Validating Dynamic RLS in Power BI

Answer Correct answer: C — Select Test as role to view the report as the HR manager.

You have a semantic model named Model1. Model1 contains five tables that all use Import mode. Model1 contains a dynamic row-level security (RLS) role named HR. The HR role filters employee data so that HR managers only see the data of the department to which they are assigned. You publish Model1 to a Fabric tenant and configure RLS role membership. You share the model and related reports to users. An HR manager reports that the data they see in a report is incomplete. What should you do to validate the data seen by the HR Manager?

  1. Select Test as role to view the data as the HR role.
  2. Filter the data in the report to match the intended logic of the filter for the HR department.
  3. Select Test as role to view the report as the HR manager. Correct Answer
  4. Ask the HR manager to open the report in Microsoft Power BI Desktop.

Community Votes

C
79%
A
21%

79% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the distinction between static and dynamic RLS, where selecting a generic role fails to validate user-specific data access without specifying the user identity.

This question addresses how to troubleshoot incomplete data visibility for users with dynamic row-level security (RLS) roles. The correct approach involves testing the role as a specific user to account for individual filtering logic.

Many learners choose Option A because it references the role name 'HR' directly, missing that dynamic RLS requires impersonating a specific person to see their filtered view.

Community Discussion (22 comments)

[Removed] 👍 16 Selected: C
Although A basically is true as well, C would be "the most" correct. For instance, if the HR manager is not part of the HR role, doing as described in A would not help you troubleshoot the issue. Also, if the RLS is set up such that different HR managers have different rows visible, you have to select the person. Thus, C is more correct than A.
hmntkmr 👍 7
Role name is HR not HR manager so the answer is A.
pk07 👍 1 Selected: A
A. Select Test as role to view the data as the HR role.
AbhiShar 👍 1
Answer is A A. Select Test as role to view the data as the HR role: This option allows you to simulate the RLS settings directly. By testing the role, you can see exactly what data is being presented to users assigned to the HR role, which helps you identify if the filtering logic is correctly implemented and if there are any issues with data visibility. B. Filter the data in the report to match the intended logic of the filter for the HR department: While this might help in analyzing the report data, it does not address whether the RLS is functioning as intended. The filtering in the report might not accurately represent the RLS logic. C. Select Test as role to view the report as the HR manager: This option would allow you to see the report from the perspective of the HR manager, but it may not provide clarity on how the RLS is filtering data specifically. D. Ask the HR manager to open the report in Microsoft Power BI Desktop: This option does not directly help you validate the data as it would not give you insight into the RLS logic being applied.
Pegooli 👍 1 Selected: A
The "Test as role" feature in Power BI allows you to impersonate a role to see the data as a user assigned to that role would see it. This helps in validating the RLS settings and ensuring that the data is being filtered correctly according to the RLS rules.
6d1de25 👍 1 Selected: A
A is the correct answer
ab695 👍 5
Correct answer is C., 100%. The key is in the "dynamic" row-level security. Selecting A. (HR Role only) would work for a static rule for RLS, but as it is dynamic you will need to input as well the HR manager email and make sure the rule is applied correctly.
6d1de25 👍 1 Selected: C
C View as report is correct
tawfik21A 👍 1 Selected: A
role name is HR
b6daab0 👍 1
I chose A because only role and not a specific user can be tested using "Test as role".
c2834e0 👍 2
Theres no role called HR MANAGER !!! Answer is A
282b85d 👍 1 Selected: C
Option C (Select "Test as role" to view the report as the HR manager) is the best approach as it directly validates what the specific HR manager sees under the dynamic RLS conditions, ensuring the completeness and accuracy of the data. A. Select "Test as role" to view the data as the HR role: This option is useful, but it doesn't specify viewing the report as the specific HR manager, which is crucial to identify user-specific issues.
trietnv 👍 2
A. the question is about how to validate role of a user. https://learn.microsoft.com/en-us/power-bi/enterprise/service-admin-rls#validate-the-roles-within-power-bi-desktop
2dc6125 👍 1
what is the difference btw see data (A) or see report (C)?
stilferx 👍 2 Selected: C
IMHO, C) HR Manager is the winner. No HR role, because each HR assigned to the own department.
e0f0ce6 👍 1
You have to check the problem of a particular user. So we should select "C". Maybe the user isn't part of the role. So "A" would achieve nothing.
Unbounded 👍 1 Selected: B
A & C: says "Test" as role. We do not know what conditions we have in Test. To test these conditions we should select B
belha 👍 4 Selected: C
you can test roles on report view , so you can see the report as " " answer is C
a998450 👍 2
first of all he is able to see data but it is incomplete test as hr role will not help to find issue. when he test role as manager then only he will understand the issue
thisiston 👍 3 Selected: A
A. Select Test as role to view the data as the HR role. This option allows you to impersonate the HR role directly within the environment where the data is published, such as Microsoft Power BI Service. By using the "Test as role" feature, you can see exactly what data the HR role (and thus the HR managers) can access according to the dynamic row-level security settings. This method provides a straightforward way to validate the RLS implementation and ensure it is working as intended.
clux 👍 3 Selected: C
A or C, they are very similar
554b579 👍 2
https://learn.microsoft.com/en-us/power-bi/enterprise/service-admin-rls You can test a role or a person ... in this case I would test as the HR Manager

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option C is correct because dynamic Row-Level Security (RLS) relies on user attributes (like email or department) to filter data at runtime. To validate what an HR manager sees, you must use the 'Test as role' feature but specify the actual user (the HR manager). This allows you to see exactly which rows are visible to that specific individual based on the dynamic rules applied to their identity.

Why the Other Options Are Wrong

Option A selects only the role ('HR') without a user context; while valid for static roles, it does not fully simulate the experience of a specific user in a dynamic setup. Option B suggests manually filtering in the report, which is a workaround rather than a validation of the security configuration. Option D is incorrect because opening Power BI Desktop locally does not reflect the published service behavior or RLS membership configured in the tenant.

Community Comment Notes

Community consensus strongly favors C, noting that 'dynamic' implies per-user logic. As one commenter noted, 'Selecting A... would work for a static rule... but as it is dynamic you will need to input as well the HR manager email.' Another user clarified that 'There's no role called HR MANAGER,' emphasizing the need to test as the person, not just the role definition.

Official Reference

Exam Strategy

When troubleshooting RLS issues involving 'dynamic' roles, always look for options that involve testing as a specific user rather than just the role itself. This ensures you are validating the intersection of the role definition and the user's specific attributes.

Frequently Asked Questions

Why can't I just test as the 'HR' role?

Static roles show all data allowed by the role. Dynamic roles require a specific user identity to apply filters correctly, so testing as a user is necessary.

Does 'Test as role' work in Power BI Service?

Yes, administrators can use 'Test as role' in the Power BI Service portal to simulate access for specific users assigned to roles.

Related Analysis

Practice All DP-600 Questions

Access 115 questions with complete answers and detailed explanations.

View Full DP-600 Practice Test →

← Back to DP-600 Study Guide