Forum Discussion
Row Level Security - SSAS/Report Server
- 10 months ago
When you go to your report on Report Server and click on the ... menu and choose Manage > Data sources - what setting do you see for the Credentials? It needs to say "As the user viewing the report" for RLS to work and you will need to have Kerberos configured. Configure Kerberos to Use Power BI Reports - Power BI | Microsoft Learn
- 10 months ago
Hi Anonymous,
PBIRS does not pass the viewer’s identity to SSAS because of the current authentication or delegation settings. As a result, SSAS processes RLS using the PBIRS service account or stored credentials, which means RLS is effectively bypassed.
Data source authentication in PBIRS
Go to Report - Manage - Data Sources and set authentication to As the user viewing the report (Windows integrated).
Avoid using stored credentials or an unattended account.
Kerberos (double-hop) setup for PBIRS to SSAS
Register SPNs for the SSAS service account (MSOLAPSvc.*) and the PBIRS service account (HTTP/ReportServerHost).
In Active Directory, for the PBIRS service account:
Delegation - Trust this user for delegation to specified services only - Use Kerberos only / Constrained delegation - add the SSAS MSOLAPSvc.* SPNs.Confirm the identity reaching SSAS
Use SSAS Profiler/XEvent or DMVs to trace while opening the report.
EffectiveUserName should be DOMAIN\actual_user.
If it shows the PBIRS service account, review your delegation and SPN setup.
Role and admin checks
Make sure users are not SSAS Server/DB Admins, since admins bypass RLS.
If your dynamic RLS uses USERNAME(), ensure its format matches your security table (usually DOMAIN\samAccountName). Adjust if you used UPNs or emails.
Model propagation (less common)
If you use many-to-many or bridge tables, check that “Apply security filter in both directions” is enabled where needed.
Quick Diagnostic Flow:
Set PBIRS data source to use viewer’s credentials, open the report, and check SSAS:
If EffectiveUserName equals the viewer, RLS is applied; otherwise, review admin/USERNAME() mapping.
If EffectiveUserName does not match the viewer, resolve SPNs and constrained delegation.
Configure Analysis Services for Kerberos constrained delegation | Microsoft Learn
Configure Kerberos to Use Power BI Reports - Power BI | Microsoft Learn
Authentication methodologies supported by Analysis Services | Microsoft LearnThank you.
I need assistance implement SSAS Row level security. I have the following on my DimServer Dax Filter =DimServer[ServerKey]=LOOKUPVALUE(DimServerSecurity[ServerKey],DimServerSecurity[LOGIN_ID],USERNAME()).
Also for context I have a DimServer with ServerKey related to DimServer Security, which has on ServerKey and Login_ID.
Hi Anonymous,
Thank you for your question. Your scenario involves defining RLS logic in SSAS using DAX (LOOKUPVALUE) and model relationships, which is different from the original thread that discussed Kerberos authentication and credential pass-through in Power BI Report Server.
To ensure you receive comprehensive support from DAX and modeling experts, please create a new thread and include your model details, such as DimServer, DimServerSecurity relationships, and a sample DAX filter.
After posting, the community will be able to provide more targeted guidance on the appropriate RLS pattern for your setup.
Thankyou.