Forum Discussion

lucasdhilsbos's avatar
lucasdhilsbos
New Member
4 months ago
Solved

App Audience Permissions Vs. Dataset Permissions when dataset shared across workspaces

We have an app whose contents include a report with a source semantic model that is shared from another workspace. It appears that in that case users must have view permission for the dataset in addi...
  • v-pnaroju-msft's avatar
    4 months ago

    Hi lucasdhilsbos,

    Based on our understanding, when a report in an app connects to a semantic model hosted in a different workspace, app audience permissions provide access to the report only. Access to the underlying semantic model must be granted separately in the source workspace. In cross workspace scenarios, users must have the appropriate permissions on the semantic model, such as Read or Build, in addition to app access.

    For user error and permission inconsistencies, placing the semantic model and report within the same workspace is a good approach for simpler scenarios. In such cases, app permissions may be sufficient and help avoid the need for managing permissions in two places. However, keeping the semantic model in a separate workspace is also a valid and commonly used enterprise practice for reuse and governance. In that case, it is best practice to use the same security group for both the app audience and the semantic model permissions. This ensures consistency and helps prevent manual errors.

    Additionally, kindly refer to the links below:
    Publish an app in Power BI - Power BI | Microsoft Learn
    Semantic model permissions - Power BI | Microsoft Learn
    Build Permission for Shared Semantic Models - Power BI | Microsoft Learn

    We hope the information provided helps resolve the issue. Should you have any further queries, kindly feel free to contact the Microsoft Fabric community.

    Thank you.