Forum Discussion

RajaSadagopan's avatar
RajaSadagopan
Regular Visitor
1 year ago
Solved

Dynamic RLS with embedding

Hi,

So I have embedded a powerbi report in another web application. To view the report, user needs to login. Now the report has data for all departments. But the logging in user belongs to some specific department and he should be given access to view only that data. 

Now the data part, The report contains 5 dashboard from 5 fact tables. All the fact table has department id which is mapped to a dim_department table (DIMENSION TABLE). Out of the 5 fact tables, we have fact_user table containing the username by which the user is logged in, his department ID and several other information which is required for dashboarding purpose.

Tricky Part: There are around 30000 users logging into the web application from different domain without powerbi license. So we embed the report by Service principal (Azure Active Directory).

How to apply RLS at department level in powerbi while embedding??

  • lbendlin's avatar
    lbendlin
    1 year ago

    RLS must control the data model. It needs to be applied to a dimension table on the outside of the star schema.

4 Replies

  • So we embed the report by Service principal

    Don't do that? 

     

    There are around 30000 users logging into the web application from different domain

    From outside your Entra ID?

     

    Is your RLS applied to one of the dimension tables? What is it based on? Mapping from userprincipalname to department?

  • No we have not applied RLS to dim table! The username in fact_user is the username used to login to the web application. The username is linked to department via department ID

    • lbendlin's avatar
      lbendlin
      Super User

      RLS must control the data model. It needs to be applied to a dimension table on the outside of the star schema.