Starting December 3, join live sessions with database experts and the Microsoft product team to learn just how easy it is to get started
Learn moreGet certified in Microsoft Fabric—for free! For a limited time, get a free DP-600 exam voucher to use by the end of 2024. Register now
Hello,
The topic of Segregation of Duties (SoD) monitoring comes up frequently and now I am wondering how to make an analytical report that can show conflicts in SoD
I have two tables, one shows a list of users and a list of security groups that are assigned and the second table shows which security groups are in conflict with each other.
Does anyone have experience with such reports? and how to find users who are members of conflicting security groups.
Solved! Go to Solution.
I'm making some assumptions about your model. Firstly, the list of users and security groups has multiple rows for each user, one row per security group they are a member of. Secondly, the conflicting security groups table has a primary group column and a conflicting group column, such that if groups A and B were conflicting there would be 2 rows in the table - one with A as primary and B as conflict and a second row with B as primary and A as conflict.
Given that, you could create a user dimension table like
Users = ALLNOBLANKROW('User security group'[User])
and then create a one-to-many relationship from the new dimension table to the user groups table. Add a new column to the dimension table like
Is in conflicting groups =
VAR UserGroups =
VALUES ( 'User security group'[group] )
VAR ConflictingGroups =
CALCULATETABLE (
VALUES ( 'Conflicting groups'[conflicting group] ),
TREATAS ( UserGroups, 'Conflicting groups'[Primary group] )
)
VAR Result =
NOT ISEMPTY ( INTERSECT ( UserGroups, ConflictingGroups ) )
RETURN
Result
would a simple COUNTROWS on the user table work ?
I'm making some assumptions about your model. Firstly, the list of users and security groups has multiple rows for each user, one row per security group they are a member of. Secondly, the conflicting security groups table has a primary group column and a conflicting group column, such that if groups A and B were conflicting there would be 2 rows in the table - one with A as primary and B as conflict and a second row with B as primary and A as conflict.
Given that, you could create a user dimension table like
Users = ALLNOBLANKROW('User security group'[User])
and then create a one-to-many relationship from the new dimension table to the user groups table. Add a new column to the dimension table like
Is in conflicting groups =
VAR UserGroups =
VALUES ( 'User security group'[group] )
VAR ConflictingGroups =
CALCULATETABLE (
VALUES ( 'Conflicting groups'[conflicting group] ),
TREATAS ( UserGroups, 'Conflicting groups'[Primary group] )
)
VAR Result =
NOT ISEMPTY ( INTERSECT ( UserGroups, ConflictingGroups ) )
RETURN
Result
@johnt75 In the Matrix table, in the rows - the main group, in the column - the conflicting group, how to show in the Values the number of users?
would a simple COUNTROWS on the user table work ?
-
Hi,
Share some data, describe the question and show the expected result.
Starting December 3, join live sessions with database experts and the Fabric product team to learn just how easy it is to get started.
March 31 - April 2, 2025, in Las Vegas, Nevada. Use code MSCUST for a $150 discount! Early Bird pricing ends December 9th.
User | Count |
---|---|
94 | |
92 | |
83 | |
71 | |
49 |
User | Count |
---|---|
143 | |
120 | |
110 | |
60 | |
57 |