Forum Discussion
Power BI REST API gives 403 error (User does not have access to group)
- 7 years ago
It seems I found the hidden setting:
https://community.powerbi.com/t5/Service/Manage-Permissions-in-Power-BI-Service/td-p/322832
Apparently, the dataset in the workspace requires the user to be added with "Manage permissions"...
After I did that, the error disappeared.
Very illogical, since Manage permissions seems to be related to sharing...
Using the following code:
System.Net.WebException ex;
Stream stream = ((System.Net.HttpWebResponse)(ex).Response).GetResponseStream();
using (StreamReader sr = new StreamReader(stream))
{
string text = sr.ReadToEnd();
}
I was able to extract more detailed error information from the exception:
{"error":
{"code":"Unauthorized","message":"User(<ii>76e423fd-314d-42ff-ab23-306f25c46aea</ii>) does not have access to Group(<ii>2c6f2b64-162d-40c8-934e-44e3075c5ee8</ii>) with Permissions(ReadWrite)"}
}This is the scope part of the decoded token (which doesn't work):
scp: "Dataset.ReadWrite.All Workspace.ReadWrite.All",
This is the same part, when using my own credentials (which works):
scp: "Dataset.ReadWrite.All Workspace.ReadWrite.All",
They are equal...
- tripleacoder7 years agoHelper I
Why doesn't the user have access to the group/workspace? I have made it owner/admin...
Also, I get the same error when instead of retrieving a dataset id, I try to create a new dataset in the same group.
Is it necessary to make the user Power BI Service Administrator?
- v-jiascu-msft7 years agoMicrosoft Employee
Hi tripleacoder,
1. Which API exactly is it?
2. Which token did you send with the request? Is it the one starts with "eyJ0e" or the one starts with "H4sIAAA"? It should be the former.
3. Are there any other message about the error?
Best Regards,
- tripleacoder7 years agoHelper I
It seems I found the hidden setting:
https://community.powerbi.com/t5/Service/Manage-Permissions-in-Power-BI-Service/td-p/322832
Apparently, the dataset in the workspace requires the user to be added with "Manage permissions"...
After I did that, the error disappeared.
Very illogical, since Manage permissions seems to be related to sharing...