Join us for an expert-led overview of the tools and concepts you'll need to pass exam PL-300. The first session starts on June 11th. See you there!
Get registeredPower BI is turning 10! Let’s celebrate together with dataviz contests, interactive sessions, and giveaways. Register now.
We have two roles: "Global VIP" and "Global".
VIP gets to see everything, while non-VIP (Global) are not to see one specific column (measure).
This is solved in our model in Tabular editor; on the specific column (in the fact table), the non-VIP (here called Global) has object level security set to "None", while the VIP one has default.
These RLS groups are populated by AD groups.
Problem arises if a person belongs to AD groups in both, that is eg a person is in group "sales personnel" which belongs to "Global", and group "managers" which is VIP. This leads to a conflict and person can't see anything based on this model.
(The AD groups are out of my control)
Any suggestions?
Preferrably I would like the more elevated role to take precedence.
Preferrably I would like the more elevated role to take precedence.
Define "elevated". By default the more permissive rule overrides the more restrictive rule.
In my case the "elevated" role would be the "Global VIP" role which has the object level security set to default, while the "Global" role has it set to None.
I have no experience with OLS, but it sounds like you either need to drop the requirement or create separate reports.
This is your chance to engage directly with the engineering team behind Fabric and Power BI. Share your experiences and shape the future.
Check out the June 2025 Power BI update to learn about new features.
User | Count |
---|---|
81 | |
75 | |
60 | |
37 | |
33 |
User | Count |
---|---|
102 | |
56 | |
52 | |
46 | |
40 |