Microsoft Certified: Power BI Data Analyst AssociateDeploy and maintain assetsHard

A Power BI data analyst is developing a report that uses a dataset with a live connection to an Azure Analysis Services model. The analyst needs to apply row-level security (RLS) based on the user's Azure Active Directory (AAD) group membership. Where should the RLS roles be defined?

  1. AIn Power BI Desktop, using the 'Manage roles' feature.
  2. BIn the Power BI service, within the dataset settings.
  3. CUsing a DAX expression within the Power BI report visuals.
  4. DDirectly in the Azure Analysis Services model.
Show answer & explanation

Correct answer: D. Directly in the Azure Analysis Services model.

When using a live connection to Azure Analysis Services, RLS is defined and managed directly within the AAS model itself. Power BI Desktop and Service inherit these roles and enforce them, but they are not created there.

Why the other options are wrong

  • A. The 'Manage roles' feature in Power BI Desktop is for RLS defined on imported or DirectQuery datasets, not live connections to AAS.
  • B. The Power BI service dataset settings allow mapping users to AAS roles but not defining the roles themselves.
  • C. DAX expressions in report visuals can filter data, but RLS is a security feature applied at the dataset level, not visual level, and is managed differently for AAS.

RLS with Live Connection to AAS

When a Power BI dataset has a live connection to an Azure Analysis Services (AAS) model, row-level security (RLS) roles are defined and managed within the AAS model.

  • RLS defined in AAS model
  • Power BI inherits AAS roles
  • Users mapped to AAS roles in Power BI service

Memory trick: The data source holds the keys to its own security rules.

More Deploy and maintain assets questions