Courseiva
Manage and secure Power BI →mediumMultiple Select

PL-300 Manage and secure Power BI Practice Question

Which TWO methods can a Power BI admin use to enforce the use of sensitivity labels on reports? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply labels automatically using Microsoft Purview Information Protection.

Option C is correct because Microsoft Purview Information Protection can be configured with auto-labeling policies that automatically apply sensitivity labels to Power BI content based on sensitive information types or other conditions, ensuring reports are labeled without relying on user action. Option D is correct because the Power BI tenant setting 'Require users to apply sensitivity labels when publishing reports' (in the admin portal under Information protection) enforces labeling at publish time, blocking publication of unlabeled reports. Option A is not correct because Intune is for device and app management (MDM/MAM) and cannot block unlabeled Power BI reports. Option B is not correct because default labels in Power BI Desktop only pre-populate a suggested label; users can still change or remove it, so it does not enforce labeling. Option E is not correct because row-level security (RLS) filters data rows by user identity and has no capability to detect or hide unlabeled reports.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy a Microsoft Intune policy to block unlabeled reports.

    Why it's wrong here

    Intune is a device management and mobile application management solution; it has no visibility into Power BI service publication workflows or sensitivity label metadata. Blocking unlabeled reports requires Power BI tenant settings (like the mandatory label requirement) or Microsoft Purview labeling policies, not an Intune compliance policy. Since Intune cannot evaluate or enforce labels on Power BI content, this method is invalid.

  • ✗

    Configure default labels in Power BI Desktop.

    Why it's wrong here

    While Power BI Desktop lets you define a default sensitivity label for local .pbix files, that label is not enforced by the Power BI service—it merely prepopulates a value that users can override or remove before publishing. Power BI admin enforcement must occur in the service or via cloud-based Purview policies; Desktop settings cannot mandate compliance for reports that are shared or published. Therefore, configuring Desktop defaults is not an admin enforcement method.

  • ✓

    Apply labels automatically using Microsoft Purview Information Protection.

    Why this is correct

    Microsoft Purview Information Protection (MIP) auto-labeling policies can inspect report content for sensitive data patterns (e.g., credit card numbers or PII) and automatically apply the appropriate sensitivity label to Power BI assets. Because Power BI is deeply integrated with Purview, these policies run in the background and can label unlabeled reports, ensuring consistent protection without manual user action. This is a fully valid admin-centric enforcement approach.

  • ✓

    Require users to apply sensitivity labels when publishing reports.

    Why this is correct

    Power BI admins can enable the tenant setting 'Require sensitivity label' in the admin portal, which forces users to select a sensitivity label before they can publish, export, or save new reports to the service. When this setting is on, the publish button is blocked if no label is chosen, making labeling mandatory at the point of content creation. This is a built-in admin enforcement method that directly prevents unlabeled reports from entering the service.

  • ✗

    Use row-level security to hide unlabeled reports.

    Why it's wrong here

    Row-level security (RLS) restricts the data rows a given user can see in a dataset based on DAX filter predicates, but it has no bearing on report visibility or sensitivity label status. RLS operates on data access, not on metadata like labels, and cannot hide, block, or flag unlabeled reports. Report sharing and label enforcement are controlled by workspace roles, sharing permissions, and Purview/Power BI admin settings, making RLS completely orthogonal to sensitivity labeling.

About these practice questions

This PL-300 question is part of Courseiva's 524-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.