Forum Discussion
Implement RLS in Power BI Using Application-Level Authentication
- 1 year ago
Hi ribisht
To implement RLS with application-level authentication (not using Microsoft user accounts), you should use Power BI embedding for service principals. First, assign RLS roles to the dataset in Power BI Desktop and publish it. Then, when generating the embed token in your application, pass the appropriate username as an effective identity in the token request. Power BI will apply RLS based on that username. This way, your app controls what data the user sees using its own authentication logic, while Power BI enforces RLS behind the scenes. No manual pivot or shared drives are needed once setup is complete.
Hi ribisht ,
Thank you for reaching out to the Microsoft fabric community forum. Also thank you rohit1991 , your suggested method is correct for enabling RLS with application-level authentication in Power BI Embedded.
In adition to that,here are a few points need to consider:
- This method requires a workspace in Power BI Premium capacity, as embedding with a service principal isn’t supported with Pro licenses.
- The identity string provided via EffectiveIdentity must match the format used in your RLS setup, usually through USERNAME() or USERPRINCIPALNAME() in the role definitions.
- Your application must handle user authentication and map users to the correct identity string, since Power BI only enforces RLS based on the embed token and does not perform authentication itself.
Once configured, this approach provides secure and dynamic data access based on your app’s user model, without manual data pivots or shared storage.
Hope this helps. Please reach out for further assistance.
Thank you.