Microsoft Certified: Power BI Data Analyst AssociateDeploy and maintain assetsHard

A data analyst has published a Power BI report to a workspace. The report contains a sensitive column, 'Salary', which should only be visible to users with an 'HR Manager' role. Other users should not even see the 'Salary' column in the field list or visuals. How can this be achieved?

  1. AUse a Power BI App to filter the 'Salary' column based on user roles.
  2. BHide the 'Salary' column in the report view for non-HR Manager roles.
  3. CApply Row-Level Security (RLS) to the 'Salary' column.
  4. DImplement Object-Level Security (OLS) on the 'Salary' column.
Show answer & explanation

Correct answer: D. Implement Object-Level Security (OLS) on the 'Salary' column.

Object-Level Security (OLS) allows you to secure specific tables or columns, making them invisible to unauthorized users. By applying OLS to the 'Salary' column, it will not appear in the field list or any visuals for users without the necessary permissions, directly addressing the requirement.

Why the other options are wrong

  • A. Power BI Apps manage access to entire reports/dashboards, not individual columns within a dataset dynamically based on roles.
  • B. Hiding a column in the report view in Power BI Desktop only affects the initial view; users can still unhide it or access it via 'See records'.
  • C. RLS filters rows of data, but the column itself would still be visible, which is not the requirement.

Object-Level Security (OLS)

A security feature that restricts access to specific tables or columns in a Power BI dataset, making them invisible to unauthorized users.

  • Hides tables/columns completely.
  • Applied at the dataset level.
  • Requires XMLA endpoint for configuration.

Memory trick: OLS hides the object, RLS hides the row.

More Deploy and maintain assets questions