Control Data Protection Microsoft Entra ID authentication Least privilege MFA and Conditional Access Role-based access control Row-Level Security (RLS) Managed identities and service principals* Group-based security Separation of duties Column/object-level restrictions Sensitive data protection These carry straight over. The skills you already have still apply.
Network Security Encryption in transit (TLS) Data classification Private connectivity Sensitivity labels Controlled data access paths Encryption at rest Secure service-toservice communication Microsoft Purview integration Compliance and regulatory support Reduced public exposure These carry straight over. The skills you already have still apply.
No Fabric Data Warehouse No Fabric Lakehouse (SQL Endpoint) No Fabric Data Lake (OneLake) No Azure SQL Database Yes Mirrored Azure SQL DB No SQL Server (on-prem) Yes
– XXX Numbers – 000000 Date & Times - 01.01.2000 00:00:00.0000000 Binary – Single Byte 0 XXXX 0 01.01.2000 00:00:00.0000000 0 Email First character of email, then Xs, then .com Always .com [email protected] Custom First and last values, with Xs in the middle kxxxn Random For numeric types, with a range 12 Datetime For datatime datatypes, plus date 6/27/1900
be configured on computed column But if computed column depends on a mask, then mask is returned Using SELECT INTO or INSERT INTO results in masked data being inserted into target (also for import/export)
Database Yes Fabric Data Warehouse Yes Fabric Lakehouse (SQL Endpoint) No Fabric Data Lake (OneLake) No) Azure SQL Database Mirrored Azure SQL DB SQL Server (on-prem) Yes Yes, but applied after mirroring Yes
CREATE SECURITY POLICY Filter hides rows, block fails writes Entra is the identity Mind the OneLake path No SQL logins Policies stop at the SQL engine Workspace roles gate the item Use OneLake RLS roles there No admin exemption Isolate policies in a schema Same predicates you already use but different identity model
the gap yourself Use firewalls Entra identity, workspace roles Audit logs Monitor identities & access Sensitivity labels DLP Tenant admin settings Nothing in Defender for Cloud Script your own config checks Review permissions on a cadence The scanner does not come with you, but here’s what you can do
Same skills, same instincts SQL Database Fabric SQL Database Fabric Warehouse Fabric SQL Endpoint Identity, access, encryption, auditing Many of the controls you already apply to SQL databases still work with Fabric.
No No No No Yes No Yes Row-Level Security (RLS) Yes Yes Yes Yes Yes Yes Yes Dynamic Data Masking (DDM) Yes Yes No No Yes Yes Yes Ledger Tables No No No No Yes No Yes Feature Fabric Lakehouse (SQL Endpoint) Fabric Data Lake (OneLake) Azure SQL Database Mirrored Azure SQL DB SQL Server (on-prem)
don’t understand Security nearest the data DB performance Data pros know data Can’t trust everyone anyone Developer productivity Managing Risk Importance of Laziness