DP-600 - Maintain a Data Analytics Solution - Section 1.1

Implement workspace-level and item-level access controls to secure a Microsoft Fabric analytics solution.

Describe the four workspace roles (Admin, Member, Contributor, Viewer) and the permissions each grants in Microsoft Fabric. Apply item-level sharing and OneLake data access roles to restrict access below workspace level without changing workspace membership.

workspace rolesAdmin Member Contributor Vieweritem-level sharingOneLake data access rolesFabric permission model

Practice question for this objective

Free sampleMaintain a Data Analytics Solutionmedium

A "Lakehouse" in a "Microsoft Fabric" workspace stores several folders of files, and a group of data scientists who already hold the Viewer workspace role must be allowed to read only one specific folder of those files through OneLake, while remaining blocked from the other folders. Which approach grants that folder-scoped read access most directly?

  • APromote the data scientists to the Contributor workspace role so their elevated role lets them reach the single folder they need inside the Lakehouse.
  • BApply row-level security filters on the semantic model built over the Lakehouse so the data scientists only see rows sourced from the permitted folder.
  • CCreate a OneLake data access role on the Lakehouse that grants read permission scoped to the specific folder and assign the data scientists to that role. Correct
  • DUse item-level sharing to share the whole Lakehouse with the data scientists, relying on the share dialog to limit them to the one folder.
OneLake data access roles enforce folder and table scoped read permissions inside a Lakehouse independently of broad workspace roles. OneLake data access roles attach permissions to specific paths within a Lakehouse, so assigning a role scoped to one folder lets those users read that folder while the absence of permission on other folders keeps them blocked.

Why A is wrong: Contributor raises rights across the whole workspace and all Lakehouse data, which over-grants access and still does not scope reading to one folder.

Why B is wrong: Row-level security restricts rows returned by a semantic model, not direct OneLake file access to a folder, so it does not control reading the files themselves.

Why C is correct: OneLake data access roles define read permissions scoped to chosen folders or tables, so a role over just that folder grants exactly the targeted file access required.

Why D is wrong: Sharing the Lakehouse item grants access to the item broadly and the share dialog does not carve out individual folders, so it cannot enforce folder-level scoping.

See more DP-600 practice questions, answers explained.

More in this domain

Back to all Maintain a Data Analytics Solution objectives, or the DP-600 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.