Memory hook: Share the item; secure the rows; verify as the viewer.
Must remember
Workspaces organize collaboration and roles. Admin, Member and Contributor permissions enable different management/editing capabilities; Viewer is a consumption role. Apps package content for audiences, while direct sharing and workspace access serve different distribution needs. Licensing/capacity affects who can consume which content, so access permission alone may not be sufficient.
Publish and update reports/semantic models deliberately; dependent reports may reuse a shared model. Dashboards combine pinned tiles, while reports provide interactive pages. Subscriptions send scheduled snapshots/notifications under supported settings; data alerts have supported visual/data requirements. Promotion indicates useful content; certification follows organizational governance rather than proving every calculation correct.
Scheduled refresh needs valid source credentials and, for appropriate private/on-premises sources, a configured gateway with reachable sources and mappings. Check refresh history, failures and source/schema changes. Gateway installation alone does not make every source available. DirectQuery and Direct Lake have different data-access/refresh behavior from Import.
Row-level security (RLS) filters model rows according to roles and identity, often using a user-to-entity mapping. Define and test roles, assign eligible users/groups, and verify effective behavior in the service. RLS is intended for consumers such as Viewers; workspace users with edit permissions are not constrained in the same way. Multiple role memberships can broaden allowed data.
Sensitivity labels classify/protect supported content and downstream handling; they do not replace all access permissions or RLS. Build permission, item sharing and model access are distinct capabilities. Test exports and Analyze in Excel-style consumption under the actual user identity before declaring data protected.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Publish curated content to many consumers | A suitable app/audience and licensing model. |
| Each salesperson sees only their region | RLS with tested identity mapping and consumer permissions. |
| Refresh cannot reach an on-premises database | Check gateway, source mapping, credentials and network path. |
Traps
- RLS is not a substitute for restricting workspace edit permissions.
- Certification/endorsement is a governance signal, not mathematical proof.
Active recall
1. Report versus dashboard?
Interactive report pages versus a service canvas of pinned tiles/content.
2. Why test as a Viewer?
Admin/editor access can bypass the consumer restrictions you intend to validate.
3. What does a gateway provide?
A controlled connection path to supported otherwise unreachable data sources.
4. Can several RLS roles broaden access?
Yes; role combinations can allow more rows than expected.
5. Does a sensitivity label grant data access?
No; classification/protection and authorization are different controls.