Microsoft Certified: Fabric Analytics Engineer AssociateImplement and manage semantic models (30-35%)Medium
A company uses Microsoft Fabric to manage its analytics. A new semantic model is being developed for financial reporting. The company's security policy dictates that users in the 'Finance Managers' role should only see data for their specific region, while 'Finance Analysts' should see data for all regions but only for departments they are assigned to. All other users should have no access. How should Row-Level Security (RLS) be implemented in this semantic model?
- ACreate two roles: 'Finance Managers' with dynamic RLS based on user region, and 'Finance Analysts' with dynamic RLS based on user department. Assign users accordingly.
- BImplement Object-Level Security (OLS) for regions and departments, and assign users to appropriate OLS roles.
- CCreate three roles: 'Finance Managers' with static RLS for each region, 'Finance Analysts' with static RLS for each department, and a 'No Access' role for others.
- DUse Power BI service security roles to define access at the report level, bypassing RLS in the semantic model.
Show answer & explanationAnswer & explanation
Correct answer: A. Create two roles: 'Finance Managers' with dynamic RLS based on user region, and 'Finance Analysts' with dynamic RLS based on user department. Assign users accordingly.
Dynamic RLS allows for filtering data based on the user's identity (e.g., username or custom security table), making it ideal for scenarios where filtering criteria vary per user within a role, such as region or department access.
Why the other options are wrong
- B. Object-Level Security (OLS) restricts access to entire tables or columns, not rows, and cannot fulfill the requirement of filtering data within a table.
- C. Static RLS would require creating numerous roles for each region and department combination, which is unmanageable and inflexible for dynamic access needs.
- D. Power BI service security roles primarily control report and app access, but RLS in the semantic model is necessary to filter the underlying data for users.
Dynamic RLS
A Row-Level Security implementation where filtering criteria are determined at query time based on the querying user's identity or attributes.
- Uses DAX expressions to filter rows.
- Often relies on USERNAME() or USERPRINCIPALNAME() functions.
- Scalable for many users with varying access patterns.
Memory trick: Row-level filters data, Object-level hides objects, Workspace controls access, Gateway secures connections.