PL-300 Manage and secure Power BI Practice Question
A Power BI administrator needs to allow an external partner organization to access a specific report without requiring them to have Power BI Pro licenses. The report is stored in a workspace assigned to a Premium capacity. What is the correct configuration?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Invite the external users as guest users in Microsoft Entra ID, add them to the workspace with Viewer role, and share the report or app
It uses Microsoft Entra B2B guest invitations so external partners authenticate with their own credentials, and then grants them Viewer access to the workspace/app; with the workspace on Premium capacity, guests can consume the content without needing Power BI Pro licenses. Adding them as workspace members with Viewer role alone (A) does not establish the required external identity in the tenant. Publishing to the web (B) creates an anonymous public link, which is insecure and not appropriate for a specific partner. 'Embed for your organization' (D) is for internal users with Power BI accounts and does not provide the licensing-free external sharing scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the external users as members of the workspace and assign them a Viewer role
Why it's wrong here
External users are not automatically present in your Microsoft Entra tenant, so they must first be invited as B2B guest users and accept the invitation. Without this prior step, you cannot add them to a Power BI workspace or assign roles like Viewer. Even if the external partner is already a guest, simply adding them to the workspace is not sufficient—you must also share the report or app for them to access the content. Thus, this option is incomplete because it omits the required guest invitation and content-sharing steps.
- ✗
Publish the report to the web and share the public link
Why it's wrong here
Publish to web generates a public URL that grants anonymous access to anyone with the link, completely bypassing Power BI security, row-level security, and licensing requirements. This is fundamentally unacceptable when the data is intended for a specific external partner, as it exposes the report to the entire internet. Additionally, the external partner would not need any identity or authentication, making the sharing uncontrolled and unaccountable. For security reasons, this method is never appropriate for sharing confidential or internal business data with a partner.
- ✓
Invite the external users as guest users in Microsoft Entra ID, add them to the workspace with Viewer role, and share the report or app
Why this is correct
This is the correct approach because you first invite the external partner as a B2B guest user in Microsoft Entra ID, which creates a secure identity in your tenant for them. After they accept the invitation, you can add them to the workspace and assign the Viewer role, restricting them to read-only access. Finally, you share the report or app directly with them, and because the workspace resides in Premium capacity, the guest users can view it without needing their own Power BI Pro licenses. This method ensures authenticated, authorized access while maintaining full security and auditability.
- ✗
Embed the report in a secure portal using the 'embed for your organization' option
Why it's wrong here
The 'embed for your organization' (secure embed) option is designed for content to be embedded in SharePoint or a portal where all users are already members of your tenant and have Power BI licenses. External partner users are not in your tenant by default, and this embedding method requires Microsoft Entra ID authentication, so without guest accounts or proper licenses, they will be blocked. Even if you invited them as guests, they would still need a Power BI license (unless the content is in Premium) and the embedding code would need to be configured for external users. Thus, this approach does not directly solve the sharing requirement for an external partner and is therefore incorrect.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PL-300 question from scratch — 524 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.