Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Register now to learn Fabric in free live sessions led by the best Microsoft experts. From Apr 16 to May 9, in English and Spanish.

Reply
Oluduroj
New Member

RLS Help

Hi,

So I have RLS configured and it works as intended when I add members to my defined role. I currently have my report published to the BI group with 5 team members belonging to the BI group. In my test I tried the UPN for one of the group members and I was able to view the report using his name when testing the role even though he isn't a member of my defined role. Is this meant to happen?

1 ACCEPTED SOLUTION
Anonymous
Not applicable

@Oluduroj

When you say the user was able to view the report, do you mean he was able to view the report under the reports list in the navigation bar? or were you referring to data/rows within the report? RLS would only work on the rows (data), reports would still be viewable. If you want to hide the reports, then you'll have to categorise them into different workspaces or groups. 

 

And, users mark as admins can see all data within a report regardless of the role, in other words, admin previliges override your role.

 

Thanks

Kaz

View solution in original post

4 REPLIES 4
Eric_Zhang
Employee
Employee

@Oluduroj

 

Based on my test,

  1. An admin of a workgroup is not be affected by RLS roles.
  2. A member of a workgroup is not be affected by RLS roles, if he is not in any RLS role, namely he is able to view all data when he is not in any role. When he is in some role, he can only view the filtered data.

 

Anonymous
Not applicable

@Oluduroj

When you say the user was able to view the report, do you mean he was able to view the report under the reports list in the navigation bar? or were you referring to data/rows within the report? RLS would only work on the rows (data), reports would still be viewable. If you want to hide the reports, then you'll have to categorise them into different workspaces or groups. 

 

And, users mark as admins can see all data within a report regardless of the role, in other words, admin previliges override your role.

 

Thanks

Kaz

Thanks for the response, I figured as much that admin can see all data, the weird thing though is when i test the role in Power BI desktop and i use my username my report returns blank, but when i test in the online version i am able to see the report.

ankitpatira
Community Champion
Community Champion

@Oluduroj When you use UPN you still have to add invidiual members you want to share report with to just one role and then use user security table in your database to do the filtering.

Helpful resources

Announcements
Microsoft Fabric Learn Together

Microsoft Fabric Learn Together

Covering the world! 9:00-10:30 AM Sydney, 4:00-5:30 PM CET (Paris/Berlin), 7:00-8:30 PM Mexico City

PBI_APRIL_CAROUSEL1

Power BI Monthly Update - April 2024

Check out the April 2024 Power BI update to learn about new features.

April Fabric Community Update

Fabric Community Update - April 2024

Find out what's new and trending in the Fabric Community.

Top Kudoed Authors