Applying DLP Policies to Power BI Fabric Items
You have a Fabric tenant that contains a workspace named Workspace1. Workspace1 contains a single semantic model that has two Microsoft Power BI reports. You have a Microsoft 365 subscription that contains a data loss prevention (DLP) policy named DLP1. You need to apply DLP1 to the items in Workspace1. What should you do?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your understanding of how Microsoft 365 governance tools integrate with Microsoft Fabric; the trap is confusing Fabric-specific endorsements or identities with standard M365 security labels.
To enforce a Microsoft 365 Data Loss Prevention (DLP) policy on Power BI items within a Fabric tenant, you must apply sensitivity labels. This question establishes that sensitivity labels are the bridge between M365 policies and Fabric content.
Candidates often select 'Create a workspace identity' because it sounds like a governance control, but workspace identities manage access, not data classification for DLP enforcement.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Sensitivity labels are the primary mechanism in Microsoft 365 for classifying and protecting data. When a sensitivity label containing DLP rules is applied to a semantic model or report in Power BI/Fabric, the associated DLP policy is enforced on that content. This ensures that sensitive information is protected according to the organization's compliance standards.Why the Other Options Are Wrong
Creating a workspace identity (Option A) manages permissions and access control lists, not data loss prevention. Certified endorsement (Option B) and master data endorsement (Option D) are related to data quality and governance workflows, not security policies or DLP enforcement. These options do not trigger Microsoft 365 DLP actions.Community Comment Notes
Community consensus strongly supports Option C. As user wgaignard2 noted, applying sensitivity labels is the correct method for configuring DLP in Fabric. Another commenter, aks2304, emphasized that sensitivity labels classify data across Microsoft 365 services, including Power BI, making them essential for DLP integration.Official Reference
Exam Strategy
Always look for 'Sensitivity Labels' when a question involves applying Microsoft 365 security policies (like DLP or encryption) to specific assets like files, emails, or reports. In Fabric, these labels extend M365 capabilities to analytical workloads.
Frequently Asked Questions
Why doesn't creating a workspace identity apply DLP?
Workspace identities manage access permissions and role assignments, not data classification or security policies like DLP.
Can I apply DLP directly without sensitivity labels?
No, in Microsoft 365 and Fabric, DLP policies are typically triggered and enforced through the application of sensitivity labels to the content.
Related Analysis
Practice All DP-600 Questions
Access 115 questions with complete answers and detailed explanations.
View Full DP-600 Practice Test →