PL-300 Manage and secure Power BI Practice Question
A Power BI admin receives a support ticket that a user cannot see any data in a report that uses row-level security (RLS). The report is based on a dataset with a single table 'Sales' and RLS roles defined. The user is assigned to the role 'SalesManager' which filters Sales[Region] = 'West'. The dataset uses Import mode. The user can see the report but all visuals show blank. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The RLS filter removes all rows for the user's role.
The RLS filter removes all rows for the user's role. In Import mode, RLS is enforced by DAX filters applied at query time, so if the 'SalesManager' role filters Sales[Region] = 'West' and the user's identity maps to no rows where Region equals 'West' (for example, due to case/spacing mismatches or the user not being in the intended region), every visual returns blank rather than an error. The other options do not fit: B would typically block report access entirely or show a permission error, not blank visuals; C describes a dashboard tile scenario, but the ticket says the user can see the report; and D is not a valid cause because refreshing with an RLS bypass account affects data loading, not the query-time RLS filtering applied to the user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The RLS filter removes all rows for the user's role.
Why this is correct
The correct diagnosis is that the row-level security (RLS) filter defined for the user's role is returning an empty result. RLS applies a DAX filter to every visual in the report; if the user's identity (via USERNAME()) doesn't match any row in the `Sales[Region]` column, all measures become BLANK and tables show zero rows. An admin can verify this by using 'View as' in Power BI Desktop and selecting the specific role to see the same empty output.
- ✗
The user does not have permission to view the report page.
Why it's wrong here
This is incorrect because report page visibility is controlled by workspace roles or app permissions, completely separate from RLS. If the user lacks permission to view the page, they would receive an access denied error or the page wouldn't render at all, not a blank report with headers and axes visible. Since the user can actually see the report page and its layout, the root cause lies in the data-level security rules.
- ✗
The user is viewing a dashboard tile instead of the report.
Why it's wrong here
This cannot explain the blank visuals because row-level security is enforced on dashboard tiles exactly as it is on report visuals. When a dashboard tile is pinned from a report, the tile runs a query against the same dataset with the viewer's effective identity, so RLS filters are applied and can return an empty set for that user. If the tile itself were the issue, the user would see the tile but with no data, which is the same symptom as in the report.
- ✗
The dataset was refreshed using an RLS bypass account.
Why it's wrong here
The refresh account is irrelevant to RLS behavior because row-level security is a query-time filter, not a data-loading filter. During refresh, Power BI imports the full dataset into memory; when an end user opens the report, the Power BI engine applies the role's FILTER() predicate to their query, regardless of which account performed the refresh. Even if the refresh used a service principal with full permissions, that only affects data loading—not the row-level scoping applied to individual viewers.
Go deeper
Related to this question
About these practice questions
This PL-300 question is part of Courseiva's 524-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.