Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

The Power BI DataViz World Championships are on! With four chances to enter, you could win a spot in the LIVE Grand Finale in Las Vegas. Show off your skills.

Reply
AndyHermle
Helper I
Helper I

Automatic enforcement of row-level security roles in the Power BI Service?

Dear Power BI Experts: 

 

This is an excerpt from a Microsoft Learn web page: 
https://learn.microsoft.com/en-us/fabric/security/service-admin-row-level-security#using-rls-with-wo...

 

"If you publish your Power BI Desktop report to a workspace in the Power BI service, the RLS roles are applied to members who are assigned to the Viewer role in the workspace."

 

Am I getting this right? Row Level Security roles are enforced automatically ? for all users that have been granted access to a specific workspace as Viewers. For these existing Viewers (Workspace role "Viewer"), I do not have to assign them to individual row level security roles?

 

Your valuable answer is very much appreciated. Thank you very much in advance. 

 

Best Regards, Andreas

1 ACCEPTED SOLUTION
ibarrau
Super User
Super User

Hi. No, it's not like that. The sentence means the role configuration will only apply for Viewers. Contributors, members and admins will always see all the semantic model without any filter. However, the viewer must be assigned to a role. Otherwise it will see an empty report because the viewer doesn't have a role assigned and the RLS is enforced to them.

You can assign them in Security Setting of the Semantic Model. Keep in mind creating a role without rules in case you have a Viewer that should see it all.

I hope that helps


If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

Happy to help!

LaDataWeb Blog

View solution in original post

2 REPLIES 2
AndyHermle
Helper I
Helper I

Hi ibarrau, 

 

thank you very much for your detailed answer. Ok, great, this explains it to me now. Thanks again. 

ibarrau
Super User
Super User

Hi. No, it's not like that. The sentence means the role configuration will only apply for Viewers. Contributors, members and admins will always see all the semantic model without any filter. However, the viewer must be assigned to a role. Otherwise it will see an empty report because the viewer doesn't have a role assigned and the RLS is enforced to them.

You can assign them in Security Setting of the Semantic Model. Keep in mind creating a role without rules in case you have a Viewer that should see it all.

I hope that helps


If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

Happy to help!

LaDataWeb Blog

Helpful resources

Announcements
Las Vegas 2025

Join us at the Microsoft Fabric Community Conference

March 31 - April 2, 2025, in Las Vegas, Nevada. Use code MSCUST for a $150 discount!

FebPBI_Carousel

Power BI Monthly Update - February 2025

Check out the February 2025 Power BI update to learn about new features.

Feb2025 NL Carousel

Fabric Community Update - February 2025

Find out what's new and trending in the Fabric community.