Skip to content

Securing data at the OneLake storage layer

OneLake security lets you define centralized, fine-grained access control (at the folder, table, row, and column level) directly on data stored in OneLake, primarily for Lakehouse items, so permissions are enforced consistently no matter which engine or tool queries the data. Learners must know how to create OneLake data access roles, scope them to specific folders/tables (with optional row/column filters), and assign them to users or groups. It's important to understand how this data-level security layers on top of, rather than replaces, workspace and item permissions.

Must-know

  • OneLake security is configured through 'data access roles' defined on a Lakehouse item, letting you grant access to specific folders (under Files or Tables) or specific tables instead of the entire item.
  • Row-level and column-level security can be added to a data access role for Delta tables by specifying filter predicates for rows and choosing which columns to include or exclude.
  • Access enforced by OneLake data access roles applies uniformly across engines that read through OneLake, such as the SQL analytics endpoint and Power BI/Direct Lake, without needing separate per-engine configuration.
  • If a user belongs to multiple OneLake data access roles, their effective access is the union of all permissions granted by those roles (most permissive combination wins).
  • OneLake security governs data-level access only; a user still needs sufficient workspace role or item permission to open/use the Lakehouse itself before OneLake role permissions take effect.
  • Lakehouse items ship with a default 'Read all' data access role granting full read access to users who already have item read permission, and admins can create narrower custom roles to restrict this default behavior.
Check this objectiveFree · always available

A lakehouse contains three top-level folders: Finance, HR, and Sales, each holding files and tables for its department. The data engineering team wants the HR security group to read only the contents of the HR folder through OneLake, while members of that group should not see the Finance or Sales folders at all, and they should not receive workspace-level Viewer access. What should the data engineer configure?

Your objective map0 tried · 0 right · 54 untouched

What you have tried across DP-700's objectives, not a readiness score.

Coverage checked against the published exam guide on Aug 11, 2026.

These are independent practice questions, written against this certification's published exam guide. They are not the certification vendor's own questions, and not the real exam.