Forum Discussion
Users not able to access Semantic Model
So in my Org, I gave someone on my Team read access to a semantic model, they're not able to access it
I tried giving them all access , still unable to access it
I then gave them workspace viewer access, they can see everything, including the SQL analytics endpoints the model is taking from, EXCEPT the semantic models.
I then tried to give someone else member access to the workspace, and they're able to see everything.
Is there something I'm missing here? Like a back end permission I need to look at ? I can't find anything that I haven't already tried online so far.
- Hi christophellis,I tested the same scenario in one of my workspaces.
With WS viewer, the user could see the Lakehouse and SQL analytics endpoint, but not the semantic model in the workspace. Then I gave Build permission on the semantic model. Then the test user could see the semantic model on Onelake Catalog, but it still not appear in the workspace item list.
When I changed the user to Contributor, the semantic model appeared in the workspace.Workspace viewer is not enough to see semantic models in the workspace.Build permissions makes the semantic model only appear in the onelake catalogThe point here is that workspace roles and item permissions are seperate.
https://learn.microsoft.com/en-us/fabric/security/permission-modelhttps://learn.microsoft.com/en-us/power-bi/connect-data/service-datasets-build-permissions.The results of my tests:* Viewer = can consume/access in onelake catalog, but semantic model not show in the workspace item list* Build permission = lets the user discover / build from the semantic model* Contributor/Member = semantic model appears in the workspace and the user gets broader permissionsensGive your user build access, and check in onelake catalog if appears there for them?
If not, give contributer role for testing and see does any changes?
//Parchitect
4 Replies
- ParchitectSolution SageHi christophellis,I tested the same scenario in one of my workspaces.
With WS viewer, the user could see the Lakehouse and SQL analytics endpoint, but not the semantic model in the workspace. Then I gave Build permission on the semantic model. Then the test user could see the semantic model on Onelake Catalog, but it still not appear in the workspace item list.
When I changed the user to Contributor, the semantic model appeared in the workspace.Workspace viewer is not enough to see semantic models in the workspace.Build permissions makes the semantic model only appear in the onelake catalogThe point here is that workspace roles and item permissions are seperate.
https://learn.microsoft.com/en-us/fabric/security/permission-modelhttps://learn.microsoft.com/en-us/power-bi/connect-data/service-datasets-build-permissions.The results of my tests:* Viewer = can consume/access in onelake catalog, but semantic model not show in the workspace item list* Build permission = lets the user discover / build from the semantic model* Contributor/Member = semantic model appears in the workspace and the user gets broader permissionsensGive your user build access, and check in onelake catalog if appears there for them?
If not, give contributer role for testing and see does any changes?
//Parchitect - Prince0011Solution Sage
This usually comes down to underlying data permissions rather than the semantic model permissions alone.
A few things to check:
Confirm whether the semantic model is using Import, Direct Lake, or DirectQuery.
If it's Direct Lake or DirectQuery, make sure the users also have the required permissions on the underlying Lakehouse, Warehouse, or SQL Analytics Endpoint. Granting Read access to the semantic model by itself may not be enough.
Verify that the users have the appropriate Read/Build permissions on the semantic model, depending on what they're expected to do.
If you're using SSO, review whether a fixed identity/shared cloud connection would be more appropriate for your scenario.
Microsoft documentation:
https://learn.microsoft.com/fabric/security/permission-model
https://learn.microsoft.com/power-bi/connect-data/service-datasets-permissions
If you've already verified all of the above and the issue persists, could you share:
Is the semantic model Import, Direct Lake, or DirectQuery?
What is the underlying source (Lakehouse, Warehouse, or SQL Analytics Endpoint)?
Do users receive an error message, or is the semantic model simply not visible?
That information will help determine whether this is a permission configuration issue or a service-related problem.
If this reply helps, please consider giving it a Kudos. If it resolves your issue, marking it as the Accepted Solution will help others facing the same problem.
- v-abhinavmuCommunity Support
Hi christophellis,
Thank you for posting your query in the Microsoft Fabric Community Forum, and thanks to Parchitect & Prince0011 for sharing valuable insights.
Could you please confirm if your query has been resolved by the provided solutions? This would be helpful for other members who may encounter similar issues.
Thank you for being part of the Microsoft Fabric Community.
- v-abhinavmuCommunity Support
Hi christophellis,
May I check if this issue has been resolved? If not, Please feel free to contact us if you have any further questions.
Thank you