Don't miss your chance to take the Fabric Data Engineer (DP-700) exam on us!
Learn moreWe've captured the moments from FabCon & SQLCon that everyone is talking about, and we are bringing them to the community, live and on-demand. Starts on April 14th. Register now
We have two roles: "Global VIP" and "Global".
VIP gets to see everything, while non-VIP (Global) are not to see one specific column (measure).
This is solved in our model in Tabular editor; on the specific column (in the fact table), the non-VIP (here called Global) has object level security set to "None", while the VIP one has default.
These RLS groups are populated by AD groups.
Problem arises if a person belongs to AD groups in both, that is eg a person is in group "sales personnel" which belongs to "Global", and group "managers" which is VIP. This leads to a conflict and person can't see anything based on this model.
(The AD groups are out of my control)
Any suggestions?
Preferrably I would like the more elevated role to take precedence.
Preferrably I would like the more elevated role to take precedence.
Define "elevated". By default the more permissive rule overrides the more restrictive rule.
In my case the "elevated" role would be the "Global VIP" role which has the object level security set to default, while the "Global" role has it set to None.
I have no experience with OLS, but it sounds like you either need to drop the requirement or create separate reports.
If you have recently started exploring Fabric, we'd love to hear how it's going. Your feedback can help with product improvements.
A new Power BI DataViz World Championship is coming this June! Don't miss out on submitting your entry.
Share feedback directly with Fabric product managers, participate in targeted research studies and influence the Fabric roadmap.
| User | Count |
|---|---|
| 52 | |
| 38 | |
| 37 | |
| 19 | |
| 18 |
| User | Count |
|---|---|
| 69 | |
| 64 | |
| 37 | |
| 32 | |
| 21 |