Forum Discussion
Direct Lake + RLS issue
Hello Team,
I am building a report using a LakeHouse with a Direct Lake connection and RLS configured. However, the end user sees a blank report when accessing it on App. if I keep everything the same and only change the connection mode to import, the user is able to see the data for him.
what could be causing this issue with the Direct Lake connection?
Thanks in advance.
Hi,
When RLS is applied on a Direct Lake semantic model, queries fall back from Direct Lake to DirectQuery against the SQL analytics endpoint. In DirectQuery mode the viewer's identity is passed through to the source, so the end user needs read access to the underlying Lakehouse / SQL endpoint itself, not just to the semantic model or the app. That's why Import works for the same user, since the data already lives inside the model and the viewer never touches the source.
The fix is usually one of two things. Either grant the user (or a security group they belong to) at least ReadData on the Lakehouse and reshare the app, or on the semantic model's connection to the SQL analytics endpoint switch from SSO to a fixed identity so viewers inherit that account's permissions.
If this helped, a thumbs up and accepting the solution would be appreciated.
Best regards,
Shai Karmani
2 Replies
- Shai_Karmani
Super User
Hi,
When RLS is applied on a Direct Lake semantic model, queries fall back from Direct Lake to DirectQuery against the SQL analytics endpoint. In DirectQuery mode the viewer's identity is passed through to the source, so the end user needs read access to the underlying Lakehouse / SQL endpoint itself, not just to the semantic model or the app. That's why Import works for the same user, since the data already lives inside the model and the viewer never touches the source.
The fix is usually one of two things. Either grant the user (or a security group they belong to) at least ReadData on the Lakehouse and reshare the app, or on the semantic model's connection to the SQL analytics endpoint switch from SSO to a fixed identity so viewers inherit that account's permissions.
If this helped, a thumbs up and accepting the solution would be appreciated.
Best regards,
Shai Karmani
- RaMahiRegular Visitor
Hello Shai_Karmani It worked, I made changes as the semantic model's connection to the SQL analytics endpoint switch from SSO to a OAuth 2.0, Thanks for your great help. 🎉