Power BI is turning 10! Tune in for a special live episode on July 24 with behind-the-scenes stories, product evolution highlights, and a sneak peek at what’s in store for the future.
Save the dateEnhance your career with this limited time 50% discount on Fabric and Power BI exams. Ends August 31st. Request your voucher.
So right now I've a dashboard dedicated for A department. Moving forward, B and C department also wants the same dashboard.
The solution that I've come out is by appending data from B and C to A dashboard and apply RLS.
However, the issue is B and C wants the same dashboard as A but at the same time also requests several new visuals and new pages to A dashboard. For this issue, the solution that I was suggested is to list out all the pages in Excel Sharepoint including the new ones and restrict it to B & C users only. The thing is, B & C is a huge department and might involve thousands of users. It seems impossible to list every B & C users and pages that they can have access. Way forward, the Excel will be hard to maintain especially when there are new joiners.
To simplify:
1. RLS is applied to A, B & C department.
2. B & C department requests for different visuals and to add several new pages to A department's dashboard.
3. How to apply RLS for new pages and visuals in B & C dashboard when the users for both departments are in huge volume.
Really need some help and recommendations on how can I solve this.
Solved! Go to Solution.
The RLS is attached to the model, not the dashboards. You can make different dashboards using the same model and they will all get the RLS that is applied to the model. So I would reccomend a dashboard for each department all pointing to the same model.
For large organizations it is far easier to use active directory security groups to assign users to RLS roles. You assign the security groups to the role rather than the individual users.
My guess would be that your organization already has security groups for the departments so you can use the ones in place.
When a new user is added to one of the security groups that is assigned to a role in the model RLS, they will automatically have the RLS applied to them. The same is true if they change security groups, the would get the RLS from their new role.
You can also use the active directory groups to share the dashboards so each group would only see their dashboard and new users assinged to the active directory groups would automatically get access and have the RLS applied.
The RLS is attached to the model, not the dashboards. You can make different dashboards using the same model and they will all get the RLS that is applied to the model. So I would reccomend a dashboard for each department all pointing to the same model.
For large organizations it is far easier to use active directory security groups to assign users to RLS roles. You assign the security groups to the role rather than the individual users.
My guess would be that your organization already has security groups for the departments so you can use the ones in place.
When a new user is added to one of the security groups that is assigned to a role in the model RLS, they will automatically have the RLS applied to them. The same is true if they change security groups, the would get the RLS from their new role.
You can also use the active directory groups to share the dashboards so each group would only see their dashboard and new users assinged to the active directory groups would automatically get access and have the RLS applied.
User | Count |
---|---|
77 | |
74 | |
42 | |
32 | |
28 |
User | Count |
---|---|
100 | |
93 | |
52 | |
50 | |
48 |