Concept and mechanism
Protecting a data product requires knowing who performs each operation. A person opening a resource in the portal does not establish that the pipeline’s managed identity can read a file or secret. In Data Lake, RBAC, conditions, and ACLs participate in the decision. A sufficient container data role can grant access without depending on a folder ACL; removing an ACL entry does not restrict that grant. When authorization relies only on ACLs, reading a file requires traversal through ancestor folders. Execute on a folder means traversing that path level; it does not mean running a program stored in the lake.
Guided application
Default ACLs define a template for new objects. Changing that template does not retroactively update existing files; migration needs scope, inventory, and verification. Networking is another boundary: ADLS Gen2 can need both Blob and DFS private endpoints, with correct resolution from the runtime. Creating Private Link does not automatically block the public endpoint. For Key Vault credential references, grant the execution principal the necessary data access and test secret retrieval without exposing values in logs. At handover, include allowed and denied tests using the same identity. Record the grant owner, reason, review, and procedure for removing access when an application is decommissioned.
An analyst still reads fund-B after restrictive ACL changes. Find container Data Reader and review that grant before repeating segregation tests.
Common pitfalls
ACL treated as absolute deny; default ACL treated as retroactive update; vault management treated as secret reading.
Related topics: Storage, distribution, and exploration · Incremental loads and recovery · Streams, time, and external effects
Establish minimum access using the principal and path actually used in operations.
Reference: Data Lake RBAC ABAC and ACL evaluation · DP-203 objectives 2024-10-24; retired 2025-03-31