Courseiva
Manage and secure Power BI →mediumMultiple Choice

PL-300 Manage and secure Power BI Practice Question

You have a Power BI dataset that uses a live connection to an Azure Analysis Services (AAS) model. The AAS model has object-level security (OLS) that hides certain measures. Your Power BI report users need to see those measures. What should you do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the object-level security roles in Azure Analysis Services to include the measures.

Modify the object-level security roles in Azure Analysis Services to include the measures. Because the Power BI dataset uses a live connection, all security—including OLS that hides measures—is enforced by the AAS model itself, so the only way to expose those measures to report users is to edit the OLS roles in AAS to grant access to them. Power BI cannot override or bypass AAS security in a live connection, so options A and B are ineffective, and option C would require abandoning the live connection and rebuilding the model, which is unnecessary and changes the architecture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Power BI Desktop object-level security to override AAS settings.

    Why it's wrong here

    Power BI Desktop's object-level security (OLS) authoring is only available for datasets that are in import mode. For a live connection to Azure Analysis Services, security is inherited entirely from the source tabular model, so any OLS settings you attempt to configure in Power BI Desktop would be ignored or unavailable. The correct place to modify OLS is in the AAS database where the roles are defined, not in the Power BI report layer.

  • ✗

    Configure row-level security (RLS) in Power BI to grant access.

    Why it's wrong here

    Row-level security (RLS) controls which rows of data a user can see, not which measures are visible in a report. On a live connection to Azure Analysis Services, RLS is defined and enforced at the AAS source model; the Power BI RLS authoring pane is disabled for live connections, so you cannot use it to grant access to hidden measures. Granting visibility to specific measures is the job of object-level security (OLS), not RLS.

  • ✗

    Change the dataset to import mode and then apply OLS in Power BI.

    Why it's wrong here

    While changing to import mode would allow applying OLS in Power BI, it is not necessary and would lose the advantages of a live connection. The correct approach is to modify OLS in AAS directly.

  • ✓

    Modify the object-level security roles in Azure Analysis Services to include the measures.

    Why this is correct

    Since the Power BI dataset uses a live connection, it fully relies on the Azure Analysis Services tabular model for security enforcement. To make the measures visible to users, you must edit the object-level security roles in AAS and grant those roles read permission on the measure metadata objects that are currently hidden. This ensures that the measures appear in the field list and are accessible to queries from Power BI for the assigned users.

About these practice questions

This PL-300 question is part of Courseiva's 524-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.