<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Invalid identifier error when removing dataset user in Developer</title>
    <link>https://community.fabric.microsoft.com/t5/Developer/Invalid-identifier-error-when-removing-dataset-user/m-p/2856194#M39377</link>
    <description>&lt;P&gt;Using this API call I can and have removed dataset users:&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/rest/api/power-bi/datasets/put-dataset-user-in-group" target="_blank" rel="noopener nofollow noreferrer"&gt;https://learn.microsoft.com/en-us/rest/api/power-bi/datasets/put-dataset-user-in-group&lt;/A&gt;&lt;/P&gt;&lt;P&gt;With this payload:&lt;/P&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;{'identifier': &amp;lt;user id&amp;gt;, 'principalType': 'User', 'datasetUserAccessRight': 'None'}&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;My problem is that this fails when the user being removed is not in AAD anymore (they left the company.) The user being removed does not have write permissions or inherited permissions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The user id in my case is an email address that is pulled from the identifier field in the response from a call to:&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/rest/api/power-bi/datasets/get-dataset-users-in-group" target="_blank" rel="noopener nofollow noreferrer"&gt;https://learn.microsoft.com/en-us/rest/api/power-bi/datasets/get-dataset-users-in-group&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again the same call/payload construction work if it is an existing AAD user, but I need to clean out permissions for users that have left.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also it is a User, not a group or an app that i'm having the issue with.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The response is a 400, Bad Request. Error message returned is:&lt;/P&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;{"error":{"code":"InvalidRequest","message":"Parameter identifier is missing or invalid"}}&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any pointers on how remove these users would be appreciated. Thanks!&lt;/P&gt;</description>
    <pubDate>Fri, 21 Oct 2022 18:27:00 GMT</pubDate>
    <dc:creator>psaliba</dc:creator>
    <dc:date>2022-10-21T18:27:00Z</dc:date>
    <item>
      <title>Invalid identifier error when removing dataset user</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Invalid-identifier-error-when-removing-dataset-user/m-p/2856194#M39377</link>
      <description>&lt;P&gt;Using this API call I can and have removed dataset users:&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/rest/api/power-bi/datasets/put-dataset-user-in-group" target="_blank" rel="noopener nofollow noreferrer"&gt;https://learn.microsoft.com/en-us/rest/api/power-bi/datasets/put-dataset-user-in-group&lt;/A&gt;&lt;/P&gt;&lt;P&gt;With this payload:&lt;/P&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;{'identifier': &amp;lt;user id&amp;gt;, 'principalType': 'User', 'datasetUserAccessRight': 'None'}&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;My problem is that this fails when the user being removed is not in AAD anymore (they left the company.) The user being removed does not have write permissions or inherited permissions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The user id in my case is an email address that is pulled from the identifier field in the response from a call to:&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/rest/api/power-bi/datasets/get-dataset-users-in-group" target="_blank" rel="noopener nofollow noreferrer"&gt;https://learn.microsoft.com/en-us/rest/api/power-bi/datasets/get-dataset-users-in-group&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again the same call/payload construction work if it is an existing AAD user, but I need to clean out permissions for users that have left.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also it is a User, not a group or an app that i'm having the issue with.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The response is a 400, Bad Request. Error message returned is:&lt;/P&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;{"error":{"code":"InvalidRequest","message":"Parameter identifier is missing or invalid"}}&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any pointers on how remove these users would be appreciated. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2022 18:27:00 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Invalid-identifier-error-when-removing-dataset-user/m-p/2856194#M39377</guid>
      <dc:creator>psaliba</dc:creator>
      <dc:date>2022-10-21T18:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid identifier error when removing dataset user</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Invalid-identifier-error-when-removing-dataset-user/m-p/2857953#M39393</link>
      <description>&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Hi&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/460336"&gt;@psaliba&lt;/a&gt;,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;I think this scenario should meet the limitations listed on the API document, perhaps you can take a look on it at the first:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;&lt;A href="https://learn.microsoft.com/en-us/rest/api/power-bi/datasets/put-dataset-user-in-group" target="_blank"&gt;Datasets - Put Dataset User In Group - REST API (Power BI Power BI REST APIs) | Microsoft Learn&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;In addition, the user account turns on/off should be a pain part for the permission manager, they obviously will change some global settings and properties that affect the common feature and corresponding API usages which are hard to trace and fix.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;For the above scenario, you can try to create a user group on the Azure side for API usage instead of accurate add/removing each user, it will be simpler to manage the group members.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Regards,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Xiaoxin Sheng&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 02:21:57 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Invalid-identifier-error-when-removing-dataset-user/m-p/2857953#M39393</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2022-10-24T02:21:57Z</dc:date>
    </item>
  </channel>
</rss>

