Forum Discussion
Self-Service via PowerBI - Build Permissions + RLS
Dears,
In our gold layer we have one semantic model per each workspace. Each workspace represents a domain
We would like to implement RLS in the semantic models so that users are subject to it
But we also, need to provide them build permissions as they will be doing self-service
Problem is that, if I am not wrong , if they have build permissions on the semantic model, then RLS is not enforced?
Or am I wrong?
What do you recommend for this?
Thanks,
Pedro
Hi fabricpribeiro ,
If users are granted only Build permission on the semantic model along with RLS security, they will still be able to create their own reports based on the data they are authorized to see. Specifically, they can connect to the semantic model and build reports using multiple existing tables from that model, including creating visuals that combine data across those tables. They can also create their own report-level measures while building reports in the Service, provided those measures are based on the existing model structure. However, they will not be able to add new physical tables, modify relationships, or change the existing semantic model itself, as that requires edit or owner-level permissions on the dataset/model.
Regards
7 Replies
- cengizhanarslanSuper User
Build permission does not bypass RLS, so users can safely be given Build access for self-service while still being restricted by RLS when querying the semantic model. The key point is that RLS is only bypassed for users with elevated workspace roles like Admin, Member, or Contributor, not for those with Viewer + Build.
- fabricpribeiroPost Patron
you mean, even if I give explicit Build permissions in the semantic model itself? not via the item permissions, but via the Semantic model itslef, still , thye RLS created at semantic model will be respected, right?
- cengizhanarslanSuper User
Yes, even if you grant Build permission directly on the semantic model, RLS is still enforced. The only cases where RLS is not enforced are when users have elevated workspace roles (Admin/Member/Contributor).
- v-nmadadi-msftCommunity Support
Hi fabricpribeiro ,
I wanted to check if you had the opportunity to review the information provided. Please feel free to contact us if you have any further questions.
Thank you. - v-nmadadi-msftCommunity Support
May I check if this issue has been resolved? If not, Please feel free to contact us if you have any further questions.
Thank you