Forum Discussion
Insert user data through power bi report database to access reports
- Anonymous6 years ago
Hi d_gosbell,
Thank you for the suggestion. I have gone through each documentation as you mentioned and finally able to set the new user with role. It works fine for the 1st user but when again i tried to add another user with same role then got below error:
"A custom role cannot contain both system-level and non-system-level tasks in the same role definition. You must specify different roles for each category of tasks"
Below is my code which i used so far.
bool isPolicies = true; ReportingService2010 rs = new ReportingService2010(); rs.Url = "http://<domainName>/ReportServer/ReportService2010.asmx"; rs.Credentials = System.Net.CredentialCache.DefaultCredentials; var policies = rs.GetPolicies("/", out isPolicies); Role browserRole = new Role(); browserRole.Name = "System User"; Role[] r1 = new Role[1]; r1[0] = browserRole; Policy po = new Policy(); po.GroupUserName = @"<domain>\<username>"; po.Roles = r1; policies[0] = po; rs.SetPolicies("/", policies);One more things i wanted to add here is suppose i added one user with some role and when again i am going to add some other user then in getPolicies i am getting the previously inserted user and his role instead of BuiltIN/Administrator.
I tried to use my crednetials but in Policies getting the same user again.
Please provide some suggestion based on the credentials should get only those related policies.
Please suggest how do i fix this issue.
Thanks,
Vikash
Hi d_gosbell,
I access the reporting server web service through web browser and got all the service in xml format.
Could you please let me know in this xml which element i could use to insert new user and assign the specific role?
Thanks,
Vikash
I've never used the raw XML against the Reporting Services SOAP endpoint. In Visual Studio I just right click on references and use the "Add Service Reference" option, tell it the url of the asmx file and let it generate a proxy object for me. And I believe many other programming languages have similar tools, utilities or libraries for doing a similar thing.
Then the general steps are as follows:
- call GetPolicies against the object you want to secure to get any existing permissions
- construct a new Policy object and add it to the array of policies you got from Step 1 (a policy has the user or AD Group and the Role they should have)
- call SetPolicies and pass in the updated array of Policy objects from Step 2
You can see an example in the source code for the Microsoft PowerShell module here https://github.com/microsoft/ReportingServicesTools/blob/master/ReportingServicesTools/Functions/Security/Grant-RsCatalogItemRole.ps1
- Anonymous6 years agoNot applicable
Hi d_gosbell,
Thank you for the suggestion. I have gone through each documentation as you mentioned and finally able to set the new user with role. It works fine for the 1st user but when again i tried to add another user with same role then got below error:
"A custom role cannot contain both system-level and non-system-level tasks in the same role definition. You must specify different roles for each category of tasks"
Below is my code which i used so far.
bool isPolicies = true; ReportingService2010 rs = new ReportingService2010(); rs.Url = "http://<domainName>/ReportServer/ReportService2010.asmx"; rs.Credentials = System.Net.CredentialCache.DefaultCredentials; var policies = rs.GetPolicies("/", out isPolicies); Role browserRole = new Role(); browserRole.Name = "System User"; Role[] r1 = new Role[1]; r1[0] = browserRole; Policy po = new Policy(); po.GroupUserName = @"<domain>\<username>"; po.Roles = r1; policies[0] = po; rs.SetPolicies("/", policies);One more things i wanted to add here is suppose i added one user with some role and when again i am going to add some other user then in getPolicies i am getting the previously inserted user and his role instead of BuiltIN/Administrator.
I tried to use my crednetials but in Policies getting the same user again.
Please provide some suggestion based on the credentials should get only those related policies.
Please suggest how do i fix this issue.
Thanks,
Vikash
- d_gosbell6 years agoSuper User
So there are 2 levels of permissions in PBIRS item-level and and system-level (see https://docs.microsoft.com/en-us/sql/reporting-services/security/grant-user-access-to-a-report-server?view=sql-server-ver15)
"System User" is a system level permission so I think you would need to use SetSystemPolicies to grant this.
(Note: I've never used the security APIs so I'm just theorising based on reading the docs)
But granting "System User" will not give access to any reports, you would also need to grant at least "Browser" rights using SetPolicies against a folder or report ( I usually try to only set permissions at the folder level if I can)
Anonymous wrote:
One more things i wanted to add here is suppose i added one user with some role and when again i am going to add some other user then in getPolicies i am getting the previously inserted user and his role instead of BuiltIN/Administrator.
This is because you are not adding a new role to the collection of roles you got from the GetPolicies call, you are overwritting the first policy (so this is probably removing the BUILTIN\Administrators). You need to add your new policy object to the array of policies instead of assigning over the top of policies[0]
So instead of overwriting the first item in the array:
policies[0] = po;you should probably be doing something like the following to add your new "po" object on to the end of the array:
policies = policies.Concat( new Policy[] { po } ).ToArray();- Anonymous6 years agoNot applicable
Hi d_gosbell,
Thank you for the suggestion. It is working fine for me.
The only issue here is when the user which is added through policy. That user if trying to access Report server it is asking the user name and password credentials. For that if manually add the domain as Trusted Sites in Internet options and again refresh the url he can able to access the reports.
Can we bypass this authentication for the Powerbi User?
Can we delete user and assigned role using web service?
Thanks,
Vikash