<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Row-Level Security and AD groups in Report Server</title>
    <link>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3605182#M32191</link>
    <description>&lt;P&gt;I'm using the same security model with dynamic row level security for some reports.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 3 roles:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;AllItems&lt;/STRONG&gt; - allows admin users to see everything. Users are added manually on the row-level security page for each report (I know I could use an AD group for this and may do so but it's only a small number of users).&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;DirectAndIndirectReports&lt;/STRONG&gt; - This is the default role and I have added this with an AD group that contains all users (domain\AllStaff) in the organisation on the row-level security page for each report.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Level1&lt;/STRONG&gt; - This is to give access to users who need to see data for certain groups of staff who they do not manage.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;For Level1 I have to add each member on the RLS page for each report. So far I have about 10 people, but this number will grow and soon it will become a problem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know I cannot assign the same AllStaff AD group to more than one role but if I create a new AllStaff AD group (e.g. domain\AllStaff2) containing all staff,&amp;nbsp;will this create a conflict because users are in more than one role? If not how would the report server determine which role a user is in if they are in both AllStaff and AllStaff2?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts on this or any alternative way of managing multiple roles?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 28 Dec 2023 10:07:43 GMT</pubDate>
    <dc:creator>Les111</dc:creator>
    <dc:date>2023-12-28T10:07:43Z</dc:date>
    <item>
      <title>Row-Level Security and AD groups</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3605182#M32191</link>
      <description>&lt;P&gt;I'm using the same security model with dynamic row level security for some reports.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 3 roles:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;AllItems&lt;/STRONG&gt; - allows admin users to see everything. Users are added manually on the row-level security page for each report (I know I could use an AD group for this and may do so but it's only a small number of users).&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;DirectAndIndirectReports&lt;/STRONG&gt; - This is the default role and I have added this with an AD group that contains all users (domain\AllStaff) in the organisation on the row-level security page for each report.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Level1&lt;/STRONG&gt; - This is to give access to users who need to see data for certain groups of staff who they do not manage.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;For Level1 I have to add each member on the RLS page for each report. So far I have about 10 people, but this number will grow and soon it will become a problem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know I cannot assign the same AllStaff AD group to more than one role but if I create a new AllStaff AD group (e.g. domain\AllStaff2) containing all staff,&amp;nbsp;will this create a conflict because users are in more than one role? If not how would the report server determine which role a user is in if they are in both AllStaff and AllStaff2?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts on this or any alternative way of managing multiple roles?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2023 10:07:43 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3605182#M32191</guid>
      <dc:creator>Les111</dc:creator>
      <dc:date>2023-12-28T10:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: Row-Level Security and AD groups</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3607857#M32203</link>
      <description>&lt;P&gt;You can have users in multiple roles and you can apply conflicting roles to the same table.&amp;nbsp; The more permissive rules will win over the more restrictive rules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By the way, dynamic RLS is when you use USERPRINCIPALNAME mappings.&amp;nbsp; your implementation is static RLS.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Dec 2023 02:02:13 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3607857#M32203</guid>
      <dc:creator>lbendlin</dc:creator>
      <dc:date>2023-12-30T02:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: Row-Level Security and AD groups</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3610668#M32219</link>
      <description>&lt;P&gt;Does this mean users will see their&amp;nbsp;DirectAndIndirectReports&lt;SPAN&gt;&amp;nbsp;and any additional data they are granted access to as a result of being assigned a value in the Level1 role?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am using USERPRINCIPLENAME to identify the user, then using a dataset with email addresses matched to data (their direct and indirect reports etc) to filter the output, so I thought this was dynamic RLS.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2024 10:09:32 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3610668#M32219</guid>
      <dc:creator>Les111</dc:creator>
      <dc:date>2024-01-02T10:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Row-Level Security and AD groups</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3611269#M32222</link>
      <description>&lt;P&gt;You have three roles - that is not something you usually do in dynamic RLS (there you have only one role, and access is controlled via the data model).&amp;nbsp; Of course you can implement a hybrid version but that gets messy quickly.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2024 15:03:46 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3611269#M32222</guid>
      <dc:creator>lbendlin</dc:creator>
      <dc:date>2024-01-02T15:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: Row-Level Security and AD groups</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3611279#M32223</link>
      <description>&lt;P&gt;Yes I was thinking this. The problem is I have a default role which allows users to see their direct and indirect reports. This is based on relationships in a table that has the manager for each staff member (this is the dynamic RLS part I think)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then there are some people who need access to one area of the organisation but they are not managers of that area (mostly admin staff or HR), so I created a separate table with these permissions based on the organisation hierarchy.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2024 15:14:19 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3611279#M32223</guid>
      <dc:creator>Les111</dc:creator>
      <dc:date>2024-01-02T15:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: Row-Level Security and AD groups</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3611328#M32224</link>
      <description>&lt;P&gt;&lt;A href="https://www.sqlbi.com/articles/managing-hierarchical-organizations-in-power-bi-security-roles/" target="_blank"&gt;Managing hierarchical organizations in Power BI security roles - SQLBI&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2024 15:33:05 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3611328#M32224</guid>
      <dc:creator>lbendlin</dc:creator>
      <dc:date>2024-01-02T15:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Row-Level Security and AD groups</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3619381#M32277</link>
      <description>&lt;P&gt;I've now successfully set this up.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 AD groups, both contain all users in the organisation. This means I don't need to assign permissions to individuals on the report server, I just add the 2 AD groups to one role each in the RLS security page.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One role is based on a hierarchy built from managers and their direct and indirect reports and the other role is based on departments within the organisation, e.g. where the user isn't a manager but needs access to data from a specific department.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These 2 roles have dax filters looking up the USERPRINCIPALNAME and matching it to data in separate datasets. If a user is in one of the datasets they will see data accordingly and if they are in both they will see the appropriate data from both.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jan 2024 15:30:02 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3619381#M32277</guid>
      <dc:creator>Les111</dc:creator>
      <dc:date>2024-01-06T15:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Row-Level Security and AD groups</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3630900#M32367</link>
      <description>&lt;P&gt;Is this a new feature? I have had issues where when a user belongs to multiple roles they do not see anything.&lt;BR /&gt;&lt;BR /&gt;It would be nice for the more permissive rule to win over the restrictive rules, however I have not experienced this.&lt;BR /&gt;&lt;BR /&gt;I am using dynamic&amp;nbsp;&lt;SPAN&gt;USERPRINCIPALNAME() only and members in an Active Directory.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 15:41:46 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3630900#M32367</guid>
      <dc:creator>a-walker</dc:creator>
      <dc:date>2024-01-10T15:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: Row-Level Security and AD groups</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3630925#M32368</link>
      <description>&lt;P&gt;I didn't put any user in 2 roles individually. I created 2 AD groups, both containing all users, then added the AD groups to one role each in the role level security page for the report.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I tried adding individual users to 2 roles it gave an error, but if you add different AD groups and put the same user in both groups it works.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 15:49:21 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Row-Level-Security-and-AD-groups/m-p/3630925#M32368</guid>
      <dc:creator>Les111</dc:creator>
      <dc:date>2024-01-10T15:49:21Z</dc:date>
    </item>
  </channel>
</rss>

