A data architect is designing a semantic model in Microsoft Fabric. The model will be used by various departments, each with different data access needs. Some departments require highly granular, row-level filtering based on user roles, while others need to restrict access to specific sensitive columns or measures. The architect also wants to ensure that specific measures are only visible to users with certain permissions. How should the architect combine security features to achieve both row-level and object-level restrictions, including measures?
- AImplement Row-Level Security (RLS) for granular data filtering and Object-Level Security (OLS) for specific columns and measures.
- BImplement only Object-Level Security (OLS) for all tables, columns, and measures.
- CUse Workspace Role-Based Access Control (RBAC) to manage all data access.
- DImplement only Row-Level Security (RLS) and use DAX to hide measures.
Show answer & explanationAnswer & explanation
Correct answer: A. Implement Row-Level Security (RLS) for granular data filtering and Object-Level Security (OLS) for specific columns and measures.
To achieve both row-level filtering and the hiding of specific columns/measures, a combination of RLS and OLS is required. RLS filters rows of data based on user identity, while OLS hides entire objects (tables, columns, or measures), making them invisible to unauthorized users. This combined approach provides comprehensive granular control over data visibility.
Why the other options are wrong
- B. OLS hides objects but does not provide row-level filtering. It would hide entire tables or columns, not specific rows for a user.
- C. Workspace RBAC controls access to the Fabric items themselves (e.g., access to the semantic model), but not granular row-level or column-level security within the model.
- D. RLS only filters rows; while DAX can conditionally return BLANK for measures, it doesn't 'hide' the measure metadata itself, and it doesn't hide columns.
Combined RLS and OLS
Combining Row-Level Security (RLS) and Object-Level Security (OLS) in a Microsoft Fabric semantic model allows for comprehensive data access control. RLS filters rows based on user identity, while OLS hides entire tables, columns, or measures, providing both horizontal and vertical security.
- RLS: Filters rows (horizontal security).
- OLS: Hides tables, columns, or measures (vertical security).
- Used together for granular and complete data access control.
- OLS is configured using Tabular Editor, RLS via the Fabric UI or Tabular Editor.
Memory trick: For full security, filter rows with RLS, hide objects with OLS.