Join us at FabCon Atlanta from March 16 - 20, 2026, for the ultimate Fabric, Power BI, AI and SQL community-led event. Save $200 with code FABCOMM.
Register now!The Power BI Data Visualization World Championships is back! Get ahead of the game and start preparing now! Learn more
We have two roles: "Global VIP" and "Global".
VIP gets to see everything, while non-VIP (Global) are not to see one specific column (measure).
This is solved in our model in Tabular editor; on the specific column (in the fact table), the non-VIP (here called Global) has object level security set to "None", while the VIP one has default.
These RLS groups are populated by AD groups.
Problem arises if a person belongs to AD groups in both, that is eg a person is in group "sales personnel" which belongs to "Global", and group "managers" which is VIP. This leads to a conflict and person can't see anything based on this model.
(The AD groups are out of my control)
Any suggestions?
Preferrably I would like the more elevated role to take precedence.
Preferrably I would like the more elevated role to take precedence.
Define "elevated". By default the more permissive rule overrides the more restrictive rule.
In my case the "elevated" role would be the "Global VIP" role which has the object level security set to default, while the "Global" role has it set to None.
I have no experience with OLS, but it sounds like you either need to drop the requirement or create separate reports.
The Power BI Data Visualization World Championships is back! Get ahead of the game and start preparing now!
| User | Count |
|---|---|
| 38 | |
| 36 | |
| 33 | |
| 32 | |
| 29 |
| User | Count |
|---|---|
| 129 | |
| 88 | |
| 79 | |
| 68 | |
| 63 |