Microsoft Certified Power Bi Data Analyst Associate · Free Practice Question Medium
Question 43
You are managing permissions for a shared dataset. Amelia, a Workspace Admin, wants to grant a third-party contractor temporary access to build reports on the dataset.
What steps should she take to achieve this?
-
A
Add the contractor to the workspace with Read access and enable Reshare permissions.
-
B
Share the dataset link with the contractor and ask them to request access.
-
C
Add the contractor to the workspace with Admin access and enable Write permissions.
-
D
Grant the contractor Direct Access with Build permission for the dataset.
Reveal correct answer
Correct answer: D
Explanation
Below are detailed solution explanations for Questions 39, 40, and 41, with the correct answers provided as text at the beginning of each question, following your specified layout and incorporating valid Microsoft documentation references inline.
Question 39: Grant Temporary Access to a Shared Dataset
Correct Answer: Grant the contractor Direct Access with Build permission for the dataset.
Grant Access Step-by-Step
Provide Direct Access with Build Permission
To allow a third-party contractor temporary access to build reports on a shared dataset at BrightLens Analytics, Amelia, as a Workspace Admin, should grant Direct Access with Build permission. In Power BI Service, navigate to the workspace, locate the dataset, click the ellipsis (...), and select "Manage permissions." In the permissions dialog, click "Direct access," enter the contractor’s email, select "Build" from the permissions dropdown, and click "Grant." This allows the contractor to connect to the dataset and create reports without workspace membership, keeping control granular and temporary (access can be revoked later). The Microsoft documentation on managing dataset permissions in Power BI states that "Build permission enables users to create new reports from a dataset without needing workspace access," making this the best approach for Amelia’s needs.
Why Not Other Approaches?
Read Access with Reshare
Adding the contractor to the workspace with Read access and Reshare permissions allows viewing and sharing but not building new reports—Build permission is required separately. The workspace roles documentation clarifies "Read doesn’t include report creation."
Admin Access with Write
Granting Admin access with Write permissions gives excessive control (e.g., editing the dataset), violating the principle of least privilege for a temporary contractor. The admin role documentation warns against overuse.
Share Dataset Link
Sharing a link and asking the contractor to request access shifts the burden to the contractor and doesn’t guarantee immediate Build rights—Amelia must still approve it. The sharing documentation focuses on "view-only sharing."
Additional Considerations
Time Limit: Set a reminder to revoke access post-contract, per the permissions management guidance.
Security: Ensure RLS is in place if the dataset is sensitive.
Final Answer
Amelia should grant the contractor Direct Access with Build permission for the dataset, enabling temporary report-building access without excessive privileges.
A.
Read access only allows viewing content, not building reports.
Reshare allows users to share the dataset but doesn’t help in report creation.
B.
Sharing a link doesn’t grant any actual access unless permissions are explicitly assigned.
It adds unnecessary friction and doesn’t align with proper access provisioning.
C.
This grants the contractor full control, including editing the dataset and managing workspace content.
It exceeds the minimum permissions required, increasing risk and violating least privilege principles.
D.
Giving the contractor Direct Access with Build permission ensures they can create reports based on the dataset without having unnecessary access to edit or manage the dataset itself. This approach offers precise control over access, which is essential for temporary or external users.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
