Join us at FabCon Atlanta from March 16 - 20, 2026, for the ultimate Fabric, Power BI, AI and SQL community-led event. Save $200 with code FABCOMM.
Register now!The Power BI Data Visualization World Championships is back! Get ahead of the game and start preparing now! Learn more
We manage our Power BI roles via TMDL files. Until now, we have added DevOps groups to these roles directly in Power BI Service.
To improve overview and maintainability, we want to define all group assignments within the TMDL files. For mail enabled security groups, adding the email address as a member in TMDL seems to work fine. For example:
This works as expected.
However, we found that about 80% of our groups do not have an email address (these are Azure Security Groups rather than Mail enabled security groups).
We tried adding these groups as members by either DevOps group name or by DevOps object ID (a combination of the group GUID and the organization ID), for example:
Both methods result in deployment errors when deploying to Power BI Service.
Questions:
Changing all our groups to Mail enabled Security Groups is a major operation—any alternatives would be appreciated.
Thanks in advance for your help and advice!
Kind regards, Chantal van Harten
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.