Forum Discussion
Share your thoughts on DirectQuery for Power BI datasets and Azure Analysis Services (preview)
I understand. Just surprised and sad that it is also needed for the viewers... Makes it unusable in our case...
Our situation is as follows: we have a big dataset with all the data and all the reports are based on it. Some people are only allowed to see volume columns, others can also see columns with actual $ values. It is our understanding that we cant use RLS or similar to hide the $ columns from people who are not supposed to see them (Spinning them into another dataset is not an option). If we give everyone in the organization the XMLA / Analyze in Excel option, the people who have access to some reports will be able to access also all the columns in that case, which is not acceptable... Are we thinking correctly? Thanks!
why cant you use RLS? can you not set RLS on the composite model?
- Anonymous5 years agoNot applicable
Because we would need column-level security. We do have row-level security set up. Basically, think of the data like this:
Region Volume Profit Region 1 11 12 Region 2 21 22 We have RLS set up sp that a user can only see data from Region 1. But we also need to be able to say that within that region the user can only see the column Volume, but not the column Profit.
Its ok if we only expose the Volume column in the report they are allowed to see. But once we give everyone access to Analyze in Excel, they will be able to see all the columns (indeed, only for their region but also the columns they arent supposed to see).
Right?
- jeroenterheerdt5 years ago
Microsoft Employee
right, so this is not a question about RLS, but about OLS 🙂 we are still defining the exact interaction with OLS, so stay tuned for that.