Microsoft Certified: Fabric Analytics Engineer AssociateGovern and administer Fabric (10-15%)Medium
A data analytics team is developing several critical reports and dashboards in a Microsoft Fabric workspace. They need to ensure that specific sensitive columns within a table are not visible to users with a 'Viewer' role, even if those users have access to the table itself. The solution must be implemented directly within the Lakehouse data model. Which security measure should the team implement?
- ARow-Level Security (RLS)
- BObject-Level Security (OLS)
- CWorkspace roles
- DMicrosoft Purview Information Protection
Show answer & explanationAnswer & explanation
Correct answer: B. Object-Level Security (OLS)
Object-Level Security (OLS) is designed to hide specific columns or tables from users, making it the appropriate choice for restricting access to sensitive columns within a Lakehouse data model. RLS restricts rows, workspace roles manage overall workspace access, and Purview is for broader data governance.
Why the other options are wrong
- A. Row-Level Security restricts access to specific rows, not columns, within a table.
- C. Workspace roles control overall access to items within a workspace but do not provide granular column-level control within a data model.
- D. Microsoft Purview Information Protection is used for classifying and protecting sensitive data at a broader organizational level, not for direct column-level security within a Fabric Lakehouse data model.
Object-Level Security (OLS)
Object-Level Security (OLS) in Microsoft Fabric allows you to restrict access to specific tables or columns within a data model, making them invisible to unauthorized users.
- Hides entire tables or columns from users.
- Implemented within the data model (e.g., Lakehouse, semantic model).
- Ensures sensitive data remains inaccessible even if users have table access.
Memory trick: Fabric's OLS is like a secret cloak for your columns.