Anusha66
Advocate IV
9 months agoStatus:
New
Restrict Edit Access on Semantic Models for Report Developers
Currently, all report developers who build reports from a semantic model in Microsoft Fabric require Edit Access to the model. Without this permission, they cannot create reports, as the option is unavailable.
This approach poses challenges, especially with Direct Lake models, where data resides in Fabric itself. In many scenarios, organizations may have one large semantic model serving multiple developers. Granting edit access to all report developers introduces risks such as accidental changes to the model, governance issues, and lack of isolation between roles.
Proposed Enhancement:
- Introduce role separation:
- Semantic Model Developer: Full edit access to manage model structure, measures, and relationships.
- Power BI Report Developer: Ability to create reports from the semantic model without requiring edit permissions on the model itself.
This change will improve security, governance, and collaboration in environments where multiple developers work on shared models.
No CommentsBe the first to comment
Recent ideas
Allow NotebookUtils getSecret() to authenticate with Workspace Identity
Current behavior In Microsoft Fabric, notebookutils.credentials.getSecret() authenticates against Azure Key Vault using the identity of the user who executes the notebook. This behavior appli...tmihara1 hour agoNew MemberNew3Views0likes0CommentsSupport Synonyms in Fabric Warehouse
Microsoft SQL Server has a very powerful feature by the way of "synonyms." It allows users and DBAs to do all sorts of powerful magic such as rewiring objects under the hood (e.g. run the code agains...matthias-bi5 hours agoRegular VisitorNew1.3KViews18likes2CommentsExpose Refresh Warnings and Informational Messages via Notifications and API
When a Power BI semantic model refresh completes successfully, the status shows Completed, even when the refresh details contain warnings or informational messages that require attention. Please pro...Jashwanth_K7 hours agoMicrosoft EmployeeNew22Views6likes0CommentsInvoke Pipeline Task - Workspace Identity Authentication
Currently, the Fabric Data Factory Invoke Pipeline task uses the user's credentials who saved the pipeline to then authenticate to the Azure Data Factory to execute the ADF pipeline. When that user'...dzebrowitz11 hours agoAdvocate IPlanned1.8KViews61likes5CommentsFabric Pipeline should run as workspace identity
Currently, Microsoft Fabric pipelines run under the identity of the last user who modified them, which can cause disruptions when tenant administrators make changes to security policies, such as enab...pellitteris11 hours agoAdvocate IINew1.4KViews27likes3Comments