How to Implement Row-Level Security in Fabric Warehouse?

Answer Correct answer: D, E — Create a FUNCTION to define the filter predicate and a SECURITY POLICY to bind it to Table1.

You have a Fabric warehouse named Warehouse1 that contains a table named Table1. Table1 contains customer data. You need to implement row-level security (RLS) for Table1. The solution must ensure that users can see only their respective data. Which two objects should you create? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  1. DATABASE ROLE
  2. STORED PROCEDURE
  3. CONSTRAINT
  4. FUNCTION Correct Answer
  5. SECURITY POLICY Correct Answer

Community Votes

DE
85%
AE
15%

85% of anonymous learners picked answer DE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Implementing RLS in a Fabric warehouse tests your knowledge of T-SQL security objects, specifically the requirement to create an inline table-valued function and a security policy to enforce the filter.

Implementing row-level security (RLS) in a Microsoft Fabric warehouse requires creating a filter predicate function and a security policy. This page explains why FUNCTION and SECURITY POLICY are the correct objects to restrict user access to their respective data.

Selecting DATABASE ROLE (A) instead of SECURITY POLICY (E), assuming roles alone enforce the filtering logic rather than just grouping members for the predicate.

Community Discussion (3 comments)

adane 👍 10 Selected: DE
To implement RLS for Table1 in Fabric, create a FUNCTION to define row-filtering logic and a SECURITY POLICY to enforce it. This ensures users only see the rows they are permitted to access.
zmeya 👍 1 Selected: DE
From ChatGPT: The correct answer to implement Row-Level Security (RLS) on a table in Microsoft Fabric Warehouse is: D. FUNCTION E. SECURITY POLICY Explanation: FUNCTION (D): Used to define a security function that filters the rows of the table based on the user's identity or specific criteria. SECURITY POLICY (E): Applies the security function to the table to restrict access to rows according to the defined criteria. This ensures that users can only see the data they are authorized to query, meeting the RLS requirements.
nappi1 👍 2 Selected: AE
correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

To implement row-level security (RLS) in a Fabric warehouse, you must first create an inline table-valued function (FUNCTION) that defines the filter predicate logic, checking session context or user names. Then, you create a SECURITY POLICY that binds this function to the target table, enforcing the filter automatically whenever data is accessed. These two objects work together to restrict users to seeing only their respective rows.

Why the Other Options Are Wrong

DATABASE ROLE (A) is used to group principals who will be subject to the RLS policy, but the role itself does not define or enforce the row filtering. STORED PROCEDURE (B) cannot be used as a filter predicate in a security policy; only an inline table-valued function is supported. CONSTRAINT (C) enforces data integrity (like foreign keys or check constraints) but has no mechanism to filter rows based on user identity.

Community Comment Notes

As adane noted, you must "create a FUNCTION to define row-filtering logic and a SECURITY POLICY to enforce it." Other comments like nappi1's suggestion of "AE" mistakenly substitute the database role for the security policy, confusing role membership with policy enforcement.

Official Reference

Exam Strategy

For RLS questions in Fabric, remember the two-step T-SQL pattern: a predicate function and a security policy. Do not confuse database roles, which merely group users, with security policies, which actually bind the filter logic to tables.

Related Analysis

Practice All DP-600 Questions

Access 115 questions with complete answers and detailed explanations.

View Full DP-600 Practice Test →

← Back to DP-600 Study Guide