I am running into an issue where Extensible Data Security (XDS) policies seem to fail or get bypassed when data is queried via OData endpoints.
Can anyone explain the architectural reason why XDS isn't enforcing here? More importantly, what is the best practice to apply row-level security to Data Entities to completely secure them against unauthorized "Open in Excel" or OData exports?

Report
All responses (
Answers (