Publishing an app scopes visibility to RPT1, RPT2, and DB1 while hiding RPT3

Secure and govern Power BI items
Answer Correct answer: A — a published app delivers exactly RPT1, RPT2, and DB1 as read-only content with no SM1 access.

You have a Power BI tenant that contains a workspace named WS1. WS1 contains the following items: • A semantic model named SM1. • A report named RPT1 that is connected to SM1. • A report named RPT2 that is connected to SM1. • A report named RPT3 that is connected to SM1. • A dashboard named DB1 that contains content from RPT1 and RPT2. You need to grant workspace access to a group named Group1. The solution must meet the following requirements: • Group1 must be able to view RPT1, RPT2, and DB1. • Group1 must be prevented from viewing RPT3. • Group1 must be prevented from creating new reports and dashboards by using SM1. • Group1 must be prevented from sharing the reports and dashboards to other users. • Administrative effort must be minimized. What should you do?

  1. Publish an app. Correct Answer
  2. Assign Group1 the Viewer role for WS1.
  3. Store PBIX files in a shared folder in Microsoft OneDrive.
  4. Share each item individually.

Community Votes

A
75%
C
25%

75% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

An app publishes a hand-picked subset of workspace content to an audience — viewers get exactly the chosen reports and dashboard, with no model access and no share rights, all configured once.

Group1 must view RPT1, RPT2, and dashboard DB1 but not RPT3, must not build new content from SM1, must not be able to share onward, and the setup must minimize administrative effort.

Assigning the Viewer workspace role — it exposes every item in WS1 including RPT3, which is the first thing the requirements forbid.

Community Discussion (4 comments)

MANANDAVEY 👍 2 Selected: A
✅ A. Publish an app. Explanation: Publishing an app in Power BI allows you to control which reports and dashboards are accessible to a specific audience while keeping administrative effort minimal. This approach meets all the given requirements: ✅ Group1 can view RPT1, RPT2, and DB1 (you can include only these reports in the app). ✅ Group1 is prevented from viewing RPT3 (since RPT3 will not be included in the app). ✅ Group1 cannot create new reports or dashboards using SM1 (viewers of the app cannot modify the dataset). ✅ Group1 cannot share reports and dashboards (app viewers cannot share content). ✅ Minimal administrative effort (you only need to manage access to the app instead of configuring individual report permissions).
EdExamTopics 👍 2 Selected: A
Publishing an app allows you to selectively include RPT1, RPT2, and DB1 while excluding RPT3. This approach prevents Group1 from creating new reports and dashboards using SM1 and from sharing the content with other users. Additionally, it minimizes administrative effort by providing a centralized way to manage access.
SylUK 👍 2 Selected: C
C is the answer: Store PBIX files in a shared folder in Microsoft OneDrive. because the Group 1 will only view RPT1,RPT2 and DB1. A is wrong because it require an administrative effort. B is also wrong because viewer role will allow Group1 to read all reports in the workspace even RPT3 which is against the requirement. D also needs administrative effort. Therefore C is the correct answer in this context .
b2775a4 👍 2 Selected: A
• Group1 must view specific reports and dashboards (RPT1, RPT2, DB1): • Publishing an app allows you to share selected reports and dashboards with specific groups or users. • Group1 must be prevented from viewing RPT3: • Apps allow fine-grained control, so you can exclude RPT3 from the app content. • Group1 must not create new reports or dashboards or share content: • When users access content via an app, they cannot edit or create new reports/dashboards or share the app itself. • Minimize administrative effort: • Publishing an app is simpler and more manageable than other options.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Publishing an app (A) lets you select precisely which reports and dashboards enter the app — RPT1, RPT2, and DB1 in, RPT3 out. App consumers hold read-only access to that packaged content: they cannot connect to SM1 to author new reports or dashboards, cannot reshare app content, and the single publish action covers the whole group at once, minimizing administrative effort on every requirement.

Why the Other Options Are Wrong

The Viewer role for WS1 (B) grants visibility of all workspace content including RPT3, breaching the exclusion requirement outright. A OneDrive shared folder (C) distributes PBIX files as raw artifacts — recipients could open the model and build from it, violating the no-authoring rule while adding file-management overhead. Sharing each item individually (D) means three separate share operations to maintain, and share links carry reshare options that must be managed per item — the opposite of minimal effort.

Community Comment Notes

A well-endorsed comment explains that publishing an app allows selectively including RPT1, RPT2, and DB1 while excluding RPT3, with no model access and no sharing. The OneDrive camp's reasoning relies on users opening PBIX files, which both breaches the authoring restriction and maximizes administrative effort.

Official Reference

Related Analysis

Practice All PL-300 Questions

Access 116 questions with complete answers and detailed explanations.

View Full PL-300 Practice Test →

← Back to PL-300 Study Guide