Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Get Fabric Certified for FREE during Fabric Data Days. Don't miss your chance! Learn more

Security - Ability to maintain source security for reports published on BI Sites

The general requirement is that visualizations (Power View, SSRS etc...) must not circumvent existing policies, or introduce yet another set of security policies on top of those already implemented at the source. * For example, a visualization of sales data needs to reflect the policy that account managers can only read sales data for their region. * For performance reasons, this is enforced at the source by injecting predicates into the query based on the end users identity. If identities for end users are not passed down the process chain into the data layer, it leaves us little option but to publish individual reports for every region, which results in an explosion of complexity and numbers of reports, or move the whole model to BISM and manage the policy in yet another place (namely the BISM model). Impact blocking migration to SPO/BI Sites. At least 412 Site Collections with more than 600 Power Views. Impacting Adoption or migration for majority of BPUs - e.g. Finance, LCA, HR, etc
Status: Under Review
Comments
amit18
New Member
This feature should be implemented and rolled out at the earliest.
bert_sheffer
New Member
We're working to Implement Power BI for all the schools in our district but we need to control what the user sees based on the school they work for or we run up against FERPA violations!
martijn13
New Member
Thanks for setting this to "Started"
bhartman302
New Member
Basically, I'd like to see a 'Report-Creator' filter. As in, I apply the filter on my end but the Dashboard User cannot change it.
ankittalele
Regular Visitor
How do we Implement Row Level Security??? In an Organizational Hierarchy? Do Power BI Provide any Solution For it.
gautam_arora
New Member
We are unable to sync Roles and Membership from Azure AD We have 800+ site collections in our organization. Each site has one or more Site Managers. We intend to build a Site Manager Dashboard to help them monitor and manage site usage. The idea is to exploit the RLS feature so that each Site Manager is able to view the Dashboard data for his site only. The Site Managers can be constantly added or removed across sites. We tried using the new Roles Feature within PowerBI, so that each role maps to one site, and the Site Managers are added as members into those Roles. The challenge that we are facing is ensuring the Roles-Members mapping stays up-to-date in real-time (ideally). So, for instance when a person is provided Manager access on a site in Sharepoint, then he automatically gets membership into the corresponding Role in PowerBI. Is there some API exposed by PowerBI using which we could run a script when a new manager is added/removed for a site? Can anybody suggest a better solution? We are aware that Roles in PowerBI allow Active Directory Groups to be added, but defining AD Groups for each of our 800+ sites sounds like a maintenance nightmare. Is the PowerBI team considering any feature/API to help manage such a situation? We strongly believe that the scenario is NOT unique to us and will be faced by any big enterprise deploying PowerBI with Sharepoint.
nemecv
New Member
Can anybody advise me how control the default filter according to the logged-in user
kevin37
New Member
Is this being considered? Hoping for an update as this is mission critical for us. Won't be pursuing Power BI without it.
fbcideas_migusr
New Member
'+1 for the ETA Please as this is preventing us from starting a major project and also because I used THREE whole votes 😄
vincent_lauzon
New Member
Saw it in action, it's exactly what we needed.