Microsoft Certified: Fabric Analytics Engineer AssociateImplement and manage semantic models (30-35%)Hard

A data engineer is working on a Microsoft Fabric semantic model that contains sensitive customer data and needs to ensure compliance with data governance policies. The requirement is to prevent certain users from viewing an entire column (e.g., 'Customer[CreditCardNumber]') while allowing them to see other columns in the same table. Additionally, other users should be restricted to seeing only the rows relevant to their region. Which two security mechanisms, when combined, will best achieve these requirements?

  1. AObject-Level Security (OLS) and Row-Level Security (RLS)
  2. BWorkspace Role-Based Access Control (RBAC) and Row-Level Security (RLS)
  3. CObject-Level Security (OLS) and Column-Level Security (CLS)
  4. DColumn-Level Security (CLS) and Workspace Role-Based Access Control (RBAC)
Show answer & explanation

Correct answer: A. Object-Level Security (OLS) and Row-Level Security (RLS)

The requirement to prevent viewing an entire column ('Customer[CreditCardNumber]') is addressed by Object-Level Security (OLS), which can hide tables or columns from users. The requirement to restrict users to seeing only rows relevant to their region is addressed by Row-Level Security (RLS). Combining OLS for columns and RLS for rows provides the comprehensive security needed.

Why the other options are wrong

  • B. Workspace RBAC controls access to the workspace, not data within the semantic model. RLS handles rows, but OLS is needed for columns.
  • C. While CLS can hide columns, OLS is the more encompassing term in Fabric for hiding entire objects (tables/columns). CLS is often considered a subset or specific application of OLS. However, neither addresses row-level filtering.
  • D. CLS (or OLS for columns) addresses column hiding, but Workspace RBAC doesn't provide row-level filtering within the semantic model.

Combined OLS and RLS

Combining Object-Level Security (OLS) and Row-Level Security (RLS) provides comprehensive data access control by restricting both entire objects (tables/columns) and specific data rows based on user roles.

  • OLS hides sensitive objects (tables, columns, measures).
  • RLS filters sensitive data at the row level.
  • Together they offer robust, granular security.

Memory trick: Objects hide, rows filter, together they secure, no data can slip or deter.

More Implement and manage semantic models (30-35%) questions