certslothcertsloth
DP-600/Topic 01

Microsoft / Associate

Workspace, Item and Data Security

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Access to the room is different from access to every record.

Must remember

Workspace roles determine collaboration powers across a workspace. Give consumers only the access they need; a broad editing role is not a substitute for a carefully secured app or shared item. Item permissions grant access to a particular lakehouse, warehouse, report or semantic model. Build on a model enables creating downstream content; it is different from merely viewing a report.

Data authorization must cover each path. SQL grants and row/column restrictions protect the SQL interface; file access through OneLake is another path. Semantic-model row-level security filters records; object-level security hides protected model objects. Model RLS applies to consumers under the supported role rules, not as an effective boundary against workspace administrators/editors. Test with the intended identity and its real combination of roles.

Sensitivity labels classify information and can preserve protection in supported export scenarios. Labels do not replace every data-engine permission. Endorsement signals trust: promotion and certification help consumers find approved content, but neither repairs incorrect calculations. Certification is governed by the tenant's configured authority.

Prefer groups over numerous direct user grants. Trace a consumer from report to model to source, including delegated versus fixed connection identity. A report can load while one visual fails because its underlying model or source permission differs. Inspect lineage and audit changes, and validate file, SQL, model and export paths independently.

Choose under exam pressure

Requirement Choice and reason
Only regional rows for report consumers Model RLS with properly scoped consumer permissions.
Protect a salary column from discovery Object/column controls at every supported access path.
Mark a trusted shared model Governed certification, after validation.

Traps

  • A sensitivity label is not a universal SQL/file access control.
  • Workspace editing access can defeat assumptions made for read-only model consumers.

Active recall

1. Workspace role versus item permission?

Broad workspace collaboration versus permission to a particular item.

2. Why test direct file access?

A user might bypass the SQL or semantic-model interface where a restriction was configured.

3. RLS versus OLS?

Allowed rows versus visibility of model objects.

4. Does certification make data correct?

No; it records an organizational trust decision that needs evidence.

5. Why inspect the source connection identity?

Authorization may use a delegated user or a fixed identity, producing different effective access.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.