DP-700 Implement and Manage an Analytics Solution Practice Question
You manage a Microsoft Fabric workspace containing a critical lakehouse and multiple downstream semantic models. You need to configure item-level permissions to ensure that specific business analysts can refresh the semantic models without being able to view or query the underlying tables in the lakehouse storage. Which permission level should you assign directly to the analysts on the semantic model?
⚠ Common exam trap
Candidates often assign Read or Write permissions, believing users need full workspace access or storage-level permissions just to refresh a downstream semantic model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign Build permission specifically on the semantic model to enable reporting and refresh capabilities.
Assigning the Build permission directly to the semantic model grants users the ability to create new reports based on the model and refresh it if configured, without granting access to the underlying lakehouse tables or workspace artifacts. This principle of least privilege ensures analysts can execute operational refreshes without exposing raw data layers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign Admin permission on the semantic model to grant full control over the artifact settings and refresh history.
Why it's wrong here
Admin permission grants excessive control, allowing users to delete the item, reconfigure connections, and manage all security settings. This violates the principle of least privilege required for analysts who only need to execute scheduled or manual data refreshes.
- ✗
Assign Contributor permission on the workspace containing the semantic model and the lakehouse storage.
Why it's wrong here
Workspace-level Contributor access provides read and write permissions to all items within the workspace, inadvertently exposing the underlying lakehouse tables and allowing modifications to the data storage layer that analysts should not manage.
- ✗
Assign Write permission on the semantic model to allow data modifications and structural definition updates.
Why it's wrong here
Write permission allows users to modify the semantic model definition, alter relationships, and change measure calculations. This goes beyond the operational refresh requirement and risks unintended modifications to the enterprise semantic layer.
- ✓
Assign Build permission specifically on the semantic model to enable reporting and refresh capabilities.
Why this is correct
Build permission is the specific access level required for users to connect to a semantic model, run queries, and perform refresh operations via the service interface or API, while restricting direct access to the underlying storage sources.
About these practice questions
This DP-700 question is part of Courseiva's 152-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-700 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-700 exam.