<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Token  based Identity in Azure SQL database in Developer</title>
    <link>https://community.fabric.microsoft.com/t5/Developer/Token-based-Identity-in-Azure-SQL-database/m-p/1038718#M23224</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a request from business to embed power bi reports in web app and implement RLS.However they want to reuse the RLS implementation in SQL server and not use the power BI RLS feature. For this we are using 'token base identity with Azure SQL Database'&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/power-bi/developer/embedded/embedded-row-level-security#token-based-identity-with-azure-sql-database-preview" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/power-bi/developer/embedded/embedded-row-level-security#token-based-identity-with-azure-sql-database-preview&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On passing identity blob object to embed code we are getting below error for few users(for certain users it works fine).&lt;/P&gt;&lt;DIV&gt;{"error":{"code":"InvalidRequest","message":"Identity blob value size exceeds size limit of 6144 bytes"}&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;On decoding the access token recieved we could see it also has groups information in it and for users with error has more number of groups information which is being appended to access token. Is there anyway to remove groups claims from access token recieved from AD.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Thanks &amp;amp; Regards,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Neeraja&lt;/SPAN&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 21 Apr 2020 08:50:00 GMT</pubDate>
    <dc:creator>NeerajaBen</dc:creator>
    <dc:date>2020-04-21T08:50:00Z</dc:date>
    <item>
      <title>Token  based Identity in Azure SQL database</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Token-based-Identity-in-Azure-SQL-database/m-p/1038718#M23224</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a request from business to embed power bi reports in web app and implement RLS.However they want to reuse the RLS implementation in SQL server and not use the power BI RLS feature. For this we are using 'token base identity with Azure SQL Database'&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/power-bi/developer/embedded/embedded-row-level-security#token-based-identity-with-azure-sql-database-preview" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/power-bi/developer/embedded/embedded-row-level-security#token-based-identity-with-azure-sql-database-preview&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On passing identity blob object to embed code we are getting below error for few users(for certain users it works fine).&lt;/P&gt;&lt;DIV&gt;{"error":{"code":"InvalidRequest","message":"Identity blob value size exceeds size limit of 6144 bytes"}&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;On decoding the access token recieved we could see it also has groups information in it and for users with error has more number of groups information which is being appended to access token. Is there anyway to remove groups claims from access token recieved from AD.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Thanks &amp;amp; Regards,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Neeraja&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 21 Apr 2020 08:50:00 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Token-based-Identity-in-Azure-SQL-database/m-p/1038718#M23224</guid>
      <dc:creator>NeerajaBen</dc:creator>
      <dc:date>2020-04-21T08:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Token  based Identity in Azure SQL database</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Token-based-Identity-in-Azure-SQL-database/m-p/1039538#M23234</link>
      <description>&lt;P&gt;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/97366"&gt;@NeerajaBen&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Please go through this link:&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/rest/api/power-bi/embedtoken" target="_blank"&gt;https://docs.microsoft.com/en-us/rest/api/power-bi/embedtoken&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you are using&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://docs.microsoft.com/en-us/rest/api/power-bi/embedtoken/generatetoken" target="_self"&gt;Generate Token&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;method, please try with&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/rest/api/power-bi/embedtoken/reports_generatetokeningroup" target="_self"&gt;&lt;STRONG&gt;GenerateTokenInGroup&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Did I answer your question? Mark my post as a solution!&lt;BR /&gt;Appreciate with a kudos &lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2020 14:42:12 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Token-based-Identity-in-Azure-SQL-database/m-p/1039538#M23234</guid>
      <dc:creator>nandukrishnavs</dc:creator>
      <dc:date>2020-04-21T14:42:12Z</dc:date>
    </item>
  </channel>
</rss>

