Forum Discussion
Azure AD Group question - need help
Hello,
We have Azure AD groups set up for each role, within each workspace and everything seems to be working fine. The datasets used by these workspaces are located in a "central" workspace. The issue that we seem to be encountering is when one of the workspaces is using the PBI App to share reports containing data located on the central workspace.
A user is added to the AD group which should give them access to the app and the dataset. However, this doesn't seem to be happening in some cases. User1 was added to the AD group and was able to see the app but was getting an error message saything they didn't have access to the dataset.
I verfied User1 was indeed, in the AD group. But when I added User1 directly to the dataset permission, it worked fine. They are now able to see the full reports and interact successfully with the data.
Has anyone else experienced this and found a solution?
5 Replies
- aj1973Community Champion
Hi QueenTink
Solution to