Courseiva
Deploy and maintain assetsmediumMultiple ChoiceObjective-mapped

PL-300 Deploy and maintain assets Practice Question

You are deploying a Power BI solution to a customer. The customer requires that all report access be controlled via Azure Active Directory (Azure AD) groups. You have a single workspace with multiple reports. What is the best practice for managing permissions?

⚠ Common exam trap

A common mix-up: candidates confuse Power BI groups (which are legacy and not Azure AD integrated) with Azure AD groups, or assume that direct user assignment or individual report sharing is simpler, missing the requirement for centralized Azure AD-based control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Add an Azure AD group to the workspace role.

Using an Azure AD group to manage workspace roles aligns with the customer's requirement for centralized access control via Azure AD. This approach simplifies permission management by allowing group membership changes in Azure AD to automatically propagate to Power BI workspace access, ensuring consistency and reducing administrative overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a Power BI group and add users to it.

    Why it's wrong here

    Creating a Power BI group (an Office 365/Outlook group) and adding users to it does not, by itself, grant anyone access to a Power BI workspace. These groups are deprecated as a management concept and are not recognized as direct workspace principals. To use a group for access, you must explicitly add that group to a workspace role in Power BI, which is exactly what the correct option does. Merely creating the group adds no permission and users will still get 'You need permission' errors.

  • Assign each user directly to the workspace role.

    Why it's wrong here

    Assigning each user directly to the workspace role is technically functional but becomes administrationally burdensome at scale. For every new user, change, or departure, you must manually edit the workspace role membership; with multiple workspaces and many users, this quickly becomes error-prone and time-consuming. It also bypasses central identity management, making access hard to audit and govern. Azure AD groups as role members allow membership changes to flow automatically, which is the recommended scalable approach.

  • Share each report individually with users.

    Why it's wrong here

    Sharing each report individually gives users read-only access to that specific artifact, but it does not grant access to the underlying workspace, dataset, or other content. This approach does not scale: every new report must be shared separately, and you risk stale or inconsistent permissions across reports. It also blocks collaboration and editing, because workspace roles carry broader permissions (like Viewer, Contributor, Member, or Admin). The correct pattern is to manage access at the workspace level by assigning an Azure AD group to a workspace role, so all content inherits permissions consistently.

  • Add an Azure AD group to the workspace role.

    Why this is correct

    Adding an Azure AD group to the workspace role is the correct, recommended approach for scalable access management in Power BI. When you assign the group to a role such as Viewer, Contributor, Member, or Admin, all current and future members of that group automatically receive the corresponding permissions on the workspace and its content. This centralizes identity governance in Azure AD: adding or removing a user from the group instantly reflects in Power BI, with no per-workspace or per-report edits needed. It aligns with enterprise security best practices and simplifies auditing and compliance.

About these practice questions

This PL-300 question is part of Courseiva's 217-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.