Microsoft Certified: Fabric Analytics Engineer AssociateImplement and manage semantic models (30-35%)Hard
A financial services company is developing a highly sensitive semantic model in Microsoft Fabric. The model contains a 'Salaries' table with sensitive compensation data, which should only be accessible to a few authorized HR personnel. No other user, including administrators of the Fabric workspace, should be able to view the data in this specific table, even if they have full access to the workspace. How should this requirement be met?
- AUse Power BI service workspace roles to restrict access to the semantic model for unauthorized users.
- BStore the 'Salaries' data in a separate semantic model with restricted sharing permissions.
- CImplement Object-Level Security (OLS) on the 'Salaries' table to deny access to specific roles.
- DApply Row-Level Security (RLS) to the 'Salaries' table to filter out all rows for unauthorized users.
Show answer & explanationAnswer & explanation
Correct answer: C. Implement Object-Level Security (OLS) on the 'Salaries' table to deny access to specific roles.
Object-Level Security (OLS) allows you to secure entire tables or columns, making them invisible or inaccessible to specific roles. This is the only method that can prevent even workspace administrators from seeing a table's data if they are not part of the allowed OLS role.
Why the other options are wrong
- A. Workspace roles control access to the semantic model as a whole but do not granularly hide specific tables or columns within it, nor do they prevent workspace admins from viewing data.
- B. While using a separate model can add a layer of separation, an unauthorized user with access to that model could still see the data. OLS provides direct object-level control within a single model.
- D. RLS filters rows but still shows the table and column names, and workspace admins can bypass RLS by taking ownership of the dataset.
Object-Level Security (OLS)
A security feature in Power BI/Fabric that allows you to secure access to entire tables or columns within a semantic model, making them invisible to unauthorized users.
- Hides tables or columns from specific roles.
- Prevents metadata exposure for secured objects.
- Can be managed using Tabular Editor or XMLA endpoint.
Memory trick: OLS hides objects, RLS filters rows, Sensitivity labels classify data.