Forum Discussion

CarlBlunck's avatar
CarlBlunck
Icon for Resolver I rankResolver I
1 year ago
Solved

RLS on a PowerBI semantic model - OneLake Catalog

Hi, I created a semantic model that has RLS applied to it and published this online.  In a new pbix file, I connected to this semantic model through the OneLake Catalog and create a new report. In...
  • v-veshwara-msft's avatar
    v-veshwara-msft
    1 year ago

    Hi CarlBlunck ,

    Thanks for providing the additional details.

    RLS continues to work even if the report is published to a different workspace and then shared, so workspace-level access is not a factor here.

     

    The USERPRINCIPALNAME() function always returns the signed-in user’s UPN. If that value does not exist in the workemail column of your security table, the filter evaluates to FALSE() for all rows, which results in the user seeing a blank report. This is the expected outcome since RLS only allows data access to users that are present in the filter table.

     

    It is also important to ensure that the role you defined in Desktop is actually assigned in the Power BI Service. If the role is not assigned, the user effectively has no access, and the report will appear blank.

     

    Finally, since there is a many-to-many relationship between the RLS filter tables, that can cause filters not to propagate correctly and lead to unexpected or empty results. Redesigning the model to avoid many-to-many relationships in the RLS filtering path is generally recommended.

     

    Hope this helps. Please reach out for further assistance.

    Thank you.