Courseiva

Three Prerequisites to Enable Power BI Sensitivity Labels from Microsoft Purview

Which THREE of the following are required to configure Microsoft Purview Information Protection sensitivity labels for Power BI? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Users must have appropriate permissions (e.g., Azure Information Protection rights) to apply labels.

Option C is correct because applying a sensitivity label to a Power BI artifact requires the user to hold the appropriate usage rights, such as Azure Information Protection (AIP) rights, so the label's protection settings can be enforced on the item. Option D is correct because sensitivity labels must first be created and published to the relevant users from the Microsoft 365 Compliance Center (Microsoft Purview compliance portal) before they become available for use in Power BI. Option E is correct because an admin must enable sensitivity labels for Power BI in the Power BI admin portal tenant settings; otherwise the labeling feature remains unavailable in the service and Desktop. Option A is not required because sensitivity labels are not gated on a Power BI Pro license specifically, and Option B is not required because labeling works without assigning the workspace to a Power BI Premium capacity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Each user must have a Power BI Pro license.

    Why it's wrong here

    The Power BI Pro license is a general prerequisite for creating and editing content in the service, but it is not a step you perform when configuring sensitivity labels. While a user must hold a Pro license to apply a label, that licensing requirement already exists for any Power BI interaction and does not need to be set up specifically for information protection. Even after all users have Pro licenses, sensitivity labels will still remain invisible and non-functional unless the admin separately enables them in the tenant settings and labels are published from the Compliance Center. Therefore, this is an unrelated prerequisite, not a configuration requirement.

  • ✗

    Have a Power BI Premium capacity assigned to the workspace.

    Why it's wrong here

    This is incorrect because sensitivity labels in Power BI work identically in shared capacity as they do in Premium capacity. The label is stored as metadata on the dataset and report, and its enforcement is handled by Microsoft Purview, not by the capacity's computing resources. Assigning the workspace to a Premium capacity is only necessary for other features such as paginated reports, AI visuals, or XMLA endpoints, and it has no bearing on whether the label picker appears or whether labels can be applied. Premium capacity is therefore never a configuration step for identity-based sensitivity labels.

  • ✓

    Users must have appropriate permissions (e.g., Azure Information Protection rights) to apply labels.

    Why this is correct

    To apply sensitivity labels, a user's identity must have the appropriate rights defined in the label itself via Azure Information Protection (now Microsoft Purview Information Protection). This is usually accomplished by adding the user to the label's 'Viewer' or 'Editor' permission list, which grants them the right to see and modify content protected by that label. Without these rights, the label will appear in the picker but the user will receive an error when trying to apply it, because the label's encryption policy forbids them from doing so. Delegating these rights to individual users or groups is an explicit configuration action that must be performed outside of Power BI.

  • ✓

    Sensitivity labels must be published in the Microsoft 365 Compliance Center.

    Why this is correct

    Sensitivity labels are defined and published in the Microsoft 365 Compliance Center (now Microsoft Purview) as part of a label policy. Publishing exposes the labels to all services that integrate with Microsoft Purview, including Power BI, and controls which users can see and select them. If a label is created but never published, it will not appear in Power BI's sensitivity label dropdown, making the publishing step an absolute requirement for the feature to function. Additionally, the published label must be scoped to 'Files' to be available for the dataset and report content in Power BI.

  • ✓

    Enable sensitivity labels in the Power BI admin tenant settings.

    Why this is correct

    The Power BI admin must explicitly turn on the sensitivity labels toggle in the Power BI admin portal under 'Tenant settings' or 'Information protection'. This setting establishes the connection between the Power BI service and Microsoft Purview, allowing Power BI to download and display the published label list and to validate user permissions. If this toggle is left off, Power BI will silently ignore all sensitivity label configuration, and users will not see any label option in the user interface. Enabling this setting is the first active step an administrator must perform to make labels operational within the environment.

About these practice questions

This PL-300 question is part of Courseiva's 524-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.