Forum Discussion
Access / Security Question
- Anonymous6 months ago
Hi LiquidThinking,
Thank you for reaching out to the Microsoft fabric community forum.
It looks like the difference is mainly coming from the workspace role. When the internal user is set as Viewer, they can open and view the report, but tools like DAX Studio may not show the full semantic model structure. That is why you are only seeing disconnected tables or facing connection issues. When the same user is changed to Contributor or Member, they get higher workspace permissions and the tool can read the full model, so all fact and dimension tables become visible.Since you already confirmed that Build permission is granted and RLS is configured the same, and your external account works without issues, it does not look like a problem with the semantic model itself. It is more likely related to the permission level of the user when accessing the model through external tools. If your internal users need to inspect the model using tools like DAX Studio, they may need Contributor or Member access instead of Viewer. This would explain why it works in one role but not the other.
Kindly refer to the below documentation links for better understanding:
Build Permission for Shared Semantic Models - Power BI | Microsoft LearnHope this helps clarify the behaviour you are seeing. Let us know if you notice anything different after checking with your tenant team.
Regards,
Community support Team.
Thanks,
1. I'm in Fabric - when you say select Dataset is that the same as the Semantic Model?
2. I have granted Build in the Manage Permissions for the Semamtic Model - do I need to do that elsewhere as well?
3. How do I do that please?
4. The RLS works for my external account but not for internal ones, even though they are setup identically
Thanks for your assistance
Hello LiquidThinking,
In Fabric, the dataset = Semantic Model, so permissions are managed the same way.
Grant Build permission via Fabric → Workspace → Semantic Model → Manage Permissions to let users see all tables in Tabular Editor.
Check RLS roles for internal users; they may need to sign out/in to refresh permissions.
After this, internal users will see all tables and have RLS applied correctly.
Grant Build Permission in Microsoft Fabric
- LiquidThinking6 months agoNew Member
Thank you - that makes sense, the terminology threw me.
Yes, I've done all that - but the internal account can't see the data/tables when it is a Viewer (but can when it is a Contributor).
My external account has no issues.
Thanks,
Liquid Thinking