a { text-decoration: none; color: #464feb; } tr th, tr td { border: 1px solid #e6e6e6; } tr th { background-color: #f5f5f5; }
The current workspace access model is limited to the predefined workspace roles (Admin, Member, Contributor, and Viewer). While these roles control overall workspace access, they do not provide sufficient granularity for large enterprise environments where different users require different capabilities within the same workspace.
We need the ability to assign permissions for specific features and actions independently of workspace roles.
For example, we need to be able to:
- Allow users to view reports while restricting their ability to export data.
- Allow users to publish reports but prevent them from modifying semantic models.
- Allow users to create content but prevent them from deleting artifacts.
- Restrict access to workspace settings and administrative functions without removing broader workspace access.
- Control sharing permissions independently from content creation permissions.
Implementing feature-level permissions would provide the following benefits:
- Improved Governance: Better enforcement of enterprise security and compliance requirements.
- Reduced Risk: Minimize accidental exposure or modification of critical content.
- Operational Flexibility: Allow organizations to grant only the permissions users need.
- Reduced Workspace Sprawl: Eliminate the need to create multiple workspaces solely to achieve different permission models.
We believe granular feature-level permissions are essential for enterprise-scale deployments and would greatly enhance governance and security within Power BI.
Recent ideas
Enable OneLake to Read Snowflake-Managed Iceberg Tables via Horizon Catalog
1. Current Problem Snowflake lets customers create Iceberg tables where Snowflake manages both the catalog and the storage (CATALOG = 'SNOWFLAKE', EXTERNAL_VOLUME = 'SNOWFLAKE_MANAGED'). This is th...NareJoshi8 hours agoMicrosoft EmployeeNew4Views0likes0CommentsSet SQL analytics endpoint access mode (User's identity) via REST API and Terraform
The SQL analytics endpoint enforces OneLake security only in User's identity access mode. The only documented way to choose the mode is the Security tab in the portal (Data access mode settings). Not...smorimoto12 hours agoNew MemberNew2Views0likes0Comments