Assigning an RLS role to a Mail-enabled group rather than a Microsoft 365 group

Secure and govern Power BI items
Answer Correct answer: A — Group2, as a mail-enabled group, is a documented supported member type for an RLS role.

You have a Microsoft 365 subscription that contains the resources shown in the following table. You create a new dashboard that uses row-level security (RLS) filters. You define a new role named Consultants. To which resource can you assign the Consultants role? - image

  1. Group2 Correct Answer
  2. Team1
  3. Sales reports
  4. Group1

Community Votes

A
67%
C
33%

67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Microsoft documents that RLS role membership accepts distribution groups, mail-enabled groups, and Microsoft Entra security groups — Microsoft 365 groups and Teams teams are explicitly unsupported, and roles attach to semantic models, not to workspaces or reports.

A dashboard uses row-level security with a new Consultants role, and the resources on offer are a Microsoft 365 group, a mail-enabled group, a Teams org-wide team, and the Power BI workspace itself.

Assigning the role to the workspace or to whichever group contains the consultants by description — the group's type decides eligibility, and a Microsoft 365 group fails that test regardless of membership.

Community Discussion (20 comments)

Endeetheanalyst 👍 17
Sales Report
627628c 👍 7 Selected: A
A. Group 2. Per Microsoft Learn, here's why: "You can use the following groups to set up row-level security: Distribution Group Mail-enabled Group Microsoft Entra Security Group Note that Microsoft 365 groups aren't supported and can't be added to any roles." https://learn.microsoft.com/en-us/fabric/security/service-admin-row-level-security Because of this, it should be Group 2.
b92fc92 👍 1 Selected: C
C in my opinion
b92fc92 👍 1 Selected: C
C in my opinion
5bf040d 👍 1 Selected: A
In the Power BI service, you can add a member to the role by typing in the email address or name of the user or security group. You can't add Groups created in Power BI. You can add members external to your organization. In the Power BI Service, you can create workspaces and groups to organize and share reports, dashboards, and datasets. However, these Power BI workspace groups (or app workspace groups) are not the same as security groups (e.g., Microsoft Entra Security Groups, Distribution Groups, or Mail-enabled Groups). Power BI workspace groups (created in the Power BI Service) cannot be assigned to RLS roles. https://learn.microsoft.com/en-us/fabric/security/service-admin-row-level-security
a5de5a2 👍 1 Selected: D
Group1 is a Microsoft 365 group, which supports RLS role assignment. and its answered by chatGPT
namuuu 👍 1 Selected: C
Justifies the questions
lmml_et 👍 2 Selected: A
https://learn.microsoft.com/en-us/fabric/security/service-admin-row-level-security#manage-security-on-your-model
desibaby09 👍 2 Selected: C
Sales reports RLS is implemented at the dataset level within Power BI workspaces.
irena.petkovich 👍 3 Selected: A
You can use the following groups to set up row level security. Distribution Group Mail-enabled Group Security Group Note, however, that Office 365 groups are not supported and cannot be added to any roles.
jaume 👍 1 Selected: B
Office 365 Groups without mail-enabled security features cannot be directly used to manage roles in Power BI, as they lack the necessary integration for permissions
LuluSkyy 👍 3
I agree the answer is sales report
El_Montasser89 👍 3
Answer is A! https://learn.microsoft.com/en-us/fabric/security/service-admin-row-level-security#add-members
Davery 👍 2 Selected: C
Roles are assigned in PowerBI Service which means the answer must be C sales reports
d5e1798 👍 1
group 1
LuluSkyy 👍 1
what's the correct answer then?
b92fc92 👍 1 Selected: C
why not C?
Monsta 👍 3 Selected: A
Group 1 is the right answer
a638741 👍 3
I think the answer is D:Group 1 as it's a MS 365 group that you can assign not a Mail enabled group
jiheneB 👍 1
Why A ?

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The resources table shows Group2 is a mail-enabled group containing all consultants. Microsoft's row-level security documentation lists the supported group types for role membership as distribution groups, mail-enabled groups, and Microsoft Entra security groups, so the Consultants role can be assigned to Group2 directly and every consultant inherits the role.

Why the Other Options Are Wrong

Group1 is a Microsoft 365 group, and the same documentation explicitly notes Microsoft 365 groups are not supported for RLS role membership. Team1 is a Microsoft Teams org-wide team, which is also not among the supported types and additionally contains all employees, not just consultants. Sales reports is a Power BI workspace — roles are defined and assigned on the semantic model level, not on a workspace or report object, and the consultants already hold Viewer on that workspace anyway.

Community Comment Notes

A well-endorsed comment quotes the Microsoft Learn passage enumerating distribution, mail-enabled, and security groups while excluding Microsoft 365 groups, which settles the choice of Group2. Another comment answering Sales reports confuses role assignment (semantic model scope) with workspace access, which the question already covers separately.

Official Reference

Related Analysis

Practice All PL-300 Questions

Access 116 questions with complete answers and detailed explanations.

View Full PL-300 Practice Test →

← Back to PL-300 Study Guide