<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic when add Domain's security group to RLS of Power BI Report Server , error occured in report page in Report Server</title>
    <link>https://community.fabric.microsoft.com/t5/Report-Server/when-add-Domain-s-security-group-to-RLS-of-Power-BI-Report/m-p/2449063#M23677</link>
    <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The security group named ‘PBIGroup’ have crteated already in domain environment, while add the&amp;nbsp;‘PBIGroup’ to the RLS on Web site , there is no error in current page , but go to report page, the error "This visual contains restricted data.See details" occured for every visuals.&amp;nbsp; while add individual user account to this rls box, the report page works well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;img /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i refer to the link&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/power-bi/report-server/row-level-security-report-server#considerations-and-limitations" target="_blank" rel="noopener"&gt;Row-level security (RLS) in Power BI Report Server - Power BI | Microsoft Docs.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;there is a limit like below, but there is no other details or configuration guidance to describe the "&lt;SPAN&gt;NTLM or Kerberos authentication&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&lt;img /&gt;&lt;/P&gt;&lt;P&gt;so how can i make the security group work for the RLS of Power BI Report Server, there is other steps is missing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the document link&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-au/power-bi/report-server/configure-kerberos-powerbi-reports" target="_blank" rel="noopener"&gt;Configure Kerberos to use Power BI reports - Power BI | Microsoft Docs&lt;/A&gt;&amp;nbsp;is the right one to solve this group rls issue ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;note: the data source is SQL Server&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any suggestions is welcome , thank you for your help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Amy&lt;/P&gt;</description>
    <pubDate>Mon, 04 Aug 2025 05:59:30 GMT</pubDate>
    <dc:creator>Meng</dc:creator>
    <dc:date>2025-08-04T05:59:30Z</dc:date>
    <item>
      <title>when add Domain's security group to RLS of Power BI Report Server , error occured in report page</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/when-add-Domain-s-security-group-to-RLS-of-Power-BI-Report/m-p/2449063#M23677</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The security group named ‘PBIGroup’ have crteated already in domain environment, while add the&amp;nbsp;‘PBIGroup’ to the RLS on Web site , there is no error in current page , but go to report page, the error "This visual contains restricted data.See details" occured for every visuals.&amp;nbsp; while add individual user account to this rls box, the report page works well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;img /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i refer to the link&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/power-bi/report-server/row-level-security-report-server#considerations-and-limitations" target="_blank" rel="noopener"&gt;Row-level security (RLS) in Power BI Report Server - Power BI | Microsoft Docs.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;there is a limit like below, but there is no other details or configuration guidance to describe the "&lt;SPAN&gt;NTLM or Kerberos authentication&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&lt;img /&gt;&lt;/P&gt;&lt;P&gt;so how can i make the security group work for the RLS of Power BI Report Server, there is other steps is missing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the document link&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-au/power-bi/report-server/configure-kerberos-powerbi-reports" target="_blank" rel="noopener"&gt;Configure Kerberos to use Power BI reports - Power BI | Microsoft Docs&lt;/A&gt;&amp;nbsp;is the right one to solve this group rls issue ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;note: the data source is SQL Server&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any suggestions is welcome , thank you for your help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Amy&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2025 05:59:30 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/when-add-Domain-s-security-group-to-RLS-of-Power-BI-Report/m-p/2449063#M23677</guid>
      <dc:creator>Meng</dc:creator>
      <dc:date>2025-08-04T05:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: when add Domain's security group to RLS of Power BI Report Server , error occured in report page</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/when-add-Domain-s-security-group-to-RLS-of-Power-BI-Report/m-p/2454346#M23706</link>
      <description>&lt;P&gt;The username it not resolving correctly as defined in the RLS table that you had created.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try create measure&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;_user = USERPRINCIPALNAME()&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and see that the names in RLS table and this measures matched.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 08:45:39 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/when-add-Domain-s-security-group-to-RLS-of-Power-BI-Report/m-p/2454346#M23706</guid>
      <dc:creator>FarhanAhmed</dc:creator>
      <dc:date>2022-04-13T08:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: when add Domain's security group to RLS of Power BI Report Server , error occured in report page</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/when-add-Domain-s-security-group-to-RLS-of-Power-BI-Report/m-p/2458761#M23731</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="268760" data-lia-user-login="Meng" class="lia-mention lia-mention-user"&gt;Meng&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;The format that your report uses locally to configure permissions is DOMAIN\User or user@contoso.com ?&lt;/P&gt;
