Forum Discussion
Data Masking
- 2 years ago
Power_Guy ,
One suggestion on the top of my mind apart from RLS and OLS is to create a calculated column using userprincipalname().Masked_Customer_Address =
IF( USERPRINCIPALNAME() IN {"[email protected]", "[email protected], "[email protected]"}, "******", [Customer_Address])Con: For any new users, your IN operator will need constant manual appending of Email IDs if address is to be masked.
- 2 years ago
Power_Guy You could have a masked address field and a full address field, OLS could hide the unmasked field from non admin users.
@anand24 has an idea too, though I would flip it around so that the masked address is viewed by default and only users specified as admin see the unmasked.
Note page level security and the idea from anand are not actually security, just workarounds. This means you must be careful how you give permissions on the underlying data model / dataset, as users will still have access to the fields / data.
Power_Guy I would recommend that this should probably be done upstream in the data warehouse or somewhere other than Power BI, but if you're wanting to do it in Power BI, you can use RLS (Row Level Security). Have you used RLS before? There is also something called Object Level Security, but I think you still need a 3rd party app to make this work.