Forum Discussion
Can Admin override a sensitivity label?
As the admin, I would like the ability to change/override a sensitivity label on a Power BI dataset or report that was manually applied by a colleague. Is this possible?
Here's my context. A colleague had created a new Power BI report & dataset, set the sensitivity label to be "Business/Employees Only", and published it. They told me it's location, invited me to download it to review the implementation details, then they left for the day. When I tried to download & open the .pbix file, I received this error about being restricted. See screen shot above.
This is confusing because 1.) we're employees of the same company, so with a label that says Employees Only, I'm expecting access but I don't have access. 2.) with an error that says, "To request access, contact your team's Power BI admin." I'm expecting to be able to change the access because I'm the admin, but I can't. Why not?
Side note, within the Admin portal, Tenant settings, the Information protection items are all enabled for the entire org.
5 Replies
- jb_weddingFrequent Visitor
foodd Unfortunately, your latest link does NOT address my issue. It shows how to set & view & remove sensitivity labels, but not how to change them if you're not the user who applied the label.
This link is more applicable (service-security-sensitivity-label-change-enforcement ). It mentions the authorized users, however, even as a Office Security Admin, I don't see exactly how to grant the usage rights to allow a person to change the sensitivity label on an individual Power BI report.
To re-iterate from my original message above, the screen shot says, "To request access, contact your team's Power BI admin". What exactly can the admin do in this situation?
- jb_weddingFrequent Visitor
foodd Your link above does NOT directly address my question. How can the admin change the sensitivity label of a report or dataset, per the error message that I posted in my original message?
- AnonymousNot applicable
Hi jb_wedding ,
Here are the requirements to apply sensitivity labels in the Power BI service:
- You must have a Power BI Pro or Premium Per User (PPU) license and edit permissions on the content you want to label.
- Sensitivity labels must be enabled for your organization. Contact your Power BI admin for information about your configuration.
- You must belong to a security group that has permissions to apply sensitivity labels, as described in Enable sensitivity labels in Power BI.
- All licensing and other requirements must be met.
You can apply or change the sensitivity label on a report or dashboard by following these steps:
- On the More options... menu for a report or dashboard, select Settings.
- In the Settings side pane, go to the Sensitivity label section.
- Select the appropriate sensitivity label in the drop-down list.
- Select Save to apply the modified settings.
If the Sensitivity label setting isn't available, you might not have the correct usage rights to change the setting. If you're not able to change a sensitivity label, consider asking the person who originally applied the label to make the change.
Best regards,
Community Support Team_Binbin Yu
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly. - jb_weddingFrequent Visitor
I have a resolution to this, and it's based upon my own admin education. This MS article was helpful to a certain degree https://learn.microsoft.com/en-us/power-bi/enterprise/service-security-sensitivity-label-change-enforcement
To summarize my new understanding, 3 planets need to be aligned to make this override happen:
- Within Admin portal > Tenant settings > Info protection > Allow workspace admins to override.... needs to be enabled. That had been enabled for us, so no change was needed for me.
- The person doing the overriding needs to be a WORKSPACE admin. NB, being a global power bi admin doesn't equate to workspace admin.
- The person doing the overriding needs to open the report online, AND switch to edit mode to be allowed to make the change. It's not editable from the workspace view.