Microsoft Fabric · Security status guide
Fabric security in 2026: separate controls from roadmap
Separate current Fabric permissions, OneLake security, Purview controls, preview limits, and unverified roadmap claims before deployment.
Microsoft Fabric security is a set of overlapping control planes, not one switch. In August 2026, teams can use workspace roles, item permissions, OneLake security roles, engine-specific controls, and Microsoft Purview integrations.
The original version of this article mixed available features with expected roadmap items. This update separates what Microsoft documents now from preview and unverified claims.
Evidence rule
Product status can change after publication. Check the linked Microsoft pages, region, workload, engine, mode, and licensing before using a feature in a security design.
Available now: layered Fabric permissions
Fabric first checks whether an identity can access the service, then the workspace and item. Data access may also depend on OneLake, SQL, semantic-model, or workload controls.
The Fabric permission model explains workspace roles and item permissions. A user can receive access through more than one path, so review effective access rather than one assignment in isolation.
OneLake security roles
OneLake security roles can grant access to tables, folders, rows, and columns within supported Fabric items. The current OneLake security overview documents this data-plane model.
Important boundaries include:
- the user still needs Fabric access to the item
- workspace Admins, Members, and Contributors are not constrained by OneLake security roles
- a default reader role can grant data access unless it is changed or removed
- shortcuts and unsupported target items have their own evaluation rules
- effective access can reflect multiple grant paths
Test with the actual identity and tool used in production.
Microsoft Purview integrations
Microsoft documents current Fabric integrations with Purview Unified Catalog, Information Protection, data-loss prevention, Audit, Insider Risk Management, and governance for supported Copilot and agent interactions.
The Purview and Fabric guide lists each integration. Licensing, item coverage, export behaviour, and policy scope differ, so verify the feature needed by the workload.
These tools can support a compliance program. They do not certify that a deployed workload meets a law or control framework.
Engine support: generally available and preview differ
Microsoft’s secured-data engine matrix lists several generally available paths. They include Graph, Lakehouse, Spark notebooks, Direct Lake semantic models in OneLake mode, and SQL analytics endpoints in user-identity mode.
The same matrix lists Eventhouse row filtering and authorized third-party engines as preview. Eventhouse does not have column filtering in that entry. SQL and semantic-model paths require the documented mode.
Do not translate “OneLake security is available” into “every engine enforces every rule.” Use the current matrix as a release gate and include a negative access test for each engine.
Announced direction is not a control
Microsoft states that Purview and Fabric will continue to integrate more closely. It does not make every future integration a supported design dependency.
Keep announced items in a separate roadmap record with the official source, publication date, expected status, owner, and fallback. Promote an item into the production architecture only after Microsoft documents its availability and constraints.
Claims not verified in current primary documentation
This update does not retain several claims from the original article because no current Microsoft source was identified for them:
- compliance packs that automatically configure all Fabric policies
- universal row, column, masking, and folder enforcement across every engine
- a Copilot prompt that generates an audit-ready compliance report
- automatic detection and repair of all OneLake access problems
- a single governance view that replaces workload-specific security review
Treat these as unverified, not as promised roadmap features.
A practical security review
- Inventory users, groups, service principals, and connection owners.
- Draw every route to the data, including exports and shortcuts.
- Record workspace, item, OneLake, SQL, semantic-model, and Purview controls.
- Test allowed and denied access through each production engine.
- Review privileged workspace roles and default reader access.
- Confirm logging, alert, retention, and incident ownership.
- Recheck preview and engine status before each release.
Fabric provides useful security controls in 2026. A defensible design comes from joining those controls around a real access path and keeping roadmap assumptions outside the enforcement model.
Reviewing a Fabric security design?
Trace each identity through its real access path, engine, and governance controls.