Skip to content

Commit 70a09c7

Browse files
authored
overview simple since more to come
1 parent 9dfa209 commit 70a09c7

File tree

1 file changed

+2
-60
lines changed

1 file changed

+2
-60
lines changed

Security/README.md

Lines changed: 2 additions & 60 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# Security \& Governance
1+
# Security \& Governance Overview
22

33
Costa Rica
44

@@ -10,65 +10,7 @@ Last updated: 2025-05-08
1010
------------------------------------------
1111

1212

13-
## Lakehouse Permissions
14-
15-
> `Lakehouse `is a `specific type of data architecture within Microsoft Fabric `that combines the features of data lakes and data warehouses. `It allows for the storage and processing of both structured and unstructured data`, providing the flexibility of a data lake with the performance and management features of a data warehouse. <br/> <br/>
16-
17-
<div align="center">
18-
<img width="700" alt="image" src="https://github.com/user-attachments/assets/fd102034-660b-4f93-8aa1-ccda4e4d1893" style="border: 2px solid #4CAF50; border-radius: 5px; padding: 5px;"/>
19-
</div>
20-
21-
| **Permission** | **Definition** | **Use Cases** |
22-
|-----------------------------------------------|---------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
23-
| Read all SQL endpoint data | This permission allows access to SQL-based data endpoints in Microsoft Fabric. | - `Power BI`: Connecting to semantic models or datasets using DirectQuery or Import mode.<br/>- `Data Factory Pipelines`: Reading from or writing to SQL endpoints as part of ETL/ELT processes.<br/>- `OneLake / Gen2 Data Lake`: SQL endpoints can expose structured views over data stored in the lake.<br/>- `Data Activator / Agents`: Agents may use SQL endpoints to monitor or trigger actions based on data changes.<br/>- `Excel / Office Integration`: Connecting Excel to SQL endpoints for live data refresh and pivot analysis.<br/>- `Third-party BI Tools`: Using Tableau, Qlik, etc., to connect to SQL endpoints.<br/>- `Custom Applications`: Internal apps querying SQL endpoints for real-time dashboards. |
24-
| Read all Apache Spark and subscribe to events | This permission relates to Apache Spark workloads, which are more code- and compute-intensive. | - `Notebooks`: Running PySpark, Scala, or SparkSQL code for data exploration and transformation.<br/>- `Machine Learning`: Training models using Spark MLlib or integrating with Azure ML.<br/>- `Data Science Workloads`: Performing large-scale data analysis or feature engineering.<br/>- `Copilot & Agents`: If they need to interact with Spark jobs or listen to Spark events (e.g., job completion).<br/>- `Streaming Analytics`: Real-time data processing using Spark Structured Streaming.<br/>- `Data Engineering Pipelines`: Complex transformations and joins across large datasets.<br/>- `Event-Driven Automation`: Triggering workflows or alerts based on Spark job events.<br/>- `Integration with Delta Lake`: Managing transactional data lakes with ACID guarantees. |
25-
26-
https://github.com/user-attachments/assets/2974bdee-4b02-4750-ba6c-b745215e0f82
27-
28-
### Read all SQL endpoint data
29-
30-
> Permissions:
31-
> - Read <br/>
32-
> - Read All <br/>
33-
> - Subscribe OneLake Events
34-
35-
36-
> Lakehouse Manage Permissions:
37-
38-
<img width="550" alt="image" src="https://github.com/user-attachments/assets/a2559d8a-35b9-456b-a14c-81c9bb5d2b9c" /> |
39-
40-
<img width="550" alt="image" src="https://github.com/user-attachments/assets/2f0c625d-2cbb-43c0-930a-a2ee29eff60f" />
41-
42-
> When `Read all SQL endpoint data`:
43-
44-
<img width="550" alt="image" src="https://github.com/user-attachments/assets/19a31eaf-79e6-4836-a380-75137823e315" />
45-
46-
> `Read` access is granted, you add more permissions.
47-
48-
<img width="800" alt="image" src="https://github.com/user-attachments/assets/2035ae73-f247-493d-905c-d9a3d76ec5f2" />
49-
50-
51-
### Lakehouse Semantic Model
52-
53-
> Permissions:
54-
> - Reshare <br/>
55-
> - Build <br/>
56-
> - Write
57-
58-
<img width="550" alt="image" src="https://github.com/user-attachments/assets/f767acdc-6491-4576-a99e-337cf6f2b37c" />
59-
60-
<img width="800" alt="image" src="https://github.com/user-attachments/assets/a574988f-f78c-43be-b29c-150f67599386">
61-
62-
### SQL Analytics Endpoint
63-
64-
> Permissions:
65-
> - Read <br/>
66-
> - Read Data <br/>
67-
> - Read All
68-
69-
<img width="550" alt="image" src="https://github.com/user-attachments/assets/969433d1-5ceb-4369-a11f-26a29bb606dd" />
70-
71-
<img width="800" alt="image" src="https://github.com/user-attachments/assets/60241837-759f-44f6-8934-67bb98002ada" />
13+
- [Lakehouse Permissions](./LakehousePermissions.md): Lakehouse, Semantic Model, SQL Endpoint
7214

7315
<div align="center">
7416
<h3 style="color: #4CAF50;">Total Visitors</h3>

0 commit comments

Comments
 (0)