Forum Discussion

syasmin25's avatar
syasmin25
Helper V
5 years ago

RLS security groups

Hello, 

I have an email group for Managers from different companies that I am setting up dashboards for. I have tied the managers to the reports that I create for just their companies. I only have one email security group irrespective of the companies they are in. When I test their permissions for their reports , I can see that they can only see what I have permitted them to see. Their users ID's are tied to the company that they are working on. 

However, since they have the same email group, when I share it with all of them, managers from other companies can view dashboards of different companies with no limitations which they should not be allowed to. Can somebody please tell me how somebody from Company A and view everything from the dashboard created for Company B? Isnt it supposed to show restrcited data instead?

2 Replies

  • Greg_Deckler's avatar
    Greg_Deckler
    Community Champion

    @syasmin25 PLEASE don't cross post!!

     

    Sorry, having trouble following, would need to see data model and RLS rules.


    Not really enough information to go on, please first check if your issue is a common issue listed here: https://community.powerbi.com/t5/Community-Blog/Before-You-Post-Read-This/ba-p/1116882

    Also, please see this post regarding How to Get Your Question Answered Quickly: https://community.powerbi.com/t5/Community-Blog/How-to-Get-Your-Question-Answered-Quickly/ba-p/38490

    The most important parts are:
    1. Sample data as text, use the table tool in the editing bar
    2. Expected output from sample data
    3. Explanation in words of how to get from 1. to 2.

    • syasmin25's avatar
      syasmin25
      Helper V

      I am providing the sample here. I have a Manager's table, 

      EIDCompany CodePositionUPN
      5002402Manager[email protected]
      5003402Manager[email protected]
      5070403Manager[email protected]
      5879403Manager[email protected]
      4566402Manager[email protected]
      4568402Manager[email protected]
      4598403Manager[email protected]
      4789403Manager[email protected]

       

      I have another table for visuals to demonstate the projects they are currently working on, 

      EIDCompany CodeProjects
      45684024545-jk
      47894038585-res
      47894038585-res
      45984037898-kl
      47894038585-res
      45684024545-jk
      45664025056-qw
      45684024545-jk
      45664025056-qw
      45984037898-kl
      45664025056-qw
      45984037898-kl
      47894038585-res
      45684024545-jk
      45664025056-qw
      45684024545-jk
      45664025056-qw
      45664025056-qw
      45984037898-kl
      45664025056-qw
      47894038585-res
      45984037898-kl
      47894038585-res
      45684024545-jk
      45684024545-jk

       


      As you can see the employees have different company codes here. I have connected both the tables for RLS based on their Company Code. However, they only have one security group which I added in both the security part on Power BI server and also on the share. So, when I share a report to company 402, company  403 has complete access to it. They can even access information that is for higher officials in 402 which employees in 402 cannot access. Since the company codes aren't the same, shouldn't their view show restricted data?