15 min read
OneLake Shortcuts Are an Authorization Boundary, Not a Storage Convenience — A Security Model for Microsoft Fabric
A shortcut splices two independently governed permission domains together. Treating it as an access-control and identity problem: two-layer permissions, pass-through vs delegated auth, the Direct Lake / SQL identity-passthrough exception, and where enforcement silently changes hands.