
Explanation:

You need to configure OneLake security for two users with the following requirements:
User1: Read all the Spark data
User2: Read all the SQL endpoint data
The available permissions are: Read, ReadAll, and ReadData.
Understanding the permissions:
Read # Grants access to metadata but not the data itself.
ReadData # Grants access to query data through SQL endpoints (SQL-based access).
ReadAll # Grants access to read data across all engines (including Spark and SQL endpoints).
Applying least privilege principle:
User1 (Spark access): Needs to read all the Spark data # Assign ReadAll because Spark requires this permission to access data in OneLake.
User2 (SQL endpoint access): Needs to read SQL endpoint data only # Assign ReadData, as this grants access to SQL endpoints without over-provisioning Spark access.
Final Answer:
User1: ReadAll
User2: ReadData
References:
Microsoft Fabric OneLake permissions
Fabric Lakehouse & SQL Endpoint security