Which Tool Audits Sharing of Reports and Dashboards in Power BI?
You are a Power BI administrator. You need to audit all activities related to sharing reports and dashboards in the Power BI service. Which tool should you use?
Quick Answer
The answer is the Power BI activity log, accessible through the admin API or the admin portal. This tool is correct because it captures a comprehensive, queryable record of every user action in the Power BI service, including all sharing activities such as sharing reports, dashboards, and apps with users or groups. On the Microsoft Power BI Data Analyst PL-300 exam, this question tests your understanding of native auditing versus external tools—a common trap is choosing Microsoft Purview, which offers broader audit logs but lacks the granular, Power-BI-specific detail needed for sharing audits. Diagnostic settings and Microsoft Sentinel are for log forwarding and security analysis, not direct auditing. To remember, think of the activity log as Power BI’s own “black box” for sharing events—if you need to audit who shared what and when, start here.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Power BI activity log (via admin API or portal)
The Power BI activity log provides a comprehensive record of all user activities within the Power BI service, including sharing reports and dashboards. Option A (Microsoft Purview compliance portal audit log) can capture some Power BI activities but is less specific and may not include all sharing events. Option B (Azure diagnostic settings) exports telemetry data to other destinations and is not designed for direct auditing of user actions. Option D (Microsoft Sentinel) is a SIEM tool that can ingest logs but is not the primary tool for auditing Power BI activities. The Power BI activity log is the correct choice as it is purpose-built for auditing Power BI user activities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview compliance portal audit log
Why it's wrong here
The Microsoft Purview compliance portal audit log retains Microsoft 365 service activity, but Power BI sharing events are recorded in the Power BI activity log, not there. It is tempting because Purview is the standard auditing surface for Microsoft 365 workloads, and would be correct for auditing Exchange, SharePoint or Teams activity.
- ✗
Azure diagnostic settings for Power BI
Why it's wrong here
Azure diagnostic settings export resource-level platform metrics and logs for Azure resources; Power BI is a SaaS service whose sharing activity is not surfaced through that mechanism. Diagnostic settings are tempting because they centralise Azure telemetry, and would be correct for capturing logs from resources such as Key Vault or SQL Database.
- ✓
Power BI activity log (via admin API or portal)
Why this is correct
The Power BI activity log records granular events including ShareReport, ShareDashboard and CreateDashboard, retrievable through the admin portal or REST API. It satisfies the audit requirement by capturing who shared what, with whom, and when across the tenant.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a SIEM that ingests and correlates security signals; it does not natively expose Power BI sharing events without a configured connector and data pipeline. It is tempting because Sentinel centralises audit data across cloud services, and would be correct for threat detection and incident investigation across an estate.
Go deeper
Related to this question
About these practice questions
One of 524 original PL-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on PL-300
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator wants to monitor all Power BI activities, including viewing reports, exporting data, and sharing workspaces. Which tool should they use?
easy- ✓ A.Power BI activity log in the admin portal
- B.Power BI usage metrics report
- C.Power BI capacity metrics app
- D.Microsoft 365 audit log
Why A: The Power BI activity log captures user activities such as viewing, exporting, and sharing. Option B is wrong because the usage metrics report shows aggregate usage, not detailed activities. Option C is wrong because the Power BI capacity metrics app focuses on performance and capacity metrics, not user activities. Option D is wrong because the Microsoft 365 audit log is broader but less specific to Power BI; the activity log is the dedicated tool.
Variation 2. You need to audit Power BI activities such as viewing reports, sharing dashboards, and exporting data. Which TWO actions should you take to enable and access audit logs? (Choose two.)
medium- A.Configure Microsoft Defender for Cloud Apps to forward logs to Microsoft Sentinel.
- ✓ B.Access the audit log from the Microsoft 365 compliance portal.
- ✓ C.Enable the 'Create audit logs for Power BI activities' tenant setting in the admin portal.
- D.Use the 'Export' feature in Power BI to export audit logs to a CSV file.
- E.Set up a diagnostic setting in Azure Monitor to collect Power BI logs.
Why B: To audit Power BI activities, you must first enable audit logging by turning on the 'Create audit logs for Power BI activities' tenant setting in the Power BI admin portal (option C). Once enabled, you can access the audit logs from the Microsoft 365 compliance portal (option B). Option A is incorrect because Microsoft Defender for Cloud Apps is not the primary location for audit logs; it can integrate but is not required. Option D is incorrect because Power BI does not have an export feature for audit logs to CSV; you can export from the compliance portal. Option E is incorrect because Azure Monitor diagnostic settings are for Azure resources, not for Power BI audit logs.
Variation 3. You need to audit Power BI activity for compliance. Which tool should you use to access detailed logs of user actions?
easy- A.Microsoft Defender XDR
- ✓ B.Microsoft Purview compliance portal (Audit)
- C.Microsoft Purview Data Map
- D.Power BI Premium capacity metrics app
Why B: The correct option is B, Microsoft Purview compliance portal (Audit), because it provides the unified audit log that captures detailed Power BI user activity such as viewed reports, edited datasets, shared dashboards, and exported data, which is exactly what a compliance audit requires. Power BI activity events are surfaced through the Microsoft 365 audit log, accessible via the Purview compliance portal's Audit search (or the Search-UnifiedAuditLog cmdlet), letting you filter by workload, user, and date. Option A, Microsoft Defender XDR, focuses on security incidents and threat detection across endpoints, identities, and email, not on Power BI activity auditing. Option C, Microsoft Purview Data Map, catalogs and classifies data assets for governance but does not record user action logs. Option D, the Power BI Premium capacity metrics app, reports on capacity utilization and performance metrics, not detailed per-user activity logs.
Variation 4. A Power BI administrator needs to audit which users have exported data from a specific report in the last 30 days. What is the most efficient way to retrieve this information?
medium- A.Use the Microsoft Purview compliance portal to search for 'Export' events.
- B.Check the report's usage metrics report for export counts.
- ✓ C.Query the Power BI activity log using the audit log search in the Microsoft 365 Defender portal.
- D.Review the 'Export to Excel' metrics in the Azure Monitor for Power BI Premium.
Why C: The correct option is C: query the Power BI activity log using the audit log search in the Microsoft 365 Defender portal, because Power BI audit events such as ExportReport, ExportData, and ExportToFile are centralized in the unified Microsoft 365 audit log, which supports filtering by user, date range, and activity type for the last 30 days. This is the most efficient way to identify exactly which users exported data from a specific report, since the audit log records per-user, per-item activity. Option A is not the right tool because Microsoft Purview compliance portal search is oriented toward compliance and eDiscovery scenarios rather than granular Power BI report export auditing. Option B only provides aggregated usage metrics (view counts and similar statistics) without per-user export detail. Option D is incorrect because Azure Monitor for Power BI Premium focuses on capacity and resource telemetry, not user-level export auditing.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.