Dynamic RLS USERNAME() Blank Result Fix

Answer Correct answer: A — Adding user objects to the synced list in Microsoft Entra Connect ensures identities exist in Entra ID, allowing USERNAME() to return the UPN.

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen. Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com that syncs with a Microsoft Entra tenant by using Microsoft Entra Connect. You have a Fabric tenant that contains a semantic model. You enable dynamic row-level security (RLS) for the model and deploy the model to the Fabric service. You query a measure that includes the USERNAME() function, and the query returns a blank result. You need to ensure that the measure returns the user principal name (UPN) of a user. Solution: You add user objects to the list of synced objects in Microsoft Entra Connect. Does this meet the goal?

  1. Yes Correct Answer
  2. No

Community Votes

A
60%
B
40%

60% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of identity synchronization prerequisites for dynamic row-level security; the trap is confusing sync scope with DAX functions.

Resolving blank results from the USERNAME() function in Power BI semantic models by ensuring user UPNs are synchronized to Microsoft Entra ID via Entra Connect.

Selecting No and suggesting USERPRINCIPALNAME(); while USERPRINCIPALNAME() is often preferred, the root cause of a blank result is missing identity data in the cloud directory, not just the DAX function choice.

Community Discussion (5 comments)

Mhunity 👍 6 Selected: A
Key Points for Evaluation: The USERNAME() function in Power BI returns the UPN of the logged-in user, which corresponds to the user's identity in Microsoft Entra ID (Azure AD). If the query returns a blank result, it indicates: Either the UPN is not properly synced between AD DS and Microsoft Entra ID. Or the user object is missing from the sync configuration. By adding the user objects to the list of synced objects in Microsoft Entra Connect: The UPNs for the users will be synced from AD DS to Microsoft Entra ID. This ensures that the USERNAME() function can retrieve the UPN correctly. Does the solution meet the goal? Yes. Adding the user objects to the sync configuration in Microsoft Entra Connect ensures that the UPNs are available in Microsoft Entra ID, allowing the USERNAME() function to return the correct result.
MultiCloudIronMan 👍 5 Selected: B
To ensure that the measure returns the user principal name (UPN) of a user, you need to make sure that the USERNAME() function is correctly configured to retrieve the UPN. This typically involves ensuring that the UPN is correctly mapped and available in the data model.
VojtechSima 👍 1 Selected: B
I think it should be No. You should use USERPRINCIPALNAME(), if you want to make sure, you get always UPN.
Stants 👍 3 Selected: A
The answer is A: Yes Here's why: The USERNAME() function requirement: USERNAME() returns the UPN of the current user UPN is needed for dynamic RLS to work properly UPN must be available in Microsoft Entra ID Microsoft Entra Connect sync: By default, not all user attributes might be synced User objects need to be explicitly included in sync configuration UPN is a critical attribute for user identification Why this solution works: Adding user objects to sync ensures UPN attributes are synchronized Ensures proper user identity flow from AD DS to Microsoft Entra ID Enables USERNAME() function to retrieve the correct UPN Completes the identity chain needed for dynamic RLS
e810eb0 👍 1
Here should be Yes

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The USERNAME function relies on the authenticated user's identity being present and valid within the target service (Microsoft Entra ID). If the query returns a blank result, it indicates that the user object does not exist or lacks the necessary attributes in the cloud tenant. By adding user objects to the list of synced objects in Microsoft Entra Connect, you ensure that the user account exists in Entra ID with its attributes (including UPN) populated. This allows the authentication flow to succeed and the USERNAME function to return the correct value.

Why the Other Options Are Wrong

Choosing "No" implies that syncing users is incorrect or insufficient. While some experts argue that USERPRINCIPALNAME is more explicit than USERNAME, the fundamental issue causing a blank result is the absence of the user in the identity store. Without the user object in Entra ID, no DAX function will return a valid UPN. Therefore, fixing the sync configuration is the primary and correct step to resolve the connectivity/identity gap.

Community Comment Notes

Community feedback is split, with many voting for 'Yes' based on the logic that identity must be present first. One commenter noted that USERPRINCIPALNAME should be used to ensure UPN retrieval, but this overlooks the prerequisite of having the user object synced. Another comment affirmed the 'Yes' answer, highlighting that default sync settings might exclude certain users or attributes, requiring explicit inclusion.

Official Reference

Exam Strategy

When troubleshooting blank values in RLS functions, always check the identity layer first. Ensure the user is synced and has the required claims before optimizing the DAX measure.

Frequently Asked Questions

Why does USERNAME() return blank if the user is in AD?

Because the user object must be synced to Microsoft Entra ID. If it's not in the sync list, it doesn't exist in the cloud identity store.

Is USERPRINCIPALNAME() better than USERNAME()?

USERPRINCIPALNAME() is often safer for clarity, but both require the user to be successfully authenticated and present in the directory.

Related Analysis

Practice All DP-600 Questions

Access 115 questions with complete answers and detailed explanations.

View Full DP-600 Practice Test →

← Back to DP-600 Study Guide