Microsoft Certified: Fabric Analytics Engineer AssociateImplement and manage semantic models (30-35%)Hard
A data engineer is working on a Microsoft Fabric semantic model that includes a dimension table named 'DimCustomer'. This table contains sensitive customer contact information that should only be visible to a limited group of users (e.g., Customer Service). For all other users, this sensitive information (specifically the 'EmailAddress' and 'PhoneNumber' columns) should be completely hidden, but they should still be able to see other customer attributes like 'CustomerName' and 'CustomerSegment'. How should the data engineer implement this security requirement?
- AImplement Object-Level Security (OLS) to hide 'EmailAddress' and 'PhoneNumber' columns for specific roles.
- BUse Dynamic RLS expressions that evaluate to 'FALSE()' for sensitive columns.
- CApply Row-Level Security (RLS) to filter rows in 'DimCustomer' for specific users.
- DCreate a separate 'DimCustomer_Public' table without sensitive columns and implement RLS.
Show answer & explanationAnswer & explanation
Correct answer: A. Implement Object-Level Security (OLS) to hide 'EmailAddress' and 'PhoneNumber' columns for specific roles.
The requirement is to hide specific columns ('EmailAddress', 'PhoneNumber') for certain users, while other columns from the same table ('CustomerName', 'CustomerSegment') remain visible. This is a classic use case for Object-Level Security (OLS), which allows granular control over column visibility based on user roles.
Why the other options are wrong
- B. RLS expressions apply to rows. While you could theoretically create a complex measure that always returns blank for sensitive columns, OLS is the proper and more robust solution for column-level security.
- C. RLS filters rows, not columns. It would not hide specific columns while showing others from the same table.
- D. Creating a separate table is a workaround, but OLS is the dedicated feature for hiding columns within the same table, offering a cleaner and more manageable solution.
Object-Level Security (OLS)
A security feature in Microsoft Fabric semantic models that allows restricting access to specific tables, columns, or measures based on user roles, effectively hiding them from unauthorized users.
- Controls visibility of entire objects (tables, columns, measures).
- Implemented by defining roles in Tabular Editor or XMLA endpoint.
- Different from RLS, which filters rows within a visible object.
Memory trick: Objects hidden, columns unseen, OLS makes it pristine.