Platform guide

OneLake shortcuts and external data sharing in Microsoft Fabric

Shortcuts point to data without copying it, and external sharing opens it to another tenant. Here is what each does and what to settle in a data licence before you use them.

Updated 5 October 20267 min read

A OneLake shortcut makes data stored in one place appear in another without copying it, and external data sharing extends that reach to another organisation's Fabric tenant. Both avoid making copies, and both widen who can read the data. This guide sets out what each does according to Microsoft's documentation, what that means when the data is licensed, and a layout that keeps one governed copy of licensed company data.

Fokals is delivered direct, by REST API and bulk files in JSON, JSON Lines or CSV, which you load into storage you control with Fabric's own loaders, and a shortcut then points at that storage. Bringing external company data into OneLake covers that step. From then on the data is held under your data licence, and this guide is about keeping to its terms.

What a shortcut does

Microsoft's page on shortcuts describes a shortcut as an object in OneLake that points to another storage location, inside or outside OneLake. It appears as a folder and behaves like a symbolic link, independent of its target: deleting the shortcut leaves the target untouched, while moving, renaming or deleting the target path can break the shortcut. You create shortcuts in lakehouses and KQL databases. In a lakehouse, shortcuts in the Tables area sit at the top level and are meant for Delta data, and shortcuts in the Files area can sit at any level and point at data in any format.

Targets inside Fabric include lakehouses, warehouses, mirrored databases and SQL databases. External targets include Azure Data Lake Storage Gen2, Azure Blob Storage, Amazon S3 and S3-compatible storage, Google Cloud Storage, Dataverse, Iceberg tables, and OneDrive and SharePoint. The data stays where it is, so a change at the source shows through the shortcut at once.

Who can read through a shortcut

Authorisation depends on the type of shortcut, according to Microsoft's security page. A shortcut between two OneLake locations in one tenant uses passthrough by default: the caller's own identity is checked at the target, and where the shortcut path and the target path differ in permission, the more restrictive one applies. A shortcut can instead be delegated, which uses a fixed identity such as a service principal, and the reader then sees the intersection of their own access and that identity's. Shortcuts to external storage, such as Amazon S3 or Google Cloud Storage, are always delegated, so people can read the data without access to the external system.

OneLake security roles can limit what a reader sees down to tables, folders, rows and columns, but they apply to the Viewer role and to users with Read permission only. Workspace Admins, Members and Contributors already have read and write access to the data in a workspace, so the workspace role is the first control to set.

Caching matters for external shortcuts. For shortcuts to S3, S3-compatible storage, Google Cloud Storage and on-premises gateway sources, OneLake can store the files it reads in a cache in the consuming workspace to reduce egress cost, once the workspace setting is on. The retention period runs from 1 to 28 days, files over 1 GB are not cached, and the same setting page has a button to reset the cache.

What external data sharing does

External data sharing is a separate feature that shares OneLake data with users in another Fabric tenant. The data is shared in place: nothing is copied, and the recipient's tenant receives a read-only shortcut that points back to the provider's data, so changes show at once. A Fabric administrator turns it on in both tenants through its own tenant settings, which name who may create shares and who may accept them. A user with Read and Reshare permission on an item shares tables or files from a lakehouse, warehouse, KQL database, SQL database or mirrored database. The recipient accepts through a link within 90 days and chooses a lakehouse to hold the shortcut.

Microsoft's page lists what changes when data crosses the tenant boundary. The share gives read-only access to any user in the home tenant of the person invited. The sharer cannot control who has access in the consumer's tenant, and the consumer can grant access to anyone, including guests from outside the consumer's organisation. Data may cross geographic boundaries when it is read, and governance controls from the provider tenant, such as sensitivity label behaviour, are not enforced in the consumer tenant. Anyone with Read and Reshare permission on the item can revoke a share at any time, and Microsoft's warning is that a revoked share cannot be restored and everything the recipient built on it stops working.

What this means for a licence

A data licence answers three questions: who may read the data, where it may live and what happens when the licence ends. Fokals licenses by written agreement, for internal use, embedding in a product or redistribution, and shortcuts and sharing touch each of the three questions.

