This is best Fabric, Power BI, SQL and AI community event. How do we know? The last event sold out! Save €200 with code FABCMTY200.
Register nowA new Data Days event is coming soon! This time we’re going bigger than ever. Fabric, Power BI, SQL, AI and more. Don't miss out.
Hi all!
my situation it that i have this kind of structure:
father AAD group --> (person A, personB, sonAADgroup1, sonAADgroup2)
the two son AAD group had people in it
i have some rule on my semantic model:
ALL
group 1 --> with sonAADgroup1 in it
group 2 --> with sonAADgroup2 in it
where i should add my father grupo to let people A and B to see everythin?
my doubt is that if i do a thing like that:
ALL --> with fatherAAD in it
group 1 --> with sonAADgroup1 in it
group 2 --> with sonAADgroup2 in it
then sonAADgroup1 and sonAADgroup2 will see everything because they are in the father, and father can see all
Solved! Go to Solution.
Hi @GiudiDavi,
Power BI does not expand nested Azure AD group membership for RLS evaluation.
Only direct membership is considered.
This means:
Adding the parent AAD group to the ALL role will give full access only to the direct members (Person A and Person B).
Members of the child groups will not inherit access to the ALL role, even though their groups are nested inside the parent group in Azure AD.
Nested group expansion is not supported in Power BI’s RLS resolution process.
If this response was helpful in any way, I’d gladly accept a kudo.
Please mark it as the correct solution. It helps other community members find their way faster.
Connect with me on LinkedIn
Correct structure:
ALL role → father AAD group (A, B, son1, son2)
Group1 role → sonAADgroup1 only
Group2 role → sonAADgroup2 only
AAD nesting expands members transitively. Sons get ALL + their specific role = unrestricted access. Use separate non-nested groups for A/B if needed.
Hi @GiudiDavi,
Power BI does not expand nested Azure AD group membership for RLS evaluation.
Only direct membership is considered.
This means:
Adding the parent AAD group to the ALL role will give full access only to the direct members (Person A and Person B).
Members of the child groups will not inherit access to the ALL role, even though their groups are nested inside the parent group in Azure AD.
Nested group expansion is not supported in Power BI’s RLS resolution process.
If this response was helpful in any way, I’d gladly accept a kudo.
Please mark it as the correct solution. It helps other community members find their way faster.
Connect with me on LinkedIn
can you please confirm taht the visibility of objects inside the workspace is inherited?
if i gave my fathergroup viewer role on the workspace then someone inside the songroupA access power bi they will see the workspace
Check out the May 2026 Power BI update to learn about new features.
Sign up to receive a private message when registration opens and key events begin.
If you have recently started exploring Fabric, we'd love to hear how it's going. Your feedback can help with product improvements.
| User | Count |
|---|---|
| 32 | |
| 26 | |
| 23 | |
| 22 | |
| 15 |
| User | Count |
|---|---|
| 63 | |
| 45 | |
| 28 | |
| 24 | |
| 22 |