Microsoft Certified: Fabric Analytics Engineer AssociateImplement and manage semantic models (30-35%)Easy

A data architect is designing a semantic model in Microsoft Fabric. The model will contain highly sensitive financial data, and there is a strict requirement to prevent unauthorized users from even seeing the names of certain critical columns, such as 'EmployeeSalary' or 'CustomerCreditCardNumber'. Row-level security (RLS) is already implemented for data rows. Which security feature should be used to hide these specific columns from unauthorized users?

  1. AData Masking
  2. BDynamic RLS
  3. CColumn-level permissions in the underlying data source
  4. DObject-Level Security (OLS)
Show answer & explanation

Correct answer: D. Object-Level Security (OLS)

Object-Level Security (OLS) allows you to secure specific tables or columns from being accessed by certain users or roles, effectively hiding their existence from reports and queries, which directly addresses the requirement to prevent users from even seeing column names.

Why the other options are wrong

  • A. Data masking obfuscates data values but still allows users to see the column name; it does not hide the column itself.
  • B. Dynamic RLS filters rows based on user identity but does not hide columns.
  • C. While important, securing the underlying data source doesn't directly control visibility within the semantic model itself after data is loaded.

Object-Level Security (OLS)

A security feature in Tabular models (including Fabric semantic models) that restricts access to sensitive table or column objects for specific users or roles.

  • Hides the existence of tables or columns from unauthorized users.
  • Prevents users from seeing column names or querying them.
  • Implemented using external tools like Tabular Editor.

Memory trick: OLS hides the column; RLS hides the row.

More Implement and manage semantic models (30-35%) questions