Microsoft Certified: Power BI Data Analyst AssociateDeploy and maintain assetsHard

A Power BI administrator needs to prevent a specific group of users from seeing a particular column (e.g., 'Salary') in multiple reports that all connect to the same shared dataset. Implementing RLS for every report is deemed inefficient. What is the most effective and scalable solution?

  1. ACreate a new dataset without the 'Salary' column for those users.
  2. BApply a sensitivity label to the 'Salary' column.
  3. CUse a Power BI App with audience permissions to hide the column.
  4. DImplement Object-Level Security (OLS) on the 'Salary' column.
Show answer & explanation

Correct answer: D. Implement Object-Level Security (OLS) on the 'Salary' column.

Object-Level Security (OLS) allows you to secure specific tables or columns, making them invisible to unauthorized users. This is a scalable solution as it's applied at the dataset level and affects all reports built on that dataset.

Why the other options are wrong

  • A. Creating a new dataset is not scalable and leads to data redundancy and maintenance overhead.
  • B. Sensitivity labels classify data but do not prevent users from seeing the actual column data.
  • C. Power BI Apps manage report access but cannot hide specific columns within a report if the underlying dataset exposes them.

Object-Level Security (OLS)

Object-Level Security in Power BI allows you to secure specific tables or columns in a dataset, making them invisible to unauthorized users, regardless of the report.

  • Applied at the dataset level.
  • Hides entire tables or columns from users.
  • Implemented using Tabular Editor 2 or other external tools.

Memory trick: OLS Obscures, RLS Restricts Rows.

More Deploy and maintain assets questions