PL-300 Manage and secure Power BI Practice Question
You create a Power BI report that uses a live connection to an Azure Analysis Services (AAS) model. You want to enforce row-level security defined in the AAS model. What should you do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No additional configuration needed; RLS from AAS is automatically applied.
Option B is correct because when a Power BI report uses a live connection to an Azure Analysis Services (AAS) model, the report does not contain its own dataset or RLS definitions; instead, it queries the AAS model directly, so the row-level security roles and memberships defined in the AAS model are automatically enforced for the connecting user. This is the standard behavior for live connections to Analysis Services, where security is managed at the source model rather than in Power BI. Option A is wrong because object-level security (OLS) restricts columns/tables, not rows, and is not a substitute for RLS. Option C is wrong because you cannot create RLS roles on the dataset in the Power BI service when the report uses a live connection, since there is no imported dataset in Power BI to configure. Option D is wrong because defining RLS roles in Power BI Desktop and publishing applies only to imported or DirectQuery datasets hosted in Power BI, not to live-connected AAS models.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use object-level security (OLS) instead.
Why it's wrong here
Object-level security (OLS) is meant to restrict access to specific tables, columns, or metadata in a tabular model, not to filter which data rows a user can see. OLS operates at the schema level by hiding objects from unauthorized users, whereas row-level security (RLS) applies predicate filters on rows. In a live connection to Azure Analysis Services (AAS), OLS is also defined in the source model, so using it instead of RLS would fail to deliver row-level filtering and would not satisfy the requirement for showing only a subset of rows.
- ✓
No additional configuration needed; RLS from AAS is automatically applied.
Why this is correct
When a Power BI report uses a live connection to Azure Analysis Services (AAS) or SQL Server Analysis Services (SSAS), row-level security defined in the source tabular model is enforced directly by the source. The live connection passes the authenticated user's identity to the server, which then evaluates the RLS roles and filters rows before returning data to Power BI. There is no need for additional configuration in Power BI; the source model is the single authority for data security, ensuring consistent and secure row filtering across all reports that connect live.
- ✗
Use Power BI service to create RLS roles on the dataset.
Why it's wrong here
Power BI service only supports creating row-level security roles for datasets that use Import mode, where the data is stored in Power BI's internal engine. For live connection datasets, the model remains in AAS/SSAS, and the 'Security' page in Power BI service does not provide an option to manage roles because Power BI cannot edit the source model. Attempting to create RLS roles directly on a live-connected dataset would fail or be disabled; any RLS must be defined in the underlying tabular model in its native environment.
- ✗
Define the same RLS roles in Power BI Desktop and publish.
Why it's wrong here
Power BI Desktop's 'Manage Roles' feature is disabled when the data source is a live connection, because there is no local data model stored in the .pbix file to attach roles to. Defining RLS roles requires a metadata model with tables and relationships; with a live connection, the .pbix file contains only connection metadata, not the schema. Therefore, you cannot define the same RLS roles in Power BI Desktop and publish them; the roles must be created and managed in the AAS/SSAS tabular model and published from there, making this option technically impossible.
Go deeper
Related to this question
About these practice questions
One of 524 original PL-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on PL-300
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You have a Power BI dataset that uses a live connection to an Azure Analysis Services (AAS) model. The AAS model has object-level security (OLS) that hides certain measures. Your Power BI report users need to see those measures. What should you do?
medium- A.Use Power BI Desktop object-level security to override AAS settings.
- B.Configure row-level security (RLS) in Power BI to grant access.
- C.Change the dataset to import mode and then apply OLS in Power BI.
- ✓ D.Modify the object-level security roles in Azure Analysis Services to include the measures.
Why D: The correct answer is D: Modify the object-level security roles in Azure Analysis Services to include the measures. Because the Power BI dataset uses a live connection, all security—including OLS that hides measures—is enforced by the AAS model itself, so the only way to expose those measures to report users is to edit the OLS roles in AAS to grant access to them. Power BI cannot override or bypass AAS security in a live connection, so options A and B are ineffective, and option C would require abandoning the live connection and rebuilding the model, which is unnecessary and changes the architecture.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.