Forum Discussion
RLS / PLS for large-audience reports
- 4 years ago
JrBIAnalyst See if this works for you:
You need to create two security roles:
Admin
Basic User
Filter the Basic User to only see the pages you want them to access, don't filter the Admin role. In PowerBI.com, put 'Everyone except external users' in the Basic User role and put the Admin AAD group in the Admin role.
Hi JrBIAnalyst ,
In the Power BI service, you can add a member to the role by typing in the email address or name of the user or security group. You can't add Groups created in Power BI. You can add members external to your organization.
You can use the following groups to set up row level security.
- Distribution Group
- Mail-enabled Group
- Security Group
Note, however, that Office 365 groups are not supported and cannot be added to any roles.
If you publish your Power BI Desktop report to a new workspace experience in the Power BI service, the RLS roles are applied to members who are assigned to the Viewer role in the workspace. Even if Viewers are given Build permissions to the dataset, RLS still applies. For example, if Viewers with Build permissions use Analyze in Excel, their view of the data will be protected by RLS. Workspace members assigned Admin, Member, or Contributor have edit permission for the dataset and, therefore, RLS doesn’t apply to them.
If you want RLS to apply to people in a workspace, you can only assign them the Viewer role.
For more information, please see:Row-level security (RLS) with Power BI
Hope it helps,
Community Support Team _ Caitlyn
If this post helps then please consider Accept it as the solution to help the other members find it more quickly.