Don't miss your chance to take the Fabric Data Engineer (DP-700) exam on us!
Learn moreWe've captured the moments from FabCon & SQLCon that everyone is talking about, and we are bringing them to the community, live and on-demand. Starts on April 14th. Register now
I am working on automating CI/CD for semantic models in Power BI / Fabric.
I can successfully deploy semantic models and define RLS/OLS roles using TMDL, but I am unable to automate the assignment of users or Azure AD groups to those roles.
At the moment, role membership must be added manually through the semantic model security UI.
Is there any supported way to automate role membership for RLS/OLS, for example via:
- Power BI REST API
- XMLA endpoint / TOM
- Fabric REST APIs
My goal is a fully automated, repeatable deployment without manual post-deployment steps.
Solved! Go to Solution.
Hi @FrederikAage,
currently there is no out of the box and automated solution for that in Fabric.
Check out the following post not too long ago which might help you out with a third party tool:
Solved: How to migrate RLS roles assignment between datase... - Microsoft Fabric Community
Best regards!
PS: If you find this post helpful consider leaving kudos or mark it as solution
Hi @FrederikAage ,
Thanks for reaching out to the Microsoft Fabric Community forum.
Another approach other than the valuable one suggested by @Mauro89 for assigning Row-Level Security (RLS) membership in Power BI is to use Microsoft Entra security groups. RLS roles are defined in Power BI Desktop and published to the Power BI Service, after which Entra ID security groups are assigned to those roles as a one time configuration.
Source: Row-level security (RLS) with Power BI - Microsoft Fabric | Microsoft Learn
Please follow this article on how to automate creating security groups:
Configure group settings using PowerShell - Microsoft Entra ID | Microsoft Learn
I hope this information helps. Please do let us know if you have any further queries.
Thank you
May I check if this issue has been resolved? If not, Please feel free to contact us if you have any further questions.
Thank you
Hi @FrederikAage
I wanted to check if you had the opportunity to review the information provided. Please feel free to contact us if you have any further questions.
Thank you.
Hi @FrederikAage ,
Thanks for reaching out to the Microsoft Fabric Community forum.
Another approach other than the valuable one suggested by @Mauro89 for assigning Row-Level Security (RLS) membership in Power BI is to use Microsoft Entra security groups. RLS roles are defined in Power BI Desktop and published to the Power BI Service, after which Entra ID security groups are assigned to those roles as a one time configuration.
Source: Row-level security (RLS) with Power BI - Microsoft Fabric | Microsoft Learn
Please follow this article on how to automate creating security groups:
Configure group settings using PowerShell - Microsoft Entra ID | Microsoft Learn
I hope this information helps. Please do let us know if you have any further queries.
Thank you
Hi @FrederikAage,
currently there is no out of the box and automated solution for that in Fabric.
Check out the following post not too long ago which might help you out with a third party tool:
Solved: How to migrate RLS roles assignment between datase... - Microsoft Fabric Community
Best regards!
PS: If you find this post helpful consider leaving kudos or mark it as solution
If you have recently started exploring Fabric, we'd love to hear how it's going. Your feedback can help with product improvements.
A new Power BI DataViz World Championship is coming this June! Don't miss out on submitting your entry.
Share feedback directly with Fabric product managers, participate in targeted research studies and influence the Fabric roadmap.
| User | Count |
|---|---|
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |