Microsoft Certified: Fabric Analytics Engineer AssociateImplement and manage semantic models (30-35%)Medium

A financial services company is developing a highly sensitive semantic model in Microsoft Fabric. The model contains a 'Salaries' table and a 'Customer Accounts' table. Due to strict compliance regulations, certain users should not be able to see the 'Salaries' table at all, while other users should only see specific rows in the 'Customer Accounts' table based on their regional assignment. Which security features should be implemented?

  1. AWorkspace Role-Based Access Control (RBAC)
  2. BBoth Row-Level Security (RLS) and Object-Level Security (OLS)
  3. COnly Row-Level Security (RLS)
  4. DOnly Object-Level Security (OLS)
Show answer & explanation

Correct answer: B. Both Row-Level Security (RLS) and Object-Level Security (OLS)

Object-Level Security (OLS) is required to restrict access to the entire 'Salaries' table, while Row-Level Security (RLS) is needed to filter rows within the 'Customer Accounts' table based on user attributes.

Why the other options are wrong

  • A. Workspace RBAC controls access to the workspace itself, not granular data within a semantic model.
  • C. RLS only filters rows within tables; it cannot hide an entire table.
  • D. OLS hides entire tables or columns; it cannot filter specific rows within a table.

OLS and RLS Combination

Using both Object-Level Security (OLS) to hide entire objects (tables/columns) and Row-Level Security (RLS) to filter rows within visible objects, providing comprehensive data access control.

  • OLS controls visibility of objects (tables, columns, measures).
  • RLS controls visibility of rows within tables.
  • Often used together for granular security requirements.

Memory trick: Objects hidden, rows filtered, all secure and covered.

More Implement and manage semantic models (30-35%) questions