Courseiva

PL-300 Row-Level Security (RLS) Practice Question

Your organization uses Power BI with a shared capacity (no Premium capacity). You need to implement row-level security (RLS) on a dataset that is used by multiple reports. Which of the following is a limitation you must consider?

⚠ Common exam trap

The key trap is that while RLS works with DirectQuery in general, when SSO is enabled, the user's identity flows to the source, and Power BI's RLS cannot filter rows—the source must handle security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

RLS cannot be applied when the dataset uses DirectQuery to a data source that requires single sign-on (SSO) because the user's identity is passed through, and the source must enforce RLS.

The correct option is C: RLS cannot be applied when the dataset uses DirectQuery to a data source that requires single sign-on (SSO) because the user's identity is passed through, and the source must enforce RLS. In a shared capacity, Power BI does not perform RLS for DirectQuery sources that use SSO; instead, it passes the user's credentials to the source, so the source system must enforce its own row-level security. Options A, B, and D are incorrect: RLS is supported in shared capacity, roles can be created in Power BI Desktop, and RLS can be applied to DirectQuery tables (with the SSO caveat noted in C).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RLS is not supported in shared capacity; you need a Premium license.

    Why it's wrong here

    RLS is fully supported in shared capacity (i.e., with Power BI Pro or Free licenses) as long as you have permission to publish and share reports. It does not require a Premium (EM or P) capacity license. The Premium misconception may arise because some RLS-related features, like dynamic data masking or the ability to use RLS with XMLA endpoints, might have additional requirements, but basic RLS works in shared capacity for both imported and DirectQuery models.

  • ✗

    RLS roles must be created in the Power BI service after publishing; they cannot be created in Power BI Desktop.

    Why it's wrong here

    RLS roles are actually created in Power BI Desktop using the "Manage Roles" button under the Modeling tab, where you can define DAX expressions like [Email] = USERPRINCIPALNAME(). After publishing the report, you can add or remove users from the role in the Power BI service using the Security settings. Therefore, the statement is incorrect because role definitions are authored in Desktop and only user assignments are managed in the service.

  • ✓

    RLS cannot be applied when the dataset uses DirectQuery to a data source that requires single sign-on (SSO) because the user's identity is passed through, and the source must enforce RLS.

    Why this is correct

    When a DirectQuery dataset connects to a source requiring SSO, Power BI passes the signed-in user's identity to the source database and does not apply static RLS filters from the role. This is because the queries are executed in the source engine under the user's credentials, so the source itself must implement row-level security (e.g., via security predicates). Without SSO, Power BI can still apply RLS to DirectQuery tables by adding filter conditions to the generated queries.

  • ✗

    RLS can only be applied to tables that are imported, not to tables using DirectQuery.

    Why it's wrong here

    This is false. RLS is not restricted to imported tables; it can be defined and applied to tables in a DirectQuery model as long as the connection does not use SSO. In that case, Power BI translates the RLS role filters into WHERE clauses that are sent with each query. However, if the DirectQuery source uses SSO, the user's identity is passed through, and Power BI's RLS roles are ignored, which is why source-level RLS is required.

About these practice questions

One of 524 original PL-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.