You are designing a data processing solution in Azure Databricks that uses Unity Catalog. The security team requires that all users authenticate using Microsoft Entra ID and that access to tables is governed by attribute-based access control (ABAC) using table tags. Which feature should you enable?
Trap 1: Column-level security masks.
Column-level security masks are used to mask sensitive data at the column level, not for ABAC with tags.
Trap 2: Dynamic views with user context functions.
Dynamic views with user context functions enable ABAC by filtering data based on the user's attributes, such as group membership or identity, which can be mapped to table tags.
Trap 3: Row-level security filters.
Row-level security filters restrict rows based on conditions, but they do not directly provide ABAC using table tags in Unity Catalog.
- A
Column-level security masks.
Why it fails: Column-level security masks are used to mask sensitive data at the column level, not for ABAC with tags.
- B
Dynamic views with user context functions.
Why it fails: Dynamic views with user context functions enable ABAC by filtering data based on the user's attributes, such as group membership or identity, which can be mapped to table tags.
- C
Row-level security filters.
Why it fails: Row-level security filters restrict rows based on conditions, but they do not directly provide ABAC using table tags in Unity Catalog.
- D
Table tags with access control lists (ACLs) in Unity Catalog.
Table tags with ACLs in Unity Catalog provide role-based access control (RBAC), not attribute-based access control (ABAC). ABAC requires dynamic views with user context functions.