Forum Discussion

POSPOS's avatar
POSPOS
Icon for Post Partisan rankPost Partisan
1 year ago
Solved

How to have multiple roles

Hi All,

I have a requirement as below: 

I have 5 pages in the dashboard.

  • Pages 1,2,3,4 are coming from Table 1 and Table 2 and
  • Page 5 data is from Table 3.

There is a dynamic Row level security on Table 1 and 2, I have created a role a Role_user based on user login and users  see only the data they are supposed to see for Pages 1-4.
Now, specifically for Page 5 where the data is coming from Table 3, I want to ensure that the roles assigned to Role_User does not see that data.. I want to create a new role in Power BI and then assign a different user group who should be seeing the data.
Note, we do not have any user ID or user name column in Table 3.

Can anyone please advise on how to achieve this?

Thank you

  • Anonymous's avatar
    Anonymous
    1 year ago

    Hi POSPOS,

     

    Thanks for reaching out to the Microsoft Fabric Forum Community.

     

    The only solution I can Think off at the moment is

    Create a User Access Table with a level of access

    "Basic" users can see only Table1 & Table2 (Pages 1–4).

    "All" users can also see Table3 (Page 5).

     

    Then create roles

    For Table1 and Table2:
    LOOKUPVALUE(
    UserAccessControl[Access_Level],
    UserAccessControl[UserID],
    USERPRINCIPALNAME()
    ) IN { "Basic", "All" }


    For Table3:
    LOOKUPVALUE(
    UserAccessControl[Access_Level],
    UserAccessControl[UserID],
    USERPRINCIPALNAME()
    ) = "All"


    If this helped, please mark the response as the accepted solution and give it a thumbs-up so others can benefit too.

    Best regards,
    Prasanna Kumar

     

8 Replies

  • Deku's avatar
    Deku
    Icon for Super User rankSuper User

    For the first role set the RLS expression for table 3 to false().

     

    Then the second role can overwrite this with true().

    • POSPOS's avatar
      POSPOS
      Icon for Post Partisan rankPost Partisan

      Deku  - This is what I have for role 1:

      I want to create another Role 2, Not sure what code I should be using for Role 2 and where I should be mentioning True () or False()

      Note: All users assigned to Role 1 should only see page 1,2,3,4. Only users assigned to Role 2 should be seeing page 5. Also we do not have user name or user id in Table3. 

      Can you please provide detailed steps 

      • Deku's avatar
        Deku
        Icon for Super User rankSuper User

        The true false would be for table 3. If you want people to only see specific pages I would suggest splitting the report in two, from the same semantic model. Then you can publish as a app and use audiences so that each group with have conditional access to each report/set of pages 

  • Anonymous's avatar
    Anonymous
    Not applicable

    Hi POSPOS,

     

    Thanks for reaching out to the Microsoft Fabric Forum Community.

     

    The only solution I can Think off at the moment is

    Create a User Access Table with a level of access

    "Basic" users can see only Table1 & Table2 (Pages 1–4).

    "All" users can also see Table3 (Page 5).

     

    Then create roles

    For Table1 and Table2:
    LOOKUPVALUE(
    UserAccessControl[Access_Level],
    UserAccessControl[UserID],
    USERPRINCIPALNAME()
    ) IN { "Basic", "All" }


    For Table3:
    LOOKUPVALUE(
    UserAccessControl[Access_Level],
    UserAccessControl[UserID],
    USERPRINCIPALNAME()
    ) = "All"


    If this helped, please mark the response as the accepted solution and give it a thumbs-up so others can benefit too.

    Best regards,
    Prasanna Kumar

     

  • Anonymous's avatar
    Anonymous
    Not applicable

    Hi POSPOS,

     

    Just following up to see if the solution provided was helpful in resolving your issue. Please feel free to let us know if you need any further assistance.

    If the response addressed your query, kindly mark it as Accepted Solution and click Yes if you found it helpful  this will benefit others in the community as well.

     

    Best regards,

    Prasanna Kumar

  • Anonymous's avatar
    Anonymous
    Not applicable

    Hi POSPOS,

     

    We wanted to kindly check in to see if everything is working as expected after trying the suggested solution. If there’s anything else we can assist with, please don’t hesitate to ask.

    If the issue is resolved, we’d appreciate it if you could mark the helpful reply as Accepted Solution  it helps others who might face a similar issue.

     

    Warm regards,

    Prasanna Kumar

  • Anonymous's avatar
    Anonymous
    Not applicable

    Hi POSPOS,

     

    We wanted to kindly check in to see if everything is working as expected after trying the suggested solution. If there’s anything else we can assist with, please don’t hesitate to ask.

    If the issue is resolved, we’d appreciate it if you could mark the helpful reply as Accepted Solution  it helps others who might face a similar issue.

     

    Warm regards,

    Prasanna Kumar