Forum Discussion
Dynamic Row level Security for AD groups
Hello All,
I need some help in Dynamic Row Level Security.
We have 1000+ members with aligned to different AD groups and we need to set our PBI reports based on their AD Group allocation. We are able to run D-RLS when we use the Email ID of employee but maintain 1000+ email id with their access level is not a correct solution and there will be lot of bulk addition / removals of users.
Can anyone please suggest me how we can get DRLS working where we have users split by Zone Security Group , Area Security Group and Admin Security group.
Thank you
Regards
Satish
Sample File
5 Replies
- lbendlinSuper User
"maintain 1000+ email id with their access level is not a correct solution "
Please explain why you think that way. Larger companies have User Access Management tools that can maintain profiles and AD groups (including bulk load, periodic auditing and auto cleanup) . Usually these tools provide datasets or dataflows that can then be consumed by Power BI developers for their dynamic RLS needs.
- aiimsNew Member
Hi lbendlin
We already have AD groups in place for each team which has employee email id. This way we have almost 100+Ad groups which has 1000+ emails.
Any update in the records happens on AD group and all the tools updates the security accordingly.
We want to use the same AD group for our report RLS but PBI is not recognizing it.
Maintainig / Delete/Update of these email id will not be easy task as same email id can be in multiple groups/team.
We have the below kind of table to be load on PBI where access will the key to connect with PBI Base table
AD_Group
Access
UKI_Leads
UKI
IND_Leads
IND
Appreciate your help and support.
- lbendlinSuper User
I forgot to mention that all your AD groups must be mail enabled. Use their email address in Power BI