Microsoft Certified: Fabric Analytics Engineer AssociateImplement and manage semantic models (30-35%)Easy
A financial services company uses Microsoft Fabric for its analytics. A new semantic model is being developed that contains sensitive financial transaction data. The company has a strict compliance requirement that mandates specific columns, such as 'Account Number' and 'Transaction ID', must be completely hidden from users in certain roles, even if they have access to other parts of the table. Which security feature should the data engineer implement to meet this requirement?
- ADynamic Row-Level Security
- BRow-Level Security (RLS)
- CWorkspace Role-Based Access Control (RBAC)
- DObject-Level Security (OLS)
Show answer & explanationAnswer & explanation
Correct answer: D. Object-Level Security (OLS)
Object-Level Security (OLS) allows you to secure specific tables or columns in a semantic model, making them invisible to unauthorized users. This directly addresses the requirement to hide specific columns like 'Account Number' and 'Transaction ID' from certain roles.
Why the other options are wrong
- A. Dynamic RLS is a more advanced form of RLS that uses data in the model to filter rows dynamically, but still only targets rows, not columns.
- B. RLS filters rows of data based on user identity, but it does not hide entire columns.
- C. Workspace RBAC controls access to the workspace itself and its items, not granular security within a semantic model.
Object-Level Security (OLS)
Object-Level Security (OLS) in Microsoft Fabric semantic models allows you to restrict access to specific tables or columns for certain users or roles. This means unauthorized users will not even be aware of the existence of these objects.
- Hides entire tables or columns from users.
- Metadata for secured objects is not exposed.
- Implemented at the semantic model level.
- Complementary to Row-Level Security (RLS).
Memory trick: Security for models is about who sees what: rows or objects.