Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

The Power BI Data Visualization World Championships is back! Get ahead of the game and start preparing now! Learn more

Reply
robertnorman
Advocate II
Advocate II

Conflicting RLS on Object

We have two roles: "Global VIP" and "Global".

VIP gets to see everything, while non-VIP (Global) are not to see one specific column (measure).

This is solved in our model in Tabular editor; on the specific column (in the fact table), the non-VIP (here called Global) has object level security set to "None", while the VIP one has default.

 

robertnorman_0-1701267948985.png

These RLS groups are populated by AD groups.

Problem arises if a person belongs to AD groups in both, that is eg a person is in group "sales personnel" which belongs to "Global", and group "managers" which is VIP. This leads to a conflict and person can't see anything based on this model.

 

(The AD groups are out of my control)

 

Any suggestions?

 

Preferrably I would like the more elevated role to take precedence.

3 REPLIES 3
lbendlin
Super User
Super User

Preferrably I would like the more elevated role to take precedence.

Define "elevated".  By default the more permissive rule overrides the more restrictive rule.

In my case the "elevated" role would be the "Global VIP" role which has the object level security set to default, while the "Global" role has it set to None. 

I have no experience with OLS, but it sounds like you either need to drop the requirement or create separate reports.

Helpful resources

Announcements
Power BI DataViz World Championships

Power BI Dataviz World Championships

The Power BI Data Visualization World Championships is back! Get ahead of the game and start preparing now!

December 2025 Power BI Update Carousel

Power BI Monthly Update - December 2025

Check out the December 2025 Power BI Holiday Recap!

FabCon Atlanta 2026 carousel

FabCon Atlanta 2026

Join us at FabCon Atlanta, March 16-20, for the ultimate Fabric, Power BI, AI and SQL community-led event. Save $200 with code FABCOMM.