Forum Discussion
Power BI Security question
- 8 years ago
Hi ShaunBrewer,
I don't believe I will have problems with read only users, my concern is with report creators in the seperate divisions, these staff should not have access to other divisions data. However I can't see a way to bock report creators once the access is via the gateway.
While these users are internal I can control access to the data by creating divisional views and limiting access to these veiws by AD groups. However I am concerned that once in the cloud and accessing data via the gateway this control is lost?
If you have set the limit permission in the database, then when the report creator fetches data from Power BI Desktop, it can only fetch the corresponding data. When you publish the report to PowerBi Service and configure the gateway. The permissions you have set in SQL Server will not be invalid, because the gateway just refreshes the data.
Best Regards,
Cherry
Hi ShaunBrewer,
I don't believe I will have problems with read only users, my concern is with report creators in the seperate divisions, these staff should not have access to other divisions data. However I can't see a way to bock report creators once the access is via the gateway.
While these users are internal I can control access to the data by creating divisional views and limiting access to these veiws by AD groups. However I am concerned that once in the cloud and accessing data via the gateway this control is lost?
If you have set the limit permission in the database, then when the report creator fetches data from Power BI Desktop, it can only fetch the corresponding data. When you publish the report to PowerBi Service and configure the gateway. The permissions you have set in SQL Server will not be invalid, because the gateway just refreshes the data.
Best Regards,
Cherry
After experimenting this makes sense.
I had assumed you could develop reports in the cloud using the gateway as a power user, however it appears you can only develop the report with the Desktop tool and therefore permissions are handled normally not using the gateway credentials.
Thanks
Shaun