Forum Discussion
AD groups in Power BI (Office 365) groups
Hi,
Sorry for a question that I probably should find an answer to without asking. But I draw blank in trying to find a conclusive answer.
We have a solution were we will use groups to separate reports and for security. In the organization AD groups are used. AD groups will also be used to control access to some of the source systems. It would therefore work best if AD groups could be used to control access to groups in Power BI.
Is this a possibillity today? If not, will it be in the future? If not, what is the "best practice" solution in this case?
Thanks,
Martin
- Anonymous10 years ago
Anonymous
Is this a possibillity today? No
If not, will it be in the future? Don't know
If not, what is the "best practice" solution in this case? My typical approach is to use Group workspaces to organize departments of Report Authors and use them as the central point to share reports with end users. In this manner, you can share a dashboard with an AD group with no issues, and the reports are all managed in one location.
As opposed to creating a seperate Group Workspace for a set of individuals. This also includes the problem that now the end user has to hunt around several Group Workspaces to try to find reports if they belong to several Groups. Whereas with the first approach and good naming standards, everything is in their workspace to be viewed.
- Anonymous10 years ago
Anonymous Yes. I don't want to be in the business of User management in Power BI.
If I want to share a dashboard to 100 users, let the access be dictated by IT and AD.
11 Replies
- AnonymousNot applicable
Anonymous
Is this a possibillity today? No
If not, will it be in the future? Don't know
If not, what is the "best practice" solution in this case? My typical approach is to use Group workspaces to organize departments of Report Authors and use them as the central point to share reports with end users. In this manner, you can share a dashboard with an AD group with no issues, and the reports are all managed in one location.
As opposed to creating a seperate Group Workspace for a set of individuals. This also includes the problem that now the end user has to hunt around several Group Workspaces to try to find reports if they belong to several Groups. Whereas with the first approach and good naming standards, everything is in their workspace to be viewed.
- AnonymousNot applicable
Thanks Anonymous!
Interesting solution you propose. Will definately follow up on that.
A question on what you said. Is it so that I can share a dashboard (and the underlying reports and datasets) with an AD group and the AD group in a way that if I later add a user to the AD group that user automatically has access to the dashboard?
- AnonymousNot applicable
Anonymous Yes. I don't want to be in the business of User management in Power BI.
If I want to share a dashboard to 100 users, let the access be dictated by IT and AD.
- AmieRegular Visitor
When I tested sharing to an AAD Security Group I ran into some issues in revoking access. Members who were removed from the AAD Security Group retained access to the shared content in Power BI Service (as well as the report embedded in SharePoint Online). Also, when we revoked access to the entire AAD Security Group inside of Power BI, the individual members of the AAD Security Group still retained access.
Has anyone else had this issue, or is anyone aware of a resolution?
- AnonymousNot applicable
Amie This is definitely disconcerting if that is the case. I assume the sharing was done via dashboards and that only the AAD group was shared too, and the individual users were not also shared to as well...
And for the second case, you stopped sharing with the group and the entire group could still see the dashboard? How soon after the removal did you check, and if it was awhile later, was it still the case? Just making sure it wasn't a timing issue, in that it would take a bit to remove the permissions across the environment.
Also - I would suggest if this is actually the case, that you create a seperate post since this one was already closed.