Microsoft Certified: Fabric Analytics Engineer AssociateImplement and manage semantic models (30-35%)Easy
A data engineer is designing a semantic model in Microsoft Fabric. The model will contain sensitive customer information that should only be visible to specific sales regions. The requirement is that users from Region A should only see data for Region A, and users from Region B should only see data for Region B. There is no overlap in regional data access. Which security mechanism should the data engineer implement to achieve this granular control efficiently?
- ARow-Level Security (RLS)
- BWorkspace Role-Based Access Control (RBAC)
- CColumn-Level Security (CLS)
- DObject-Level Security (OLS)
Show answer & explanationAnswer & explanation
Correct answer: A. Row-Level Security (RLS)
Row-Level Security (RLS) is designed to restrict access to rows in a table based on user identity or roles. This directly addresses the requirement to show specific sales regions only their relevant data.
Why the other options are wrong
- B. Workspace RBAC controls access to the workspace itself (e.g., viewing, editing items), not granular data within a semantic model.
- C. CLS restricts access to specific columns, not rows based on regional data.
- D. OLS restricts access to entire tables or columns, not specific rows within a table.
Row-Level Security (RLS)
RLS restricts data access at the row level based on user identity or role, ensuring users only see authorized data.
- Filters data rows based on user context.
- Implemented using DAX expressions in semantic models.
- Essential for granular data access control.
Memory trick: Rows, columns, objects – who sees what, where the data flows.