Forum Discussion
Access / Security Question
- Anonymous6 months ago
Hi LiquidThinking,
Thank you for reaching out to the Microsoft fabric community forum.
It looks like the difference is mainly coming from the workspace role. When the internal user is set as Viewer, they can open and view the report, but tools like DAX Studio may not show the full semantic model structure. That is why you are only seeing disconnected tables or facing connection issues. When the same user is changed to Contributor or Member, they get higher workspace permissions and the tool can read the full model, so all fact and dimension tables become visible.Since you already confirmed that Build permission is granted and RLS is configured the same, and your external account works without issues, it does not look like a problem with the semantic model itself. It is more likely related to the permission level of the user when accessing the model through external tools. If your internal users need to inspect the model using tools like DAX Studio, they may need Contributor or Member access instead of Viewer. This would explain why it works in one role but not the other.
Kindly refer to the below documentation links for better understanding:
Build Permission for Shared Semantic Models - Power BI | Microsoft LearnHope this helps clarify the behaviour you are seeing. Let us know if you notice anything different after checking with your tenant team.
Regards,
Community support Team.
Hello LiquidThinking
Tabular Editor connects via XMLA to the semantic model. For that to work, yuor workspace must be on Power BI Premium capacity, and the XMLA endpoint for that capacity must be Read or Read/Write.
If your company users are B2B guests, they must switch their Active Directory context to your personal tenant i.e. that hosts the workspace/semantic model, in order to browse via XMLA.
Hello Deborshi,
I'm sorry I meant Dax Studio. When I run this I see the following behaviour:
- External account works correctly
- Internal test user account shows all data when set to Contributor/Member, and cannot connect when set to Viewer
RLS is setup identically for both accounts to enable testing.
I don't think it's an XLMA issue, something to do with the tenant not allowing RLS restrictions ?
Many Thanks,
LiquidThinking
- deborshi_nag6 months ago
Super User
Hello LiquidThinking
DAX Studio also connects to the dataset via the XMLA endpoint. To use tools like DAX Studio or Analyze in Excel, the user must have Build permission on the dataset (Viewer alone is not enough).Grant Build at the dataset level (not workspace Contributor/Member).Power BI Service > Dataset > Manage permissionsGive access to the user(s) > Select Read + BuildEnsure they’re assigned to the appropriate RLS role(s) in the dataset: Dataset > Security > add the user(s) to the RLS role(s).- LiquidThinking6 months agoNew Member
Thanks Deborshi,
Yes, I have done those actions.
I think it is something in the tenant that is causing me the issues - are there any things to typically look for? I am scheduling a call with the company that manages the tenant.
Thanks,
Liquid Thinking
- deborshi_nag6 months ago
Super User
I can't think of anything else to recommened if you've done the above. Check with the other company regarding tenant and let us know how it goes.