Forum Discussion
Trying to get roles needed for an RLS report using the APi
Hi,
I currently have an AppService that uses a service principal, and I'm trying to embed reports in an Angular application using a combination of a Microsoft user and a service principal to generate the embedded tokens. Everything works except that when I try to load RLS reports, I need to provide the proper roles, and I don't have an easy way to get those roles either from the user or from the PowerBI API. I have Tenant.ReadAll access, so I think that prevents me from using the admin APIs. Any advice is appreciated.
Hi,
Sorry for the late response. What I ended up doing was a combination of steps: I used the workspace analysis with the dataset to get the full list of roles on the report and who’s assigned to them. Since I already had the user’s email and the AD groups, I just compared them and pulled out the matches.
https://learn.microsoft.com/en-us/rest/api/power-bi/admin/workspace-info-post-workspace-info
https://learn.microsoft.com/en-us/rest/api/power-bi/admin/workspace-info-get-scan-result
9 Replies
- lbendlinSuper User
You can enumerate RLS roles in a semantic model via DMV queries.
select * from $SYSTEM.TMSCHEMA_ROLES
- luish_castrocRegular Visitor
Thanks for the response, im not familiar with that process since i'm using the powerbi REST api
- lbendlinSuper User
You can run a DMV query through the REST API.
Datasets - Execute Queries In Group - REST API (Power BI Power BI REST APIs) | Microsoft Learn
- v-nmadadi-msftCommunity Support
May I ask if you have resolved this issue? If so, please mark the helpful reply and accept it as the solution. This will be helpful for other community members who have similar problems to solve it faster.
Thank you.
- v-nmadadi-msftCommunity Support
Hi luish_castroc
I wanted to check if you had the opportunity to review the information provided. Please feel free to contact us if you have any further questions. If our responses has addressed your query, please accept it as a solution and give a 'Kudos' so other members can easily find it.
Thank you. - v-nmadadi-msftCommunity Support
As we haven’t heard back from you, we wanted to kindly follow up to check if the solution provided by the community members for the issue worked. If our response addressed, please mark it as Accept as solution and click Yes if you found it helpful.
Thanks
- luish_castrocRegular Visitor
Hi,
Sorry for the late response. What I ended up doing was a combination of steps: I used the workspace analysis with the dataset to get the full list of roles on the report and who’s assigned to them. Since I already had the user’s email and the AD groups, I just compared them and pulled out the matches.
https://learn.microsoft.com/en-us/rest/api/power-bi/admin/workspace-info-post-workspace-info
https://learn.microsoft.com/en-us/rest/api/power-bi/admin/workspace-info-get-scan-result