Which Synapse Analytics Role Allows Template Review with Least Privilege?
You have an Azure subscription that contains an Azure Synapse Analytics workspace and a user named User1. You need to ensure that User1 can review the Azure Synapse Analytics database templates from the gallery. The solution must follow the principle of least privilege. Which role should you assign to User1?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests recognition of Synapse-specific RBAC hierarchy versus broader storage or admin roles, with the common trap being over-provisioning by selecting Contributor or Administrator when only read-only gallery access is required.
This question evaluates understanding of Azure Synapse Workspace built-in roles and the principle of least privilege. The community unanimously confirms that assigning the Synapse User role provides the exact minimum permissions needed to browse database templates without granting unnecessary write or administrative capabilities.
Selecting Synapse Contributor or Synapse Administrator, as candidates frequently assume that managing resources is necessary for basic workspace navigation, completely overlooking the explicit least-privilege constraint in the scenario.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The Synapse User role is explicitly designed for end-users who require read and execute permissions within the Synapse workspace environment. Microsoft documentation confirms that this built-in role grants access to explore workspace resources, including the Azure Synapse Studio gallery where database templates are hosted. Assigning it strictly satisfies the least privilege requirement by enabling template review while blocking any modification or deployment actions.Why the Other Options Are Wrong
Synapse Administrator and Synapse Contributor roles grant excessive privileges, including the ability to create, update, and delete pipelines, notebooks, and databases, which directly violates the security constraint. Storage Blob Data Contributor operates at the Azure Data Lake Storage level rather than the Synapse workspace UI layer, meaning it controls raw data access but does not govern gallery visibility or Synapse Studio interactions. These roles are intended for developers and infrastructure engineers, not users requiring simple template browsing.Community Comment Notes
Multiple verified exam takers confirmed option D as correct, noting its appearance on recent DP-203 administrations. Comment [2] and [4] reference the official Microsoft RBAC documentation, clarifying that Synapse User is the baseline role for workspace exploration and template viewing without management rights. Candidates also emphasized that while higher roles technically allow template access, they fail the compliance requirement, making D the only architecturally sound choice.Official Reference
Exam Strategy
When a scenario explicitly mandates the principle of least privilege, immediately eliminate administrator and contributor roles unless resource creation or modification is requested. Match the exact action described in the prompt to the lowest-privileged built-in role that natively supports that functionality, such as User or Reader, rather than assuming elevated permissions are necessary.