Nod Publishers secures dbo.Royalties in a warehouse with a T-SQL security policy that filters rows by author. A data scientist who reads the same table through a OneLake shortcut in her own lakehouse, from a Spark notebook, sees every author's rows. What explains this behavior?
- A.
Spark reads the shortcut through the lakehouse's SQL analytics endpoint, which runs in delegated identity mode by default.
- B.
Security defined with T-SQL in a warehouse is enforced only in the warehouse's SQL engine and is not translated into OneLake security for the shortcut path.
- C.
OneLake-to-OneLake shortcuts always use delegated authentication, so she reads the data as the person who created the shortcut.
- D.
The security policy was created with schema binding, which skips predicate enforcement for reads that come from other items.
Show answer
Answer: B
Warehouse RLS, CLS and object permissions are enforced only in the warehouse's TDS execution context and are not converted into OneLake security, so shortcut and Spark reads bypass them.
- A. Spark reads OneLake directly and does not go through the SQL analytics endpoint.
- B. Warehouse T-SQL security applies only in its SQL engine and is not carried into OneLake security for shortcuts.
- C. Same-tenant OneLake shortcuts default to passthrough; either mode still bypasses warehouse T-SQL security.
- D. Schema binding governs changes to dependent objects, not which access paths enforce the predicate.
