Clouds Connected · Case study
Design studyFinancial services

Nineteen numbered access controls, each pinned by a test, governing what a bank’s Cloudera data lake may put in front of Copilot.

Access-control design for a US commercial bank indexing a Cloudera data lake into Microsoft Graph, setting out in 19 numbered controls what Apache Ranger can express, what a static permission cannot, and the 5 constructs the connector refuses to guess at.

Client
A US commercial bank
Sector
Financial services
Engagement
Access-control design for indexing a Cloudera data lake into Microsoft Graph
Period
2026, not yet run against a production cluster
Never run against production

This connector has never crawled a production cluster, and by design it currently refuses to crawl the customer’s QA cluster, where a policy carries a construct it will not guess at. The evidence on this page is structural: controls, implementations and the tests that pin them. There is no throughput figure and no production history. Drawn entirely from the connector’s public control mapping.

In brief

Apache Ranger access control: what this engagement covered

The challenge

A US commercial bank wanted Microsoft 365 Copilot to answer over a Cloudera data lake. Apache Ranger decides who may see what in that lake, and it is expressive in ways a search index is not: it filters rows per user, masks columns per user, denies a resource outright, scopes policies to a security zone, and switches policies on and off by the clock.

A connector writing into a search index has one instrument: a static list of principals, attached to an item, at the moment it is written. No clock, no row filter, and in the push API no way to express a deny.

The question was never how to translate Ranger into a search index. It was which parts cannot be translated, and what the connector must do when it meets one. Get that wrong and the failure is silent: the crawl succeeds, the index looks complete, and somewhere in it sits a document one person was never entitled to see.

The solution

Nineteen numbered controls, each with the code that implements it and the test that pins it. Not a policy document but a mapping an auditor can check line by line, where every claim points at a named test that fails if the behaviour changes.

Some things are never indexed. A table whose rows Ranger filters or whose columns it masks stays out, because an index holds one copy: it would either leak the unfiltered rows to everyone granted the item, or store the masked version and lie to those entitled to the real one.

A deny is obeyed by refusing, never by mirroring. A mirrored deny protects only while the translation is right every time, and a drifted translation fails open. The permission type used here cannot express a deny at all, so the property is structural rather than conventional.

One trap only showed up under scrutiny. Ranger folds case on every resource, which is right for Hive names and wrong for paths: HDFS is case-sensitive, so /data/Finance and /data/finance are two directories, holding different files under different permissions, that folding would treat as one.

Anything depending on the clock stops the run, because a Graph permission has nowhere to put a clock. Guards fire on over-granting only and under-granting is logged, since a guard that fires on the safe direction teaches operators to disable guards.

The results

19 numbered controlseach mapped to its implementation and a test that pins it
4 withdrawn controlsstruck through in place, keeping the reasoning in the record
5 constructs refusedrow filters, column masks, security zones, clock conditions, tag denials
0 settingsthat disable the refusals under schedule pressure
DimensionBeforeAfter
A masked or row-filtered tableIndexed, one copy for everyoneNever indexed
A Ranger denyMirrored, correct while the translation holdsRefused; the type cannot express a deny
A truncated policy listIndistinguishable from a complete onePaged to the end, or the run stops
A clock-dependent policyRead as absent, silently over-grantingStops the run
A withdrawn controlDeletedStruck through, with what survives spelled out

The outcome worth stating is not a throughput figure. The connector currently refuses to crawl the bank’s QA cluster. A tag-service policy there carries a condition, so two controls fire and the run stops. That is the design working, with the blocker in code rather than in a document: a document is read once, a refusal every time.

This has never run against a production cluster. The evidence is structural: controls, implementations and tests. There is no crawl duration, no throughput and no production history.

Technologies

Questions we get asked

Apache Ranger access control: common questions

Can Microsoft 365 Copilot index a Hive table that Apache Ranger row-filters or column-masks?
No, and the mismatch is unresolvable rather than a tuning problem. Apache Ranger shows different rows to different people at query time, while a search index holds one copy. Indexing such a table either leaks the unfiltered rows to everyone granted the item, or stores the masked version and lies to the people entitled to the real one. The correct behaviour is to route that table to a live query and index nothing.
How do you stop a Cloudera CDP crawl from over-granting access in Microsoft Graph?
By refusing rather than approximating. Five Ranger constructs stop the run outright: row filters, column masks, security zones, clock-dependent conditions and tag-service denials. A Ranger deny is obeyed by not indexing the resource at all, because a mirrored deny protects only while the translation is right every time and a translation that drifts fails open. In this design the permission type used cannot express a deny, which makes the property structural rather than a convention someone can breach.
What happens to time-based Apache Ranger policies when data is indexed for Copilot?
They stop the crawl. Ranger policies can carry conditions and validity schedules, while a Microsoft Graph permission is a static snapshot written at crawl time with nowhere to put a clock. Evaluating one would produce an access list that is correct at the instant it is written and silently wrong afterwards, turning a loud refusal into a quiet divergence. Static constructs such as allow exceptions are evaluated instead, because they can only ever remove groups.
How stale can an indexed permission become after a Ranger policy change?
Bound it and publish the bound. A permission change does not alter a file’s modification time, so an incremental crawl never revisits the file and its indexed access list would stay stale indefinitely. A periodic full recrawl that ignores the watermark and re-derives every grant is the only thing that closes the gap, which makes the recrawl interval the documented upper bound on access-list staleness and something that belongs in the deployment’s risk register.
Related work

Other engagements like this one

Work with us

Two ways this usually starts

For consulting partners

SharePoint delivery under your paper

Nine of the ten engagements in this library were contracted through a systems integrator, an ISV or a managed provider, with Clouds Connected as the named SharePoint delivery lead. Your client relationship, your invoice, our platform depth — white-label delivery, escalation cover, or a fixed-scope block of hours.

Every study here is anonymised by default, which is also how we work inside your accounts.

For direct clients

Upgrades, migrations, recovery, patching

SharePoint Server and Microsoft 365 platform work on estates that cannot simply be rebuilt: version upgrades, tenant and content migrations, disaster recovery design and drills, performance root-cause diagnosis, and scheduled security patching on a standing cycle.

Regulated utilities, financial services, aerospace and healthcare. Based in the Greater Toronto Area, Canada; delivery across North America.

Provenance

Where these facts come from

Reconstructed from project correspondence, September 2021 to September 2026. Every figure on this page traces to a dated message, and the source citation for each sits in the accompanying fact sheet. Nothing has been estimated, rounded up, or written on the client’s behalf.

Clouds ConnectedFinancial services · access control for indexing a data lake