Accepted answer
Pick one model as primary for day-to-day access management, most teams standardize on RBAC plus Azure AD groups, and use ACLs sparingly for exceptions. Otherwise the combinatorics get unmanageable fast.
Some engineers can read a folder in ADLS Gen2, others with what looks like the same role assignment get 403s. We're mixing RBAC roles and POSIX-style ACLs on the same storage account and it's confusing to reason about.
Accepted answer
Pick one model as primary for day-to-day access management, most teams standardize on RBAC plus Azure AD groups, and use ACLs sparingly for exceptions. Otherwise the combinatorics get unmanageable fast.
Consider DuckDB or Polars for this size before spinning up a cluster.
RBAC and ACLs are evaluated together. RBAC grants access at the storage account or container level, ACLs at the folder or file level, and the more restrictive combination effectively wins for that path. A role assignment alone doesn't override a missing ACL entry on a specific folder.
Found it, a folder had stale ACL entries from before we moved to AD groups. Cleaning those up fixed the inconsistency.
Sign in to reply.
© 2026 Lakebench, operated by Hunnurji Rao. Bengaluru, Karnataka, India.
No cluster. No install. Just the tab.