Microsoft Certified: Fabric Analytics Engineer AssociateImplement and manage semantic models (30-35%)Easy
A data engineer is integrating a new data source into an existing semantic model in Microsoft Fabric. The new source contains sensitive customer data that must be accessible only to authorized personnel, even at the column level. The engineer needs to ensure that specific columns, such as 'Customer_SSN' and 'Customer_CreditCard', are completely hidden from unauthorized users, regardless of their role or any row-level security applied. Which security feature should be implemented?
- ADynamic RLS
- BRow-Level Security (RLS)
- CWorkspace Role-Based Access Control (RBAC)
- DObject-Level Security (OLS)
Show answer & explanationAnswer & explanation
Correct answer: D. Object-Level Security (OLS)
Object-Level Security (OLS) provides the ability to secure specific tables or columns within a semantic model, making them completely invisible to unauthorized users. This is the precise mechanism for hiding sensitive columns like 'Customer_SSN' from certain roles.
Why the other options are wrong
- A. Dynamic RLS is a more advanced form of RLS that filters rows based on the user's identity, but still operates at the row level, not the column level.
- B. RLS filters rows of data, but does not hide entire columns or tables.
- C. Workspace RBAC controls access to the workspace itself (e.g., viewing/editing items), not specific columns within a semantic model.
Object-Level Security (OLS)
Object-Level Security (OLS) in Microsoft Fabric semantic models allows administrators to secure access to specific tables or columns, making them completely invisible to users who do not have the necessary permissions.
- Hides entire tables or columns from unauthorized users.
- Applied at the semantic model level.
- Independent of Row-Level Security (RLS).
Memory trick: Secure Your Data: Rows or Objects, Choose Wisely!