Forum Discussion
RLS on a PowerBI semantic model - OneLake Catalog
- 1 year ago
Hi CarlBlunck ,
Thanks for providing the additional details.
RLS continues to work even if the report is published to a different workspace and then shared, so workspace-level access is not a factor here.
The USERPRINCIPALNAME() function always returns the signed-in user’s UPN. If that value does not exist in the workemail column of your security table, the filter evaluates to FALSE() for all rows, which results in the user seeing a blank report. This is the expected outcome since RLS only allows data access to users that are present in the filter table.
It is also important to ensure that the role you defined in Desktop is actually assigned in the Power BI Service. If the role is not assigned, the user effectively has no access, and the report will appear blank.
Finally, since there is a many-to-many relationship between the RLS filter tables, that can cause filters not to propagate correctly and lead to unexpected or empty results. Redesigning the model to avoid many-to-many relationships in the RLS filtering path is generally recommended.
Hope this helps. Please reach out for further assistance.
Thank you.
Hi CarlBlunck ,
Thanks for confirming. Yes, based on what you described, my repro produced a different outcome. In my case RLS applied correctly in the second (thin) report.
A couple of additional points to double-check on your side, since they can affect whether RLS applies as expected:
>>Make sure the test user isn’t assigned a workspace role such as Admin, Member, or Contributor, because RLS will not apply if the user has those permissions.
>>After assigning the user to the RLS role in the service, ensure you click Save so the role assignment actually takes effect.
These can sometimes be overlooked and may explain the difference in behavior.
Would you be able to confirm how the test user was added to the report - only through RLS role assignment, or were they also granted a workspace role?
Thank you.
Hi v-veshwara-msft,
Can confirm the user is not assigned a workspace role.
Can also confirm that when I test the user's access in the 1st report, RLS kicks in and the result they see if correct.
However when I share the 2nd report with them, RLS is not kicking in and the result they are seeing is incorrect.
So I'm stumped haha.
Thanks
Carl
- v-veshwara-msft1 year ago
Community Support
Hi CarlBlunck ,
Thanks for confirming the checks.
Here’s what I did that worked in my repro:
-
Created the RLS role in Desktop.
Report:RLS Role:
-
Published the report with RLS applied to the Service.
-
In the Service, selecting security by clicking on 3 dots of the semantic model, assigned users to the role created in Desktop and saved the changes.
-
In Desktop, connected to the published semantic model through the OneLake Catalog.
-
Built visuals in the new report.
-
Published this second report back to the Service.
-
Shared the second report with the same users assigned in Step 3.
The users were able to see data with RLS applied as expected.
Are these steps similar to what you followed? Please revert back if there are any differences from your approach.
Hope this helps. Please reach out for further assistance.
Thank you.
- v-veshwara-msft1 year ago
Community Support
Hi CarlBlunck ,
Just wanted to check if the response provided was helpful. If further assistance is needed, please reach out.
Thank you.
-