MechanismWhere the data sitsWho can read itSettle in the agreementWhen the licence ends
Shortcut inside your tenantOne copy, in the workspace that owns itPeople with access to both the shortcut path and the targetWhich teams fall inside the licensed useDelete the target, and shortcuts to it can break
Shortcut to files in S3 or Google Cloud StorageIn your bucket, with an optional cache in the workspaceWhoever the delegated identity and OneLake security allowWhether a cached copy is within the licenceDelete the files, then reset the cache
External data shareIn place, in your tenantAny user in the recipient's tenant, and anyone they chooseWhether the agreement allows disclosure to that organisationRevoke the share, which cannot be undone

Internal use, by its plain meaning, stays inside your own organisation, while a share to another tenant reaches people outside it. Whether that share is covered, and under which of the three forms, is a question for the written agreement, and it needs an answer before the share exists, because the recipient's administrators decide who reads the data from then on. The same care applies to copies elsewhere: a shortcut avoids a copy, but a table you build from it, an export or a model in another tool is a copy, and each is data you must be able to find.

A layout that keeps one governed copy

Five choices keep licensed company data in one place.

  1. Land the files and build the tables in one workspace used only for licensed data. Keep the export's manifest beside the files: it names the sources, period, label versions and licence, so the licence travels with the data wherever a shortcut leads.
  2. Give each consuming team its own workspace and let it reach the curated tables by shortcut instead of by copy, so there is one copy to govern and one to delete.
  3. Set OneLake security roles on the owning lakehouse for Viewers, and keep the Admin, Member and Contributor roles to the few people who run the data.
  4. Turn on OneLake diagnostics for the licensed workspace. Microsoft's page says it logs data access as JSON events in a lakehouse you choose, including access through shortcuts, with the user, the time and whether the access came through a shortcut. That gives you a record of who read licensed data and when.
  5. Create no external data shares from the licensed workspace unless the agreement covers the recipient, and then share only the tables that recipient needs.

Ending a licence

Deleting data in OneLake is not instant removal. Microsoft's page on data protection says OneLake retains deleted files for seven days before permanent removal. Delta tables keep a history of changes, and Microsoft's medallion guide says history from the last seven days cannot be vacuumed by default. A table shortcut with a file transformation removes the rows of files you delete. If your agreement asks you to delete data when it ends, the steps are these: delete the files and tables at the source, run VACUUM on the Delta tables, reset the cache on external shortcuts, revoke external shares and tell the recipient, and keep the diagnostics log as your record.

Where this stops

Shortcuts and sharing move no data and add none: they decide who can reach what you have loaded. A shortcut in the Tables area of a lakehouse expects a table format such as Delta, so CSV or JSON Lines files stay in the Files area, where Spark can read them through a shortcut, until a file transformation or a load turns them into tables. A table you build by joining Fokals company data to your own records is where the licence and your own data obligations meet, and you should decide which terms govern it before it is shared. The data licensing page and what a data licence covers are the places to start, and redistributing company data under licence treats the third form in detail.

Frequently asked questions

What is a OneLake shortcut?

A shortcut is an object in OneLake that points to data in another location, inside or outside OneLake, and appears as a folder. It copies nothing: reads go to the target, so changes at the source show through. Deleting a shortcut leaves the target alone, while moving or deleting the target can break the shortcut.

Does Fabric external data sharing copy the data?

No. The data is shared in place, and the recipient's tenant receives a read-only shortcut that points back to the provider's OneLake data. Changes at the source show at once. The provider can revoke the share at any time, but a revoked share cannot be restored and stops everything the recipient built on it.

Can I share Fokals data with another company through Fabric?

Only if your agreement allows it. Fokals licenses by written agreement for internal use, embedding in a product or redistribution, and a share to another tenant reaches people outside your organisation, whom the recipient's administrators then control. Settle the recipient, the tables and the end of the share in writing before you create it.

Who can read data through a OneLake shortcut?

Within a tenant, the caller's own permissions at the target are checked by default, and the more restrictive of the shortcut path and the target path applies. Shortcuts to external storage are always delegated. OneLake security roles can limit Viewers to tables, folders, rows and columns, but workspace Admins, Members and Contributors are not restricted by them.

How does Fokals data reach OneLake?

Fokals is delivered direct, by REST API and as bulk files in JSON, JSON Lines or CSV, with a manifest naming the period, label versions and licence. You load the files into storage you control with Fabric's own loaders, and a first load comes from a bulk export while the API keeps it current. From then on you can reach the data with shortcuts inside your own tenant.

What happens to cached files when a licence ends?

For shortcuts to S3, S3-compatible storage, Google Cloud Storage and on-premises gateway sources, OneLake can cache files in the workspace for 1 to 28 days when the setting is on. After you delete the source files, reset the cache in the workspace's OneLake settings so that no cached copy remains.

What this page says about the products it names was checked against their public documentation on 4 October 2026. Product and company names are trademarks of their owners. Fokals is not affiliated with them or endorsed by them.