DP-700 · Access Control and Data Masking
17 cards
Workspace and Item Access Controls
-
Quick check
A colleague is granted an item permission on one lakehouse. What does that grant reach?
AEvery item stored inside the same workspace
That is the reach of a workspace role, which covers all content in the workspace rather than a single item.
BThat one Fabric item and nothing else
Right. An item permission is confined to the item it was granted on and does not apply to other items.
CEvery workspace running on the same capacity
Nothing in this permission model spreads across a capacity; even a workspace role stops at its own workspace.
2 / 17
-
Quick check
An engineer must view and modify every item in one workspace, but must not be able to share content or manage permissions. Which role fits?
AContributor
Right. Contributor is the least privileged role that can modify all workspace content, and it stops short of sharing and permission management.
BViewer
Viewer can see all content but cannot perform the modifications the requirement asks for.
CAdmin
Admin adds both sharing and permission management, so it breaks the two stated limits at once.
5 / 17
-
Quick check
A regional lead must modify and share every item in the region's workspace, must not manage its permissions, and must not reach other regions. What should you assign?
AAdmin in the regional workspace
Admin covers the content work but also grants permission management, which the requirement excludes.
BContributor in every regional workspace
Contributor cannot share content, and assigning it everywhere breaks the regional boundary as well.
CMember in the regional workspace
Right. Member allows modifying and sharing content, and a workspace role reaches only its own workspace.
7 / 17
-
Keep your progress in the app
That’s 3 of 7 quick checks. In the app they stay answered, and every lesson remembers where you left off.
-
Quick check
A contractor with no workspace role needs one report and must not be able to browse the rest of the workspace. What do you do?
AShare the report with the contractor
Right. A direct share gives access to that single item through its link, and no workspace role is created by it.
BAssign Viewer across the whole workspace
Viewer would open every item in the workspace, which is exactly the browsing the requirement rules out.
CAssign Contributor across the whole workspace
Contributor would expose all workspace content and additionally allow modifying it, far past the requirement.
9 / 17
-
Quick check
An external analyst must open a shared DirectLake report and query its Delta tables directly, while the rest of the workspace stays closed. Which pair of grants fits?
AWorkspace Viewer plus item Read on the report itself
Viewer opens every item in the workspace, and item Read still would not authorize a direct query against the tables.
BItem Read on the report plus Reshare on it
Reshare only lets the analyst pass the report on; neither of these permissions reaches the underlying data.
CItem Read plus OneLake permission on the tables
Right. The item grant opens the report, the OneLake grant allows the direct table queries, and no other item is exposed.
12 / 17
-
Quick check
A departing collaborator holds both a direct grant on a report and Viewer in its workspace, and must lose the link and all workspace visibility. What change achieves that?
ARemove the direct report grant and keep the Viewer role
Viewer would still show the report, and every other item in that workspace, from inside the workspace.
BRemove the direct report grant and the Viewer role
Right. Both access paths are independent, so both the item grant and the workspace role have to go.
CKeep the direct report grant and remove Viewer
The direct grant would keep the shared link working even with the workspace role gone.
15 / 17
-
Quick check
Which statement correctly separates the workspace boundary from the item boundary?
AA workspace role covers all items in its workspace, while item Read opens one item without opening its data layer
Right. The role is workspace-wide, the item permission is item-scoped, and item Read stops short of SQL and OneLake data.
BAn item permission spreads to every item in the tenant, while a workspace role covers a single report
The scopes are reversed: item permissions stay on one item and workspace roles cover the workspace they are assigned to.
CSharing an item raises the recipient's workspace role, so one grant is always enough
Sharing leaves workspace roles untouched, which is exactly why two separate paths can exist at once.
17 / 17
-
7 quick checks · then the test
In the app, finishing the quick checks opens this lesson’s 10-question test, and the ones you miss come back exactly when you’re about to forget them.
The whole course, on your phone
Lessons you can read, audio you can listen to on the way to work, and practice that remembers what you got wrong.