Advance your Data & AI career with 50 days of live learning, dataviz contests, hands-on challenges, study groups & certifications and more!
Get registeredJoin us at FabCon Atlanta from March 16 - 20, 2026, for the ultimate Fabric, Power BI, AI and SQL community-led event. Save $200 with code FABCOMM. Register now.
Hi,
I'm creating a summary report that uses several semantic models from different workspaces, using Direct Query. The issue is that most users cannot see visuals that are not part of the workspace they belong to and I'm trying to figure out what permissions are missing. An import detail is that my summary report should be visible for all users in my company but the different semantic models and corresponding existing reports/dashboards of each team on specific workspaces are restricted to each team only.
Would it be enough to provide access to different semantic models? If so, how can I provide access to all users at once and not one by one? Is through sharing link? And if user access is provided only on semantic model level (not in the different workspaces neither reports), does this mean that users would be only to see the data displayed in my summary report and not the whole data, right?
Thank you very much for you support.
Solved! Go to Solution.
The solution was to provide user access to the semantic models using the option Direct Access and unticking all the checkboxes, ensuring only read access (no build, reshare, etc). I had to use an AD Group to ensure access to all users in my organization. Additionally, using the option OneLake, I asked some users to check if they could see the semantic models for which access was given and the option "Explore data" was deactivated, meaning they can only see the data I display in my report and nothing else (given that some details are confidential). I didn't had to provide any permission in the different workspaces, so the users cannot access any team specific workspaces or reports.
The solution was to provide user access to the semantic models using the option Direct Access and unticking all the checkboxes, ensuring only read access (no build, reshare, etc). I had to use an AD Group to ensure access to all users in my organization. Additionally, using the option OneLake, I asked some users to check if they could see the semantic models for which access was given and the option "Explore data" was deactivated, meaning they can only see the data I display in my report and nothing else (given that some details are confidential). I didn't had to provide any permission in the different workspaces, so the users cannot access any team specific workspaces or reports.
Glad that this works for you. Personally I think that not giving Build access is counterproductive.
 uses several semantic models from different workspacesAll report users must have access to all workspaces. If you share via app them all users must have "installed" (registered) all apps from the participating workspaces.
