Repair identity-to-region access across security paths and roles

A hands-on PL-300 lab. You produce the real artefact and 9 automated checks verify it behaves the way the exam expects.

Try this labAll PL-300 practice

Certification
PL-300
Format
Structured configuration
Difficulty
hard
Estimated time
40 min
Automated checks
9

The brief

Edit row-security.plan.json. roles maps arbitrary role names to predicates plus groups/principals lists. Supported predicates: identity-match uses target {table,column} plus identityFunction userprincipalname/username; entitlement-lookup also supplies mappingKey and mappingIdentity references from one mapping table; static-set uses target and typed values. Predicates within a role intersect; assigned role results union. Either filter Regions by an entitlement lookup, or filter Entitlements by identity and enable the reverse security path on region_entitlement. relationships configures each supplied ID with active, direction single/both and securityBoth. Reverse security needs both and the explicit flag; ordinary Both does not suffice. Keep region_sales active. workspaceGrants maps supplied groups to Viewer/Contributor/Member/Admin; the highest granted role applies and editing roles bypass RLS. Consumers must remain restricted, and the editor must retain full rows and editing. Assign the guest principal directly to the dynamic role using its supplied principal ID; do not assume an unresolved external group authentication path. Remove extra role grants that widen consumers. Keep missing mappings and unassigned Viewers denied while preserving multiple entitlements, authorized zero/null observations and changed populations. Inspect exact IDs, counts, sums, workspace roles and per-role graph receipts, then repair without Reset.

What the checks verify

Your work is graded on 9 independent properties, not on matching one reference answer.

  • Compile typed role predicates, memberships, relationship settings and workspace grants.
  • Single-region Viewers see only their entitled original observations.
  • The multi-region Viewer sees each entitled observation once, despite duplicate mappings.
  • Unmapped identities and Viewers lacking an assigned role see no observations.
  • Desktop/service, case-variant and actual supplied guest UPN contexts preserve their intended populations.
  • Consumers remain restricted while the editing principal retains full rows and edit authority.
  • A forbidden-region query and an empty selection do not widen model security.
  • A real zero and a null amount preserve their distinct visible row identities, counts and sums.
  • Changed region keys, assignments, transaction identities and values produce the new exact authorized populations.

Where this sits in the PL-300 blueprint

Domain
Manage and Secure Power BI
Objective
Secure and Govern Power BI Items
Skill
Row-Level Roles and Membership

Part of PL-300 preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.