Configure Service Account for Power BI XMLA Endpoint Access

Answer Correct answer: D — Add a managed identity to App1 to allow it to authenticate to the XMLA endpoint using a service account.

You have a Microsoft Power BI Premium Per User (PPU) workspace that contains a semantic model. You have an Azure App Service app named App1 that modifies row-level security (RLS) for the model by using the XMLA endpoint. App1 requires users to sign in by using their Microsoft Entra credentials to access the XMLA endpoint. You need to configure App1 to use a service account to access the model. What should you do first?

  1. Add a managed identity to the workspace.
  2. Modify the XMLA Endpoint setting.
  3. Upgrade the workspace to Premium capacity.
  4. Add a managed identity to App1. Correct Answer

Community Votes

D
80%
C
20%

80% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests configuring Azure App Service authentication to Power BI via the XMLA endpoint; the common trap is thinking managed identities are added to the Power BI workspace directly.

To configure an Azure App Service to use a service account for Power BI XMLA endpoint access, you must first enable a managed identity on the app. This page explains why adding a managed identity to the App Service is the required first step over other workspace or endpoint configurations.

Choosing to add a managed identity to the workspace, which is incorrect because managed identities are assigned to Azure resources like App Services, not Power BI workspaces.

Community Discussion (4 comments)

MultiCloudIronMan 👍 6 Selected: D
Adding a managed identity to App1 will allow it to authenticate and access resources securely without needing to manage credentials explicitly. This is the first step in configuring the app to use a service account for accessing the model via the XMLA endpoint.
aks2304 👍 1 Selected: D
To configure App1 to use a service account to access the model, you should add a managed identity to App1. Managed identities provide an automatically managed identity in Azure Active Directory for applications to use when connecting to resources that support Azure AD authentication, such as the Power BI XMLA endpoint So, the correct answer is D. Add a managed identity to App1.
Bumstar1 👍 2 Selected: C
A. Add a managed identity to the workspace. Incorrect. Managed identities are associated with Azure resources (e.g., App Services), not directly with Power BI workspaces. B. Modify the XMLA Endpoint setting. Incorrect. While XMLA endpoints are required, modifying their settings alone won't enable service account access for App1. C. Upgrade the workspace to Premium capacity. Correct. To use a service account (managed identity or service principal), the workspace must be in Premium capacity. PPU does not support service principal authentication. D. Add a managed identity to App1. Incorrect. While adding a managed identity is necessary for App1, this step comes after ensuring the workspace supports service principal authentication, which requires Premium capacity.
shorymor 👍 1 Selected: D
Answer seems correct!

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Adding a managed identity to App1 is the correct first step because it provisions an Azure Active Directory (Entra ID) identity for the Azure App Service. This identity allows the application to authenticate to resources like the Power BI XMLA endpoint without relying on interactive user credentials. Once the managed identity is enabled on App1, it can be granted the necessary permissions in the Power BI workspace.

Why the Other Options Are Wrong

Adding a managed identity directly to the workspace (Option A) is invalid because managed identities are features of Azure resources, not Power BI workspaces. Modifying the XMLA Endpoint setting (Option B) does not provision an identity for the application. Upgrading the workspace to Premium capacity (Option C) is unnecessary because the workspace is already Premium Per User (PPU), which supports XMLA endpoint access via service principals.

Community Comment Notes

Commenters correctly point out that adding a managed identity to App1 allows it to "authenticate and access resources securely without needing to manage credentials explicitly." Another user accurately dismissed adding a managed identity to the workspace by noting that "Managed identities are associated with Azure resources (e.g., App Services), not directly with Power BI workspaces."

Official Reference

Exam Strategy

When asked to configure an Azure App Service to use a service account for Power BI, focus on the Azure resource first. Remember that managed identities are assigned to Azure resources (like App Services) and then added to Power BI workspaces as members, not the other way around.

Related Analysis

Practice All DP-600 Questions

Access 115 questions with complete answers and detailed explanations.

View Full DP-600 Practice Test →

← Back to DP-600 Study Guide