Repair identity-to-region access across security paths and roles
A hands-on PL-300 lab. You produce the real artefact and 9 automated checks verify it behaves the way the exam expects.
Try this labAll PL-300 practice
- Certification
- PL-300
- Format
- Structured configuration
- Difficulty
- hard
- Estimated time
- 40 min
- Automated checks
- 9
The brief
Edit row-security.plan.json. roles maps arbitrary role names to predicates plus groups/principals lists. Supported predicates: identity-match uses target {table,column} plus identityFunction userprincipalname/username; entitlement-lookup also supplies mappingKey and mappingIdentity references from one mapping table; static-set uses target and typed values. Predicates within a role intersect; assigned role results union. Either filter Regions by an entitlement lookup, or filter Entitlements by identity and enable the reverse security path on region_entitlement. relationships configures each supplied ID with active, direction single/both and securityBoth. Reverse security needs both and the explicit flag; ordinary Both does not suffice. Keep region_sales active. workspaceGrants maps supplied groups to Viewer/Contributor/Member/Admin; the highest granted role applies and editing roles bypass RLS. Consumers must remain restricted, and the editor must retain full rows and editing. Assign the guest principal directly to the dynamic role using its supplied principal ID; do not assume an unresolved external group authentication path. Remove extra role grants that widen consumers. Keep missing mappings and unassigned Viewers denied while preserving multiple entitlements, authorized zero/null observations and changed populations. Inspect exact IDs, counts, sums, workspace roles and per-role graph receipts, then repair without Reset.
What the checks verify
Your work is graded on 9 independent properties, not on matching one reference answer.
- Compile typed role predicates, memberships, relationship settings and workspace grants.
- Single-region Viewers see only their entitled original observations.
- The multi-region Viewer sees each entitled observation once, despite duplicate mappings.
- Unmapped identities and Viewers lacking an assigned role see no observations.
- Desktop/service, case-variant and actual supplied guest UPN contexts preserve their intended populations.
- Consumers remain restricted while the editing principal retains full rows and edit authority.
- A forbidden-region query and an empty selection do not widen model security.
- A real zero and a null amount preserve their distinct visible row identities, counts and sums.
- Changed region keys, assignments, transaction identities and values produce the new exact authorized populations.
Where this sits in the PL-300 blueprint
- Domain
- Manage and Secure Power BI
- Objective
- Secure and Govern Power BI Items
- Skill
- Row-Level Roles and Membership
Part of PL-300 preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.