Forum Discussion

Jessy_D's avatar
Jessy_D
Helper I
8 months ago
Solved

Setting permissions correct

Hi,

We just started with Fabric, but are stuck with the permissions.
For the moment we use a F2 capacity.
We use the medallion architecture.
The lakehouse, warehouse and semantic model are in Workspace A.
The report is in Workspace B.
Both workspaces are using the same capacity.
I have free users and pro users.
The report is a mix of the semantic model from workspace A and some other data. 
The issue is that the users can't see the data from the semantic model from workspace A. The report is shared through an app.


I tried the following:
- Only read rights to the semantic model in workspace A

- Only read and build rights to the semantic model in workspace A

- Add to the workspace A as viewer

 

But it seems by adding the users as a viewer to the workspace they can see the data, but I don't want the users to see that workspace. Does anyone know how we can set the rights correctly?

  • Hi,

    No, I'm not working in MSFT for the cert exams. I did some of the examns and the security was my weak spot ðŸ˜…
    I checked everything and the settings were all correct. 
    But then I checked my semantic model again, and because I made it directly on the warehouse, the tables were in direct lake storage mode (no idea yet how to change that when creating them directly from the lakehouse in fabric). So I gave the user read rights to the warehouse and it was solved.
    But thanks for helping me think about all the steps.

6 Replies

  • Hi Jessy_D

     

    I believe when sharing with an app, it won't automatically grant read to the semantic models on a different workspace. 

     

    You should just need to grant read on the models, not viewer on the workspace. 

     

    Note that free users will not be able to view the reports, you need an F64 or higher capacity for that. 

     

    If you found this helpful, consider giving some Kudos. If I answered your question or solved your problem, mark this post as the solution. 

    • Jessy_D's avatar
      Jessy_D
      Helper I

      I gave read rights to the semantic model in the other workspace, but when I check the report, I then get the following error on each visual using that data: 

      • Underlying Error QueryUserError
      • Activity IDaf138442-1b6f-446d-b425-fcc6a8343cca
      • Correlation IDe31d7aa2-94bb-f181-a16c-677f49b527b4
      • Request ID57c23deb-7f6d-4165-8ddf-557808ad7e3d
      • TimeWed Dec 17 2025 16:22:55 GMT+0100 (Midden-Europese standaardtijd)
      • Service version13.0.27228.39
      • Client version2512.1.27028-train
      • Cluster URIhttps://wabi-west-europe-e-primary-redirect.analysis.windows.net/
  • Hi Jessy_D

     

    Interesting... what happens if you grant build permissions? 

     

    If you found this helpful, consider giving some Kudos. If I answered your question or solved your problem, mark this post as the solution. 

  • Hi Jessy_D  are you sure you are not working for the people in MSFT that does the cert. exams?! It looks like an exam question 😅  ... here's the 

     

    #1. Enable cross‑workspace semantic model usage (Admin setting), this governs sharing and discovery across workspaces.

    #2. Grant direct item permissions on the semantic model (Workspace A), from Workspace A → Semantic model → More (…) → Manage permissions:

    • For app consumers: grant Read (or App) permission as they don’t need workspace Viewer
    • For report authors in Workspace B (who need to build/refresh reports) grant Build permission

    With F2, Fabric Free users cannot consume Power BI apps (and cross‑workspace semantic models), so in addition ... 

    #3. Upgrade App audiences to  Power BI Pro 

     

    Let me know iof this works, in particular, take a closer look to Introduction to Semantic Models Across Workspaces - Power BI | Microsoft Learn  and current consideration and limitations.  

     

    Hope it works as you expected, I would appreciate a thunbs up if this information has been useful, and mark as solution if appropiate, here if you need a follow up 😉 ... best of lucks! 

    • Jessy_D's avatar
      Jessy_D
      Helper I

      Hi,

      No, I'm not working in MSFT for the cert exams. I did some of the examns and the security was my weak spot ðŸ˜…
      I checked everything and the settings were all correct. 
      But then I checked my semantic model again, and because I made it directly on the warehouse, the tables were in direct lake storage mode (no idea yet how to change that when creating them directly from the lakehouse in fabric). So I gave the user read rights to the warehouse and it was solved.
      But thanks for helping me think about all the steps.