Forum Discussion
Insert user data through power bi report database to access reports
- Anonymous6 years ago
Hi d_gosbell,
Thank you for the suggestion. I have gone through each documentation as you mentioned and finally able to set the new user with role. It works fine for the 1st user but when again i tried to add another user with same role then got below error:
"A custom role cannot contain both system-level and non-system-level tasks in the same role definition. You must specify different roles for each category of tasks"
Below is my code which i used so far.
bool isPolicies = true; ReportingService2010 rs = new ReportingService2010(); rs.Url = "http://<domainName>/ReportServer/ReportService2010.asmx"; rs.Credentials = System.Net.CredentialCache.DefaultCredentials; var policies = rs.GetPolicies("/", out isPolicies); Role browserRole = new Role(); browserRole.Name = "System User"; Role[] r1 = new Role[1]; r1[0] = browserRole; Policy po = new Policy(); po.GroupUserName = @"<domain>\<username>"; po.Roles = r1; policies[0] = po; rs.SetPolicies("/", policies);One more things i wanted to add here is suppose i added one user with some role and when again i am going to add some other user then in getPolicies i am getting the previously inserted user and his role instead of BuiltIN/Administrator.
I tried to use my crednetials but in Policies getting the same user again.
Please provide some suggestion based on the credentials should get only those related policies.
Please suggest how do i fix this issue.
Thanks,
Vikash
I've never used the raw XML against the Reporting Services SOAP endpoint. In Visual Studio I just right click on references and use the "Add Service Reference" option, tell it the url of the asmx file and let it generate a proxy object for me. And I believe many other programming languages have similar tools, utilities or libraries for doing a similar thing.
Then the general steps are as follows:
- call GetPolicies against the object you want to secure to get any existing permissions
- construct a new Policy object and add it to the array of policies you got from Step 1 (a policy has the user or AD Group and the Role they should have)
- call SetPolicies and pass in the updated array of Policy objects from Step 2
You can see an example in the source code for the Microsoft PowerShell module here https://github.com/microsoft/ReportingServicesTools/blob/master/ReportingServicesTools/Functions/Security/Grant-RsCatalogItemRole.ps1
Hi d_gosbell,
Thank you for the suggestion. I have gone through each documentation as you mentioned and finally able to set the new user with role. It works fine for the 1st user but when again i tried to add another user with same role then got below error:
"A custom role cannot contain both system-level and non-system-level tasks in the same role definition. You must specify different roles for each category of tasks"
Below is my code which i used so far.
bool isPolicies = true;
ReportingService2010 rs = new ReportingService2010();
rs.Url = "http://<domainName>/ReportServer/ReportService2010.asmx";
rs.Credentials = System.Net.CredentialCache.DefaultCredentials;
var policies = rs.GetPolicies("/", out isPolicies);
Role browserRole = new Role();
browserRole.Name = "System User";
Role[] r1 = new Role[1];
r1[0] = browserRole;
Policy po = new Policy();
po.GroupUserName = @"<domain>\<username>";
po.Roles = r1;
policies[0] = po;
rs.SetPolicies("/", policies);
One more things i wanted to add here is suppose i added one user with some role and when again i am going to add some other user then in getPolicies i am getting the previously inserted user and his role instead of BuiltIN/Administrator.
I tried to use my crednetials but in Policies getting the same user again.
Please provide some suggestion based on the credentials should get only those related policies.
Please suggest how do i fix this issue.
Thanks,
Vikash
- d_gosbell6 years agoSuper User
So there are 2 levels of permissions in PBIRS item-level and and system-level (see https://docs.microsoft.com/en-us/sql/reporting-services/security/grant-user-access-to-a-report-server?view=sql-server-ver15)
"System User" is a system level permission so I think you would need to use SetSystemPolicies to grant this.
(Note: I've never used the security APIs so I'm just theorising based on reading the docs)
But granting "System User" will not give access to any reports, you would also need to grant at least "Browser" rights using SetPolicies against a folder or report ( I usually try to only set permissions at the folder level if I can)
Anonymous wrote:
One more things i wanted to add here is suppose i added one user with some role and when again i am going to add some other user then in getPolicies i am getting the previously inserted user and his role instead of BuiltIN/Administrator.
This is because you are not adding a new role to the collection of roles you got from the GetPolicies call, you are overwritting the first policy (so this is probably removing the BUILTIN\Administrators). You need to add your new policy object to the array of policies instead of assigning over the top of policies[0]
So instead of overwriting the first item in the array:
policies[0] = po;you should probably be doing something like the following to add your new "po" object on to the end of the array:
policies = policies.Concat( new Policy[] { po } ).ToArray(); - Anonymous6 years agoNot applicable
Hi d_gosbell,
Thank you for the suggestion. It is working fine for me.
The only issue here is when the user which is added through policy. That user if trying to access Report server it is asking the user name and password credentials. For that if manually add the domain as Trusted Sites in Internet options and again refresh the url he can able to access the reports.
Can we bypass this authentication for the Powerbi User?
Can we delete user and assigned role using web service?
Thanks,
Vikash
- d_gosbell6 years agoSuper User
Anonymous wrote:
Hi d_gosbell,
Thank you for the suggestion. It is working fine for me.
The only issue here is when the user which is added through policy. That user if trying to access Report server it is asking the user name and password credentials. For that if manually add the domain as Trusted Sites in Internet options and again refresh the url he can able to access the reports.
Can we bypass this authentication for the Powerbi User?
You can't do anything from the report server side to change this, it's a browser security setting. You will need to talk to your domain or network admins as they can set this via group policy so that you site is automatically added to either Intranet sites or Trusted sites for all users.
Can we delete user and assigned role using web service?
My guess is that you just call GetPolicies find the user in the array of policies, remove the items from the array that you no longer want then call the SetPolicies method passing in the array without the policies that are no longer required.
- Anonymous6 years agoNot applicable
Hi d_gosbell,
Thank you for the suggestion. I have got the answer which i asked.
I am marking it as answer.