Forum Discussion
need help with semantic model permissions
- Anonymous1 year ago
Hi info_algoritmia,
Thank you for reaching out to the Microsoft Fabric Forum Community.
1. Losing “Show data table” after editing auto-generated reports, This is expected behavior. Once you edit or duplicate an auto-generated report, Power BI treats it as a regular report. The special “Show data table” feature is only available in auto-generated reports and is not preserved after manual edits. There is currently no supported way to retain that feature after editing or customizing the report.
2. External users with Read access can still “View semantic model”: Yes, even without Build permission, if the user has read access to the report connected to a dataset in a different workspace, and that dataset is discoverable, Power BI may still allow "View semantic model", though they can’t change or use it. This is by design to allow traceability and transparency. Unfortunately, this view cannot be removed entirely via report or dataset settings alone.
3. To disable semantic model exploration for external users, go to the Power BI Admin Portal (requires admin rights), then navigate to Tenant settings. Under Export and sharing settings, turn off or restrict the following options, “Allow users to view and interact with semantic models in the Data hub”, “Allow semantic model export to Excel”, and “Allow build for external users”. These settings can be scoped to specific security groups to ensure external or guest users are excluded from accessing the semantic model.
If you find this response helpful, please consider marking it as the accepted solution and giving it a thumbs-up to support others in the community.
Thank you & regards,
Prasanna Kumar
Hi info_algoritmia,
Thank you for reaching out to the Microsoft Fabric Forum Community.
To prevent external users from accessing your semantic model while still allowing them to view report data, use Power BI's auto-generated reports (like Quick Insights or "Create report" from the Service), which enable the “Show data table” option but restrict semantic model access. Avoid creating reports manually in Power BI Desktop or giving Build permissions to external users. Instead, manage access via apps with view-only permissions and use tenant settings to disable model exploration and data export. For customization, duplicate an auto-generated report to retain its restricted behavior.
If you find this response helpful, please consider marking it as the accepted solution and giving it a thumbs-up to support others in the community.
Thank you & regards,
Prasanna Kumar
Anonymous
- after duplicating the auto generated report and edit it the report loses the "show data table" option and then again the "View semantic model" option appears
- I'm only giving access to external guest users via app, so they have Read permissions, no build permissions, they can see the semantic model but without making changes or use it at all BUT still can see it, and don't need that
- what would be this option "use tenant settings to disable model exploration and data export." and where to find it? I don't want external users to see the data model
- Anonymous1 year agoNot applicable
Hi info_algoritmia,
Thank you for reaching out to the Microsoft Fabric Forum Community.
1. Losing “Show data table” after editing auto-generated reports, This is expected behavior. Once you edit or duplicate an auto-generated report, Power BI treats it as a regular report. The special “Show data table” feature is only available in auto-generated reports and is not preserved after manual edits. There is currently no supported way to retain that feature after editing or customizing the report.
2. External users with Read access can still “View semantic model”: Yes, even without Build permission, if the user has read access to the report connected to a dataset in a different workspace, and that dataset is discoverable, Power BI may still allow "View semantic model", though they can’t change or use it. This is by design to allow traceability and transparency. Unfortunately, this view cannot be removed entirely via report or dataset settings alone.
3. To disable semantic model exploration for external users, go to the Power BI Admin Portal (requires admin rights), then navigate to Tenant settings. Under Export and sharing settings, turn off or restrict the following options, “Allow users to view and interact with semantic models in the Data hub”, “Allow semantic model export to Excel”, and “Allow build for external users”. These settings can be scoped to specific security groups to ensure external or guest users are excluded from accessing the semantic model.
If you find this response helpful, please consider marking it as the accepted solution and giving it a thumbs-up to support others in the community.
Thank you & regards,
Prasanna Kumar