How to Implement Row-Level Security in Fabric Warehouse?
You have a Fabric warehouse named Warehouse1 that contains a table named Table1. Table1 contains customer data. You need to implement row-level security (RLS) for Table1. The solution must ensure that users can see only their respective data. Which two objects should you create? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Community Votes
85% of anonymous learners picked answer DE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Implementing RLS in a Fabric warehouse tests your knowledge of T-SQL security objects, specifically the requirement to create an inline table-valued function and a security policy to enforce the filter.
Implementing row-level security (RLS) in a Microsoft Fabric warehouse requires creating a filter predicate function and a security policy. This page explains why FUNCTION and SECURITY POLICY are the correct objects to restrict user access to their respective data.
Selecting DATABASE ROLE (A) instead of SECURITY POLICY (E), assuming roles alone enforce the filtering logic rather than just grouping members for the predicate.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To implement row-level security (RLS) in a Fabric warehouse, you must first create an inline table-valued function (FUNCTION) that defines the filter predicate logic, checking session context or user names. Then, you create a SECURITY POLICY that binds this function to the target table, enforcing the filter automatically whenever data is accessed. These two objects work together to restrict users to seeing only their respective rows.Why the Other Options Are Wrong
DATABASE ROLE (A) is used to group principals who will be subject to the RLS policy, but the role itself does not define or enforce the row filtering. STORED PROCEDURE (B) cannot be used as a filter predicate in a security policy; only an inline table-valued function is supported. CONSTRAINT (C) enforces data integrity (like foreign keys or check constraints) but has no mechanism to filter rows based on user identity.Community Comment Notes
As adane noted, you must "create a FUNCTION to define row-filtering logic and a SECURITY POLICY to enforce it." Other comments like nappi1's suggestion of "AE" mistakenly substitute the database role for the security policy, confusing role membership with policy enforcement.Official Reference
Exam Strategy
For RLS questions in Fabric, remember the two-step T-SQL pattern: a predicate function and a security policy. Do not confuse database roles, which merely group users, with security policies, which actually bind the filter logic to tables.
Related Analysis
Practice All DP-600 Questions
Access 115 questions with complete answers and detailed explanations.
View Full DP-600 Practice Test →