cdok1091
Advocate II
9 years agoStatus:
Needs Votes
Enable RLS for reports connected to a live Power BI Service dataset
RLS roles are disabled for reports built on a live connection to a Power BI Service dataset. Please enable this functionality -- this is critical for the scalability of Power BI in my organization!
10 Comments
- fbcideas_migusrNew MemberI believe RLS still applies to online reports created from the dataset, but it can't be viewed in a desktop report created from the online dataset.
- rwalker1New MemberLuke is correct, we use this functionality heavily. the roles applied to the parent report are reflected in the child report. The View as Role should be accessible from the child report though. The inability to do this makes managing complex security rules a nightmare. We are going to have to revert back to our on premise SSAS model if this feature can't find it's way in soon which would be a sad day for us :(
- davide_x_sormanNew MemberI agree with proposal. "Test as role" online on child reports would be useful
- aemNew MemberThis is not correct. RLS is against the dataset not the child reports and dashboards. It works fine with live connections. However view as role in child reports is a must in big organisations. It's the only way to be sure!
- rajiv_e_dixitNew Membera very important feature pending from April, 2017 and not addressed yet. any possibility on this?
- luuk_oudevrieliNew MemberI have just posted my question in the community about this issue: (https://community.powerbi.com/t5/Desktop/Get-Power-BI-Datasets-in-Power-BI-Desktop-from-published-dataset/m-p/908794#M435575) Got response back to submit an new idea, but found in this case (kind of) the similar situation. When dataset creators create the dataset with RLS, publish the dataset in the PBI Service (and promote the dataset) and assign roles to the dataset security to certain users, I was expecting that users with viewer role can just see the report/dashboard, but contributors should be able to find the (promoted) dataset as a source in PBI Desktop to connect to in order to make their own (child) report, but now they can see the data without RLS. This is just a breach that has been secured through PBI Service, but broken by sharing it through the Contributor/Member role.... Possible solution? Who is signing in to the PBI Desktop and connect to the Dataset should be linked to the RLS Security role from the Parent Dataset? Any thoughts how to get this idea very very quickly and urgent to the Dev Team? Vote!
- Vijay_TyagiNew MemberThis is key to optimizing data sets & capacity usage, and must be enabled urgently to allow scalability of Power Users in Organisation happening to be under different roles & different divisions. Everyone creating their own data sets create struggles with the available premium capacity.
- pmingo1New MemberI have tried to build a report that uses a dataset with a RLS plus other data sources. The only way my user could see the data was by giving him admin role in the workspace where the first dataset was located, but then the RLS does not work. If he had only viewer access, he could not see any of the data from the first dataset.
Could anyone explain how did you manage to get this working?
- Dmitriy_PiryushNew Member
How many votes does it need to be implemented? This seems so obvious to be implemented with Live Connection to Power BI dataset functionality (which MS basically encourage people to use) but still it's not yet done. The only workaround is copying your original dataset to have 2 diff RLS scenarios. It's not very efficient...
- fbcideas_migusrNew MemberStatus added:Needs Votes
Recent ideas
Power BI, import report and semantic model: show change connection pop-up
When you need to import an existing Power BI report and semantic model in Tenant B that's created in Tenant A, you need to jump through a number of hoops to fix the original connection. It's doable, ...Reitse1 hour agoMost Valuable ProfessionalNew4Views1like0CommentsEnable per-user security for shared gateway connections using service accounts
When a shared gateway connection uses a highly privileged service account, all source queries run with that account’s permissions. Users cannot see the stored credentials, but report developers who c...AshishChougala1 hour agoMicrosoft EmployeeNew6Views3likes0CommentsRequest to add a feature to extract gateway connection status and last time credentials used
Could you please add a feature in the admin UI on Microsoft Fabric/Power BI to extract the Gateway connections with details of the gateway connection status and last activity information along with t...Vinodkumar_Chak3 hours agoNew MemberNew21Views1like0CommentsPower BI - incorrect handling of empty string parameter in DAX query in paginated report
Blank string parameters in paginated reports are treated as empty strings in Power BI Report Builder but as null values in the Power BI Service, resulting in incorrect report output. -> Create a pag...roshinikumarkar6 hours agoMicrosoft EmployeeNew25Views5likes0CommentsAllow NotebookUtils getSecret() to authenticate with Workspace Identity
Current behavior In Microsoft Fabric, notebookutils.credentials.getSecret() authenticates against Azure Key Vault using the identity of the user who executes the notebook. This behavior appli...tmihara8 hours agoNew MemberNew20Views1like1Comment