DP-700 Implement and Manage an Analytics Solution Practice Question
You are configuring a new Microsoft Fabric tenant. You want to ensure that users can only create Fabric items if they are assigned to a specific security group. Where should you configure this restriction?
⚠ Common exam trap
Candidates often assume these restrictions are managed inside individual workspaces or Azure Entra ID portal, overlooking the central administrative governance scope.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fabric Admin Portal - Tenant Settings
Tenant-level control is managed through the Fabric Admin Portal. Administrators can enable or disable specific features for the entire organization or limit them to specific security groups. This ensures that resource creation is governed and limited to authorized personnel, preventing uncontrolled sprawl and managing capacity costs effectively.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID (Azure AD) Conditional Access
Why it's wrong here
Conditional Access is used to control how users sign in and access the Fabric service based on conditions like location or device health. It does not provide the granular control needed to enable or disable specific features like item creation within the Fabric application itself.
- ✓
Fabric Admin Portal - Tenant Settings
Why this is correct
The Tenant Settings section of the Fabric Admin Portal contains the 'Users can create Fabric items' setting. By enabling this and specifying a security group, you ensure that only members of that group can provision new Lakehouses, Warehouses, and other Fabric-specific artifacts across the tenant.
- ✗
Workspace Settings - General
Why it's wrong here
Workspace settings apply only to an individual workspace and its contents. They do not have the authority to control who can create items at a tenant-wide level. Global permissions must be managed at the tenant level to ensure consistency and centralized control across all workspaces.
- ✗
Azure Subscription - Role Based Access Control (RBAC)
Why it's wrong here
Azure RBAC manages permissions for Azure resources like the Fabric Capacity itself, but it does not control the internal features of the Fabric SaaS service. Once a capacity is created, the management of who can create items within that capacity is handled internally by Fabric's own administration settings.
About these practice questions
Courseiva writes every DP-700 question from scratch — 152 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-700 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-700 exam.