Forum Discussion
Power BI App Allowing Share Access to Semantic Model
- Anonymous1 year ago
Hi YeahMan ,
Thank you for confirming that removing Report B, republishing the app, uploading a new copy, and re-adding it resolved the extra Share semantic model option. This reset created a new semantic model without leftover permissions.
For future updates, use a clean workspace, publish new copies of each report, and keep viewers on App-only access. Also, check the Audience › Advanced settings and Manage Permissions after each update; tenant-level or model-level “Build” restrictions can provide additional security if needed.
Please mark the helpful reply and accept it as the solution. This will be helpful for other community members who have similar problems to solve it faster.
Thank you.
Hi YeahMan,
When you click Update App and navigate to the Audience section, there is an advanced section. Are the options checked there?
Also, did you check to see if Heather is a member of one of the groups that has read access?
Did my answer(s) help you? Give it a kudos by clicking the Thumbs Up! ?
Did my post answer your question(s)? Mark my post as a solution. This will help others find the solution.
- YeahMan1 year agoFrequent Visitor
Hi Watsky Thanks for responding. The options are not selected under the advanced section and Heather is not a member of any of the groups with Read access to the model or the report. Thanks for the Groups suggestion - I hadn't thought of checking that one.
- Watsky1 year ago
Solution Sage
I really think that Heather is part of group that has the access. I just ran a test where I have a service account that does not have access to a specific workspace, but gave it access to an App.
When I go to load the semantic model I am getting this error:
Then I added a security group that the has the service account in it.
Now, the service account has access to Share.
App only access does not grant access to view the semantic model. You have have at least Contributor access and App is only view access. So, if Heather can see the Semantic page then she has more than just App access some where.
If you can, have Heather on a call and change the permissions of the groups to viewer and have her try and see if any are changing her permissions.
Did my answer(s) help you? Give it a kudos by clicking the Thumbs Up! ?
Did my post answer your question(s)? Mark my post as a solution. This will help others find the solution.- YeahMan1 year agoFrequent Visitor
Hi,
As near as we can tell she doesn't belong to any groups, but we'll keep digging. Thanks for everything so far.
Because reportA is behaving the way it should in the app, could there be something in the report settings on reportB either in service or desktop that could be mucking us up?