Configure Service Account for Power BI XMLA Endpoint Access
You have a Microsoft Power BI Premium Per User (PPU) workspace that contains a semantic model. You have an Azure App Service app named App1 that modifies row-level security (RLS) for the model by using the XMLA endpoint. App1 requires users to sign in by using their Microsoft Entra credentials to access the XMLA endpoint. You need to configure App1 to use a service account to access the model. What should you do first?
Community Votes
80% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests configuring Azure App Service authentication to Power BI via the XMLA endpoint; the common trap is thinking managed identities are added to the Power BI workspace directly.
To configure an Azure App Service to use a service account for Power BI XMLA endpoint access, you must first enable a managed identity on the app. This page explains why adding a managed identity to the App Service is the required first step over other workspace or endpoint configurations.
Choosing to add a managed identity to the workspace, which is incorrect because managed identities are assigned to Azure resources like App Services, not Power BI workspaces.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Adding a managed identity to App1 is the correct first step because it provisions an Azure Active Directory (Entra ID) identity for the Azure App Service. This identity allows the application to authenticate to resources like the Power BI XMLA endpoint without relying on interactive user credentials. Once the managed identity is enabled on App1, it can be granted the necessary permissions in the Power BI workspace.Why the Other Options Are Wrong
Adding a managed identity directly to the workspace (Option A) is invalid because managed identities are features of Azure resources, not Power BI workspaces. Modifying the XMLA Endpoint setting (Option B) does not provision an identity for the application. Upgrading the workspace to Premium capacity (Option C) is unnecessary because the workspace is already Premium Per User (PPU), which supports XMLA endpoint access via service principals.Community Comment Notes
Commenters correctly point out that adding a managed identity to App1 allows it to "authenticate and access resources securely without needing to manage credentials explicitly." Another user accurately dismissed adding a managed identity to the workspace by noting that "Managed identities are associated with Azure resources (e.g., App Services), not directly with Power BI workspaces."Official Reference
Exam Strategy
When asked to configure an Azure App Service to use a service account for Power BI, focus on the Azure resource first. Remember that managed identities are assigned to Azure resources (like App Services) and then added to Power BI workspaces as members, not the other way around.
Related Analysis
Practice All DP-600 Questions
Access 115 questions with complete answers and detailed explanations.
View Full DP-600 Practice Test →