Forum Discussion
Implement RLS in Power BI Using Application-Level Authentication
Our assure application has two layers of authentication: an application user login, not MS Entra or SSO, and IP address restriction by FI tenant registration, and sometimes per user if they are unable to route requests through their proxy server or from within their registered network IP range. All our Assure application’s requests to external resources leverage either Azure managed identity or user credentials stored in Azure key vault. Our requests include FI tenant and application user identification values to verify and filter access to data.
Hi ribisht
To implement RLS with application-level authentication (not using Microsoft user accounts), you should use Power BI embedding for service principals. First, assign RLS roles to the dataset in Power BI Desktop and publish it. Then, when generating the embed token in your application, pass the appropriate username as an effective identity in the token request. Power BI will apply RLS based on that username. This way, your app controls what data the user sees using its own authentication logic, while Power BI enforces RLS behind the scenes. No manual pivot or shared drives are needed once setup is complete.
2 Replies
- rohit1991Super User
Hi ribisht
To implement RLS with application-level authentication (not using Microsoft user accounts), you should use Power BI embedding for service principals. First, assign RLS roles to the dataset in Power BI Desktop and publish it. Then, when generating the embed token in your application, pass the appropriate username as an effective identity in the token request. Power BI will apply RLS based on that username. This way, your app controls what data the user sees using its own authentication logic, while Power BI enforces RLS behind the scenes. No manual pivot or shared drives are needed once setup is complete.
- AnonymousNot applicable
Hi ribisht ,
Thank you for reaching out to the Microsoft fabric community forum. Also thank you rohit1991 , your suggested method is correct for enabling RLS with application-level authentication in Power BI Embedded.
In adition to that,here are a few points need to consider:
- This method requires a workspace in Power BI Premium capacity, as embedding with a service principal isn’t supported with Pro licenses.
- The identity string provided via EffectiveIdentity must match the format used in your RLS setup, usually through USERNAME() or USERPRINCIPALNAME() in the role definitions.
- Your application must handle user authentication and map users to the correct identity string, since Power BI only enforces RLS based on the embed token and does not perform authentication itself.
Once configured, this approach provides secure and dynamic data access based on your app’s user model, without manual data pivots or shared storage.
Hope this helps. Please reach out for further assistance.
Thank you.