Forum Discussion

Anonymous's avatar
Anonymous
Not applicable
7 years ago

RLS issue: User belongs to two Azure-AD groups

My company's Azure AD structure is that all employees belong to a group for their country.

"Lisa" is a consultant and belongs to the Azure AD group called "Staff.Scotland". 

"Helen" is an HR representative and belongs to both "Staff.Scotland" and "Staff.HR". 

 

In Power BI, I've set the roles so that Staff.HR has more access to data in the reports than Staff.Scotland, but Helen's access rights are limited to Staff.Scotland's access rights. I've specifically put Helen into 'Staff.HR' in Power BI Services (Security). 

 

How do I make Power BI check Helen's access rights in the right order? 

1 Reply

  • dax's avatar
    dax
    Icon for Community Support rankCommunity Support

    Hi Preben,

     

    As I know, when you set multiple roles for the same user, the user will join these permissions together. So if Helen in tow roles, he/she will get permission of two roles.

    So you need to make sure you create two roles and make sure Helen in two groups. Or you also could try to add single users instead of group in role(dataset->security) to see whether it works or not. 

    Best Regards,
    Zoe Zhi

    If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.