off a job on a schedule or in response to an event
- Chaining notebooks and pipelines together with parameters and dynamic expressions
Ingest and transform data
- Deciding between a full reload and an incremental load
- Shaping source data ahead of a dimensional-model load
- Landing a continuous stream of data into storage
- Matching a workload to the right Fabric data store
- Picking a transformation tool from dataflows, notebooks, KQL, or T-SQL
- Linking to external data without copying it via a OneLake shortcut
- Keeping a source database continuously replicated into Fabric
- Moving data into Fabric with a data pipeline
- Writing transform logic in PySpark, SQL, or KQL
- Flattening related tables into one wide, denormalized shape
- Rolling records up with group-by aggregations
- Dealing with duplicate rows, gaps, and data that arrives late
- Selecting the right engine for a real-time workload
- Weighing storage-in-place against a linked shortcut for a Real-Time Intelligence table
- Weighing an accelerated shortcut against a standard one for query speed
- Routing and reshaping live events with an Eventstream
- Handling a continuous flow of records with Spark's structured streaming
- Querying and reshaping event data with KQL
- Aggregating a stream over sliding or tumbling time windows
Monitor and optimize an analytics solution
- Watching an ingestion job's health and progress
- Watching a transformation job's health and progress
- Tracking whether a semantic model's refresh actually succeeded
- Setting up an alert to catch a failure early
- Tracking down why a pipeline run failed and fixing it
- Diagnosing why a dataflow run failed
- Debugging a notebook run that failed
- Troubleshooting a misbehaving Eventhouse
- Troubleshooting a misbehaving Eventstream
- Debugging a T-SQL statement that failed
- Fixing a broken or unreachable shortcut
- Speeding up a Lakehouse table with maintenance operations
- Making a slow pipeline run faster
- Tuning a Fabric warehouse for faster queries
- Improving throughput on real-time streaming components
- Tuning a Spark job to run faster and cheaper
- Making a slow query run faster
Coverage checked against the published exam guide on Aug 11, 2026.
These are independent practice questions, written against this certification's published exam guide. They are not the certification vendor's own questions, and not the real exam.