A unified data governance solution that helps manage, protect, and discover data across your organization
Hey Sania Syeda,
what you are seeing is generally expected behavior because Microsoft Purview sensitivity labels, DLP policies, and Microsoft Fabric permissions operate through different enforcement layers.
Applying a restrictive sensitivity label to a lakehouse or eventhouse does not automatically override existing Fabric workspace roles or OneLake permissions. Users who already have effective access through Contributor, Viewer, or item-level permissions may still be able to browse or query the data unless additional protection policies are enforced.
Whether access is restricted depends on several factors, including whether the Fabric item matches the DLP policy conditions, whether the sensitivity label is associated with an active protection policy, whether policy evaluation and propagation have completed, and whether the user falls under an allowed or exempted scenario. Because of this, enforcement may not appear immediately after configuration changes.
Fabric agents and connected experiences operate using the requesting user’s identity and effective permissions. If the user still has access through workspace roles, OneLake permissions, or item-level authorization, the agent can also access the data.
I would recommend confirming that the lakehouse is properly onboarded and governed through Microsoft Purview, verifying that the sensitivity label is correctly published and applied, reviewing the DLP rule scope and conditions, and checking the item’s effective permissions in Fabric. In many cases, restricting OneLake permissions and workspace access is the most immediate way to prevent contributors or agents from accessing a lakehouse.
References:
• Policy enforcement in Microsoft Purview (prereqs & enforcement times) https://docs.microsoft.com/azure/purview/microsoft-purview-connector-overview#access-policy • Classification & sensitivity labels – missing or incorrectly labeled assets https://docs.microsoft.com/azure/purview/concept-best-practices-classification#classification-considerations • Use Microsoft Purview to govern Microsoft Fabric (DLP overview) https://learn.microsoft.com/fabric/governance/microsoft-purview-fabric?wt.mc_id=knowledgesearch_inproduct_azure-cxp-community-insider#microsoft-purview-and-microsoft-fabric-together • Connect Sales Research Agent to Microsoft Fabric Lakehouse (agent security model) https://learn.microsoft.com/dynamics365/sales/sales-research-agent-lakehouse-integration • OneLake security for SQL analytics endpoints (access modes) https://learn.microsoft.com/fabric/onelake/security/sql-analytics-endpoint-onelake-security?wt.mc_id=knowledgesearch_inproduct_azure-cxp-community-insider