Forum Discussion
Org App doesn't grant semantic model access although report and model are in the same workspace
Hello everyone,
we are currently investigating a permission issue related to a Power BI Org App.
Environment
We are using a Power BI Org App.
The reports included in the app are based on a central Power BI semantic model.
Both the reports and the semantic model are located in the same workspace.
Expected Behavior
Based on our understanding, access to the Org App should also provide the required access to the underlying semantic model.
Observed Behavior
Users can access the Org App and view the reports, but access to the underlying semantic model does not appear to be granted automatically, or at least not effectively.
To the best of our knowledge, this is an Org App and not a classic workspace app. Any insights or suggestions regarding the following questions would be greatly appreciated.
Has anyone experienced similar behavior with Org Apps?
Are there any known prerequisites, limitations, or special scenarios where semantic model permissions are not automatically propagated through the app?
What checks or troubleshooting steps would you recommend?
Thank you in advance.
Hi P108 , Thanks for the clarification. If users can fully open and interact with the reports in the Org App without any errors, then Power BI is already providing the required access for report consumption, even if explicit permissions are not visible on the underlying semantic model itself.
However, if reports or visuals are failing with semantic model access errors, then the deployment pipeline/Git deployment detail could be relevant, especially if the reports and semantic model were deployed or rebound separately.
If that is the case, please verify that the app was republished after deployment and confirm the reports are still correctly connected to the semantic model in the target workspace. Also check whether any RLS roles or composite/chained semantic models are involved.
7 Replies
- Shai_Karmani
Super User
This is actually expected behavior with Org Apps. Granting users access to the app gives them implicit Read on the underlying semantic model only for the queries served through the report visuals in the app. It does not grant Build, which is why anything that needs to talk to the model directly fails (Analyze in Excel, building a new report on top of the model, XMLA endpoint access, copying the report, etc).
The clean fix without re-sharing the workspace is in Manage app. Open Manage app, go to the Audience tab, expand the audience and find the dataset / semantic model permissions, and turn on "Allow recipients to build content with the data associated with this app". Then republish. After republish, the audience gets Build on the model alongside the app.
If you only want a subset of users to build, skip the app setting and grant Build directly on the semantic model from its workspace (Manage permissions on the model). Either path gives them what they are missing now. App audience changes only take effect after republishing, so any change there must be followed by Update app.
If this helped, a thumbs up and accepting the solution would be appreciated.
Best regards,
Shai Karmani - Ruba_hassan
Advocate II
The issue is most likely not with the Org App itself. Access to an Org App does not always grant Build permission on the underlying semantic model. As a result, users can view reports within the app, but they cannot directly access the semantic model or use it to create new reports.
Recommended troubleshooting steps:
1. Verify the permissions assigned to the semantic model.
2. Ensure that the affected users or security groups have been granted Build permission in addition to Read access.
3. Review any Composite Models or chained semantic model dependencies and confirm that permissions are correctly assigned across all related models.
4. Check whether Row-Level Security (RLS) or other security configurations are affecting access.
5. Republish the app after making any permission changes and validate the behavior with a test user account
- rampie
Kudo Commander
Hi,
When you share an app, your audience automatically receives Read permissions on the underlying semantic models to view the reports, but they do not get Build rights by default. In the Manage audience access pane of the app, expand Advanced and enable “Allow users to build content with the semantic models in this app.” This setting grants Build permissions on the models included and lets your users connect to them from the Dataset hub or Excel.
If the semantic model is stored in a different workspace, the app cannot propagate Build permissions across workspaces – you need to add the users to that workspace as at least Viewer or explicitly grant them Build on the dataset. Also be aware that if the model uses row‑level security, users must belong to one of its RLS roles to see data even when they have Build rights.
Hope this helps!
- v-hashadapu
Community Support
Hi P108 , Thank you for reaching out to the Microsoft Community Forum.
We find the answers shared by Shai_Karmani , rampie , parry2k & Ruba_hassan are correct. Can you please confirm if the solution worked for you. It will help others with similar issues find the answer easily.
Thank you rampie , Shai_Karmani parry2k & Ruba_hassan for your valuable responses.
- P108Frequent Visitor
Thank you all for your responses, and apologies for the delayed follow-up.
I may not have described the scenario clearly enough. The issue is not about users creating their own reports or requiring Build permissions on the semantic model.
The report is published through an Org App and is based on a shared semantic model. Users can access the Org App, but the required permissions on the underlying semantic model do not appear to be propagated as expected.
One additional detail that may be relevant: the semantic model was deployed independently of the reports via a deployment pipeline (Git repository).
- v-hashadapu
Community Support
Hi P108 , Thanks for the clarification. If users can fully open and interact with the reports in the Org App without any errors, then Power BI is already providing the required access for report consumption, even if explicit permissions are not visible on the underlying semantic model itself.
However, if reports or visuals are failing with semantic model access errors, then the deployment pipeline/Git deployment detail could be relevant, especially if the reports and semantic model were deployed or rebound separately.
If that is the case, please verify that the app was republished after deployment and confirm the reports are still correctly connected to the semantic model in the target workspace. Also check whether any RLS roles or composite/chained semantic models are involved.