Courseiva
Manage and secure Power BI →mediumMultiple Choice

PL-300 Manage and secure Power BI Practice Question

You are a Power BI administrator. Your organization uses Microsoft Entra ID for identity management. You need to ensure that only users from specific security groups can access the Power BI service. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a conditional access policy in Microsoft Entra ID that grants access to Power BI only for members of the allowed security groups.

Option B is correct because Microsoft Entra ID Conditional Access is the supported mechanism to restrict sign-in to a cloud app such as Power BI based on group membership: you create a policy assigned to the Power BI cloud app, target the specific security groups under Users, and grant access while blocking everyone else. This enforces the restriction at authentication time across the tenant, which is exactly what the scenario requires. Option A is wrong because the Power BI admin portal's 'Allow users to access Power BI' setting is a tenant-wide on/off toggle that cannot be scoped to specific security groups. Option C is wrong because B2B guest settings govern external collaboration and domain allow/deny lists, not which internal security groups may use Power BI. Option D is wrong because workspace access permissions only control content within individual workspaces and do not prevent users from signing in to the Power BI service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    In the Power BI admin portal, configure the 'Allow users to access Power BI' setting to specify the security groups.

    Why it's wrong here

    This tenant-level switch in the Power BI admin portal is a global master toggle that either enables Power BI for the entire organization or disables it for everyone; it does not expose a field to select security groups for this particular setting. While many other tenant settings support scoping to specific groups, 'Allow users to access Power BI' only allows an all-or-nothing approach, so it cannot implement the requirement to grant access solely to approved security groups.

  • ✓

    Create a conditional access policy in Microsoft Entra ID that grants access to Power BI only for members of the allowed security groups.

    Why this is correct

    A conditional access policy in Microsoft Entra ID can target the Power BI service as a cloud app and apply a grant control that only allows sign-ins from specific security groups, while blocking all other users. This is the recommended identity-driven approach because Power BI authenticates via Entra ID, so the policy is evaluated during every sign-in, and it can also incorporate conditions such as device compliance, MFA, or location.

  • ✗

    Configure the 'B2B guest user settings' to allow only specific domains.

    Why it's wrong here

    B2B guest user settings control how external collaborators are invited and whether certain domains are allowed for guest accounts, but they have no effect on the sign-in access of employees from your own tenant. Restricting allowed domains in B2B configuration would block external users from those domains, yet your internal allowed security groups would remain unaffected, and non-members from your organization could still access Power BI.

  • ✗

    Modify the workspace access permissions to include only the allowed security groups.

    Why it's wrong here

    Workspace permissions like Viewer, Contributor, or Member define what users can do with content inside a specific app workspace, not whether they can sign in to the Power BI service. Even if you remove a user from all workspace access lists, they can still launch Power BI, create their own workspaces, and see their My Workspace, because authentication and general access are governed at the tenant level, not per workspace.

About these practice questions

This PL-300 question is part of Courseiva's 524-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.