Assigning Workspace Roles to Security Groups
You have a Power BI workspace named Sales. You need to ensure that only users in the Finance security group can view reports in this workspace, while members of the Sales team can edit and share content. What should you do?
Quick Answer
Assigning Finance as Viewer and Sales as Member is the answer because Power BI workspace roles are built as a ladder of increasing permission, and this scenario asks for two very different points on that ladder for two different groups. Viewer sits at the bottom and grants read-only access, which is exactly what Finance needs since they should only view reports, not change anything. Member sits higher up and grants both editing and sharing rights, matching the Sales team's need to build out and distribute content. The distractor roles fail for specific, testable reasons rather than vague overreach: Contributor allows editing but cannot share content, so it would leave Sales unable to do part of what the scenario requires; Admin grants full control including managing workspace permissions and membership, which goes well beyond what either group needs and introduces unnecessary risk; and row-level security operates inside a report to filter which data rows a user sees, which is a completely different mechanism from workspace roles that control what a user can do with the workspace itself. When you see a scenario describing different groups needing different levels of access to the same workspace, map each group's required actions -- view only, or view plus edit plus share -- directly onto the specific role that grants exactly that and nothing more.
⚠ Common exam trap
A common trap is confusing Contributor with Member. Contributor can edit but not share, while Member can both edit and share. Also, a candidate might think Viewer is insufficient for Finance, but it correctly restricts access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add Finance as Viewer, Sales as Member.
Workspace roles in Power BI are designed to grant specific permissions: Viewer allows read-only access, ideal for Finance who only need to view reports; Member allows editing and sharing, which matches the Sales team's requirements. Option B is wrong because Contributor role cannot share content, which Sales needs. Option C is wrong because Admin grants full control, including managing permissions, which is unnecessary and excessive. Option D is wrong because row-level security (RLS) controls data access within reports, not workspace-level permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add Finance as Viewer, Sales as Member.
Why this is correct
Assigning Finance the Viewer role grants read-only report access, while the Sales team as Members can edit and share content. This satisfies both constraints simultaneously, since workspace roles govern exactly these permissions without broader tenant-level access.
- ✗
Add Finance as Contributor, Sales as Member.
Why it's wrong here
Contributor grants edit rights, so Finance could modify content, not merely view it; the requirement is read-only access. Viewer is the role that permits viewing without editing, and Contributor tempts because it is the natural choice when someone needs to work in a workspace rather than just consume its reports.
- ✗
Add Finance as Viewer, Sales as Admin.
Why it's wrong here
Granting Sales the Admin role exceeds the requirement: Admin confers full workspace control, including adding or removing members and deleting the workspace, whereas editing and sharing content needs only Member. It tempts because Admin does grant edit and share rights, and would suit a scenario requiring full workspace ownership rather than collaborative authoring.
- ✗
Use row-level security to restrict Finance data, add both as Member.
Why it's wrong here
Row-level security filters rows within a dataset; it cannot grant or deny workspace viewing rights, so Finance members would still see all reports. Workspace roles control that access. RLS suits restricting which records a viewer sees inside a report, not gating report visibility between groups.
Go deeper
Related to this question
About these practice questions
This PL-300 question is part of Courseiva's 524-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on PL-300
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You need to ensure that only members of the 'Sales' security group can edit reports in the 'Sales Reports' workspace. The workspace currently has four members: three from Sales and one from Marketing. What should you do?
easy- ✓ A.Add the Sales security group as a workspace Admin and remove the Marketing user.
- B.Configure the workspace to allow only specific users to edit by using the 'Restrict editing' option.
- C.Publish the reports to a Power BI app and grant the Sales group 'Build' permissions.
- D.Assign the Sales security group the 'Contributor' role and keep the Marketing user as 'Member'.
Why A: Adding the Sales security group as a workspace Admin grants all its members edit rights, and removing the Marketing user ensures only Sales can edit, satisfying the requirement. Workspace roles in Power BI are Admin, Member, Contributor, and Viewer, and Admin/Member/Contributor can edit content, so the Sales group must hold one of those roles while the Marketing user is removed. This is the cleanest way to enforce group-based edit access.
Variation 2. Refer to the exhibit. You run a PowerShell script to list workspaces and their users. You need to ensure that only members of the sales security group can access the Sales workspace. What should you do?
medium- A.Restore the Marketing workspace and move the reports there.
- B.Add the sales security group as a Contributor to the Sales workspace.
- C.Change the sales security group's role to Viewer.
- ✓ D.Remove the individual users (user1 and user2) from the Sales workspace.
Why D: The correct action is to remove the individual users (user1 and user2) from the Sales workspace (option D), because access to a Power BI workspace is granted through workspace roles, and any user assigned a role such as Admin, Member, Contributor, or Viewer can access the workspace regardless of security group membership. To ensure that only members of the sales security group can access the Sales workspace, you must eliminate the direct role assignments of user1 and user2, then grant access solely via the sales security group. Option A is irrelevant because restoring the Marketing workspace and moving reports does not affect Sales workspace permissions. Option B would grant the sales security group access but would not restrict the existing individual users, so it fails the requirement. Option C changes the sales security group's role to Viewer, which still leaves user1 and user2 with access and also may not match the intended permission level.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.