&lt;P&gt;According the article you provided, it mentioned:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Within Power BI Desktop, username() returns a user in the format of DOMAIN\User and userprincipalname() returns a user in the format of user@contoso.com.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Within Power BI Report Server, username() and userprincipalname() both return the user's User Principal Name (UPN), which is similar to an email address.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If you're using custom authentication in Power BI Report Server, it returns the username format you’ve set up for users.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And about&amp;nbsp;&lt;SPAN&gt;NTLM or Kerberos authentication,you could refer the following article:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/power-bi/report-server/configure-kerberos-powerbi-reports" target="_self"&gt;&lt;SPAN&gt;Configure Kerberos to use Power BI reports&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did I answer your question? Mark my post as a solution!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Best Regards&lt;/P&gt;
&lt;P&gt;Lucien&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2022 08:00:50 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/when-add-Domain-s-security-group-to-RLS-of-Power-BI-Report/m-p/2458761#M23731</guid>
      <dc:creator>v-luwang-msft</dc:creator>
      <dc:date>2022-04-15T08:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: when add Domain's security group to RLS of Power BI Report Server , error occured in report page</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/when-add-Domain-s-security-group-to-RLS-of-Power-BI-Report/m-p/2464664#M23772</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="268760" data-lia-user-login="Meng" class="lia-mention lia-mention-user"&gt;Meng&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Has your problem been solved, if so, please consider Accept a correct reply as the solution or share your own solution to help others find it.&lt;/P&gt;
&lt;P&gt;Best Regards&lt;BR /&gt;Lucien&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 02:46:57 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/when-add-Domain-s-security-group-to-RLS-of-Power-BI-Report/m-p/2464664#M23772</guid>
      <dc:creator>v-luwang-msft</dc:creator>
      <dc:date>2022-04-20T02:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: when add Domain's security group to RLS of Power BI Report Server , error occured in report page</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/when-add-Domain-s-security-group-to-RLS-of-Power-BI-Report/m-p/2476297#M23855</link>
      <description>&lt;P&gt;hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this issue has been solved.&amp;nbsp; to make the security group works in RLS of Power BI Report Server, just to follow 2 steps , which refer to the document&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-au/power-bi/report-server/configure-kerberos-powerbi-reports#configuring-kerberos-constrained-delegation" target="_blank" rel="noopener"&gt;Configure Kerberos to use Power BI reports - Power BI | Microsoft Docs&lt;/A&gt;&amp;nbsp;:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.go to&amp;nbsp;&lt;SPAN&gt;C:\Program Files\Microsoft Power BI Report Server\PBIRS\ReportServer, find&amp;nbsp;&amp;nbsp;rsreportserver.config file, add&amp;nbsp;RSWindowsNegotiate to&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;Authentication/AuthenticationTypes&lt;/STRONG&gt;&amp;nbsp;section of this file.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;like this :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;AuthenticationTypes&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;lt;RSWindowsNegotiate/&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;lt;RSWindowsNTLM/&amp;gt;&lt;BR /&gt;&amp;lt;/AuthenticationTypes&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;stop and start the report server to make sure the changes take effect&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. go to "&lt;SPAN&gt;Active Directory Users and Computers&lt;/SPAN&gt;", which domain admin know where it is.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&amp;nbsp;choose item "Computer", choose the machine account (a server , which power bi report server installed on),&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Right click on the report server service account and select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Properties&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Select the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Delegation&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tab.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Trust this computer for delegation to specified services only&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Use any authentication protocol&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Under the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Services to which this account can present delegated credentials&lt;/STRONG&gt;: select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Add&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the new dialog, select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Users or Computers&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Enter the service account for the &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;SQL Serve&lt;/STRONG&gt;r&lt;/FONT&gt; service and select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Ok&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Select the SQL Server service' SPN ( It will begin with&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;MSSQLSvc.3).&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;. You should see the SPN in the list now.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Ok&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;stop and start &lt;/SPAN&gt;the Power BI Report Server.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in this document&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-au/power-bi/report-server/configure-kerberos-powerbi-reports#configuring-kerberos-constrained-delegation" target="_blank" rel="noopener"&gt;Configure Kerberos to use Power BI reports - Power BI | Microsoft Docs&lt;/A&gt;, it takes data source "&lt;SPAN&gt;SQL Server Analysis Services&lt;/SPAN&gt;" (which links to &lt;SPAN&gt;Analysis Services&lt;/SPAN&gt;) as a example to configurate Kerberos for Power bi report server. so the steps maybe complex, and i haven't test it for data source "&lt;SPAN&gt;SQL Server Analysis Services&lt;/SPAN&gt;".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;while in my situation, the data source is SQL Server, find no needs to configurate for the SPN of SQL Server service and&amp;nbsp;SQL Browser service, just follow steps like above. thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 02:21:18 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/when-add-Domain-s-security-group-to-RLS-of-Power-BI-Report/m-p/2476297#M23855</guid>
      <dc:creator>Meng</dc:creator>
      <dc:date>2022-04-26T02:21:18Z</dc:date>
    </item>
  </channel>
</rss>

