Forum Discussion

Anonymous's avatar
Anonymous
Not applicable
10 years ago
Solved

AD groups in Power BI (Office 365) groups

Hi,

 

Sorry for a question that I probably should find an answer to without asking. But I draw blank in trying to find a conclusive answer.

 

We have a solution were we will use groups to separate reports and for security. In the organization AD groups are used. AD groups will also be used to control access to some of the source systems. It would therefore work best if AD groups could be used to control access to groups in Power BI.

 

Is this a possibillity today? If not, will it be in the future? If not, what is the "best practice" solution in this case?

 

Thanks,

Martin

 

  • Anonymous's avatar
    Anonymous
    10 years ago

    Anonymous 

    Is this a possibillity today? No

    If not, will it be in the future? Don't know

    If not, what is the "best practice" solution in this case? My typical approach is to use Group workspaces to organize departments of Report Authors and use them as the central point to share reports with end users. In this manner, you can share a dashboard with an AD group with no issues, and the reports are all managed in one location.

    As opposed to creating a seperate Group Workspace for a set of individuals. This also includes the problem that now the end user has to hunt around several Group Workspaces to try to find reports if they belong to several Groups. Whereas with the first approach and good naming standards, everything is in their workspace to be viewed.

  • Anonymous's avatar
    Anonymous
    10 years ago

    Anonymous Yes. I don't want to be in the business of User management in Power BI.

    If I want to share a dashboard to 100 users, let the access be dictated by IT and AD. 

     

11 Replies

  • Anonymous's avatar
    Anonymous
    Not applicable

    Anonymous 

    Is this a possibillity today? No

    If not, will it be in the future? Don't know

    If not, what is the "best practice" solution in this case? My typical approach is to use Group workspaces to organize departments of Report Authors and use them as the central point to share reports with end users. In this manner, you can share a dashboard with an AD group with no issues, and the reports are all managed in one location.

    As opposed to creating a seperate Group Workspace for a set of individuals. This also includes the problem that now the end user has to hunt around several Group Workspaces to try to find reports if they belong to several Groups. Whereas with the first approach and good naming standards, everything is in their workspace to be viewed.

    • Anonymous's avatar
      Anonymous
      Not applicable

      Thanks Anonymous!

       

      Interesting solution you propose. Will definately follow up on that.

       

      A question on what you said. Is it so that I can share a dashboard (and the underlying reports and datasets) with an AD group and the AD group in a way that if I later add a user to the AD group that user automatically has access to the dashboard?

       

       

      • Anonymous's avatar
        Anonymous
        Not applicable

        Anonymous Yes. I don't want to be in the business of User management in Power BI.

        If I want to share a dashboard to 100 users, let the access be dictated by IT and AD. 

         

  • Amie's avatar
    Amie
    Regular Visitor

    When I tested sharing to an AAD Security Group I ran into some issues in revoking access. Members who were removed from the AAD Security Group retained access to the shared content in Power BI Service (as well as the report embedded in SharePoint Online). Also, when we revoked access to the entire AAD Security Group inside of Power BI, the individual members of the AAD Security Group still retained access.

     

    Has anyone else had this issue, or is anyone aware of a resolution? 

    • Anonymous's avatar
      Anonymous
      Not applicable

      Amie This is definitely disconcerting if that is the case. I assume the sharing was done via dashboards and that only the AAD group was shared too, and the individual users were not also shared to as well...

      And for the second case, you stopped sharing with the group and the entire group could still see the dashboard? How soon after the removal did you check, and if it was awhile later, was it still the case? Just making sure it wasn't a timing issue, in that it would take a bit to remove the permissions across the environment.

       

      Also - I would suggest if this is actually the case, that you create a seperate post since this one was already closed.