Microsoft Certified: Fabric Analytics Engineer AssociateImplement and manage semantic models (30-35%)Easy

A data engineer is designing a semantic model in Microsoft Fabric. The model will contain sensitive customer information that should only be visible to specific sales regions. The requirement is that users from Region A should only see data for Region A, and users from Region B should only see data for Region B. There is no overlap in regional data access. Which security mechanism should the data engineer implement to achieve this granular control efficiently?

  1. ARow-Level Security (RLS)
  2. BWorkspace Role-Based Access Control (RBAC)
  3. CColumn-Level Security (CLS)
  4. DObject-Level Security (OLS)
Show answer & explanation

Correct answer: A. Row-Level Security (RLS)

Row-Level Security (RLS) is designed to restrict access to rows in a table based on user identity or roles. This directly addresses the requirement to show specific sales regions only their relevant data.

Why the other options are wrong

  • B. Workspace RBAC controls access to the workspace itself (e.g., viewing, editing items), not granular data within a semantic model.
  • C. CLS restricts access to specific columns, not rows based on regional data.
  • D. OLS restricts access to entire tables or columns, not specific rows within a table.

Row-Level Security (RLS)

RLS restricts data access at the row level based on user identity or role, ensuring users only see authorized data.

  • Filters data rows based on user context.
  • Implemented using DAX expressions in semantic models.
  • Essential for granular data access control.

Memory trick: Rows, columns, objects – who sees what, where the data flows.

More Implement and manage semantic models (30-35%) questions