Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

OneLake shortcuts and source permissions: where governance breaks


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19415
Topic starter  

TL;DR: OneLake shortcuts can expose Databricks and Snowflake data inside Fabric and Power BI, but source authorization does not automatically follow the shortcut, creating a governance gap Trust3 argues must be bridged through synchronized policy mapping and identity resolution. The core issue is not connectivity but consistent access decisions across platforms.

NHIMG editorial — based on content published by Trust3: How Trust3 AI carries source policy into OneLake

Questions worth separating out

Q: How should teams govern data access when shortcuts span multiple platforms?

A: Treat the source platform as the policy authority and use translation into the destination platform to preserve the same access decision.

Q: Why do shortcut models create governance risk for IAM teams?

A: Because the shortcut can expose governed data through a new path without automatically carrying the original authorization intent.

Q: What breaks when permissions are copied once and never resynchronised?

A: The destination model quickly diverges from the source as users change, groups are reorganized, and policies are updated.

Practitioner guidance

  • Define the source platform as the access authority Keep Databricks, Snowflake, or another governed source system as the system that defines who may access the data, then translate that decision into OneLake rather than recreating policy in Fabric.
  • Map identities and resource objects before enabling shortcuts Validate how users, groups, roles, workspaces, lakehouses, and shortcut identity modes resolve across Entra and the destination environment before you expand OneLake access.
  • Automate synchronization for policy changes Trigger permission updates when source grants are added, changed, or revoked so OneLake does not drift into a separate access model over time.

What's in the full article

Trust3's full article covers the operational detail this post intentionally leaves at the governance layer:

  • How OneLake maps source grants into roles, workspaces, and shortcut identity modes in practice
  • How principal resolution works across Entra identities, tenants, lakehouses, and destination resources
  • How continuous synchronization updates permissions when source policies change
  • How the model applies separately to Databricks and Snowflake use cases

👉 Read Trust3's analysis of OneLake shortcut governance and source permission sync →

OneLake shortcuts and source permissions: where governance breaks?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 19006
 

Policy translation is the real control plane for cross-platform analytics. The article makes a strong case that connectivity alone does not deliver governance. When data moves through OneLake shortcuts, the security decision must move with it, or access becomes dependent on the path rather than the policy. For IAM and IGA teams, this is the same lifecycle problem seen in other federation and entitlement scenarios: preserve intent across systems, or accept drift.

A question worth separating out:

Q: What is the difference between source-of-truth governance and destination-based permissions?

A: Source-of-truth governance means the original platform defines the access decision and every other system inherits it. Destination-based permissions re-create that decision in each consuming platform, which is slower and easier to get wrong. For cross-platform analytics, source-of-truth governance is the safer operating model.

👉 Read our full editorial: OneLake shortcut governance depends on source permissions following access



   
ReplyQuote
Share: