Forum Discussion

muturuf's avatar
muturuf
Frequent Visitor
1 year ago
Solved

Accessing Report/Data when OLS Set Up

Hi all,

 

I have a user who is assigned a Viewer role in a shared workspace and one of the datasets in this workspace has Object Level Security set up via a role that I named OLS and only certain tables were hidden from this role.

 

This user was not assigned to the OLS role and when the user opens the report, the entire report was blank / not displaying any data.

 

I understand that once OLS set up the Workspace Viewers need to be assigned to the security role.

However, my question is the following.

Do I need to create another security role that allows for seeing senstive data and assign other users (who should see sensitive data) so that they can view the sensitive data?

I found this post which pretty much confirms this however I shared the individual report with a user who does not have a workspace role assigned and without any security role assignment the user was able to view all the data in the report, which confused me further.

 

Any help is greatly appreciated.

  • Anonymous's avatar
    Anonymous
    1 year ago

    Hi, muturuf 

    According to the document, you indeed need to assign a viewer permission to make OLS effective.

    Object-level security (OLS) with Power BI - Microsoft Fabric | Microsoft Learn

     

    Regarding your question about whether you need to create other roles for others to access sensitive data, the answer is yes. You can restrict access to a specific table or column in OLS, which may require external tools for setup. You can refer to the relevant tutorials for more information.

    Analysis Services tabular model object-level security | Microsoft Learn

     

    As for your final question about sharing a report with a single user, who can view all the data, when we share a report via URL, the user will automatically be granted permission to view that report. As you can see, if you choose "People in your organization" or "Specific people," the shared user will have at least read access, which will share the entire semantic model (unless you set up RLS and include them in the RLS role). You can learn more about this from the relevant documentation.

    Share Power BI reports and dashboards with coworkers and others - Power BI | Microsoft Learn

     

    Finally, you can easily understand how to manage sharing permissions through the screenshots provided.

     

     

    Best Regards

    Jianpeng Li

    If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

1 Reply

  • Anonymous's avatar
    Anonymous
    Not applicable

    Hi, muturuf 

    According to the document, you indeed need to assign a viewer permission to make OLS effective.

    Object-level security (OLS) with Power BI - Microsoft Fabric | Microsoft Learn

     

    Regarding your question about whether you need to create other roles for others to access sensitive data, the answer is yes. You can restrict access to a specific table or column in OLS, which may require external tools for setup. You can refer to the relevant tutorials for more information.

    Analysis Services tabular model object-level security | Microsoft Learn

     

    As for your final question about sharing a report with a single user, who can view all the data, when we share a report via URL, the user will automatically be granted permission to view that report. As you can see, if you choose "People in your organization" or "Specific people," the shared user will have at least read access, which will share the entire semantic model (unless you set up RLS and include them in the RLS role). You can learn more about this from the relevant documentation.

    Share Power BI reports and dashboards with coworkers and others - Power BI | Microsoft Learn

     

    Finally, you can easily understand how to manage sharing permissions through the screenshots provided.

     

     

    Best Regards

    Jianpeng Li

    If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.