Forum Discussion
Power BI with Databricks
Service Principal may not support user-based RLS because it uses app-only authentication.
You can use Guest Users Azure AD B2B from Tenant B in Tenant A so OAuth passes user identity and RLS works correctly.In Tenant A's Azure AD, invite users from Tenant B as guest users.
Assign these guest users the necessary permissions in Databricks (workspace, cluster, SQL warehouse).
In Power BI (Tenant B), connect to Databricks using OAuth and authenticate with the guest user's credentials.
Publish and test the report. RLS should work as the guest user's identity is passed through OAuth.
5 Replies
- BhavinVyas3003Super User
Yes, it's possible — but OAuth won't work across tenants. Use either:
- Service Principal: Register a service principal in Tenant A and grant it access to Databricks. Use it in Power BI in Tenant B.
- Guest User: Invite a user from Tenant B as a guest in Tenant A, assign Databricks access, and use that account in Power BI.
Best Practice: Use a Service Principal for scalable and secure access.
- YashikaAgrawalPost Patron
Thanks for the reply, We have RLS in reports, we are using OAuth, will the Service principal works..
- BhavinVyas3003Super User
Service Principal may not support user-based RLS because it uses app-only authentication.
You can use Guest Users Azure AD B2B from Tenant B in Tenant A so OAuth passes user identity and RLS works correctly.- YashikaAgrawalPost Patron
You can use Guest Users Azure AD B2B from Tenant B in Tenant A so OAuth passes user identity and RLS works correctly.
Can you please explain this step... Thanks,