Bug: Dax queries execution permission issues on workspaces where AD groups are used for access
Anonymous
You can replicate this bug by doing the following:
1) create a Workspace1 with a report
2) assign an AD group with build/read permissions to this Workspace1
3) add UserX to the AD group
4) login to powerautomate with UserX
5) run dax query against dataset in Workspace1
... see how it fails with an error about permissions eventhough you are part of the AD group of Workspace1.
HOWEVER,
1) if UserX now manually visits the Workspace1 in the powerbi.com service, and then tries the powerautomate flow again, it will work. So it's the authentication via REST API that isn't working properly.
2) if you remove AD group and add UserX directly to the workspace, this also works from the first go. But of course:
a) this is not scalable
b) this is very different from any other behavior with AD groups in powerbi.com service
c) this isn't documented as being a limitation
d) given that it works after visting the workspace manually, means that post authentication, it does allow the user to do the necessary.
So after intensive tests with multiple user accounts on of your biggest enterprise customers, the bug is that via rest api call (dax query), the authentication can't seem to validate the user in an AD group assigned to a workspace.
PS: the authentication works in any other typical scenario like normal workspace/report access, but it doesn't work using POWERBI REST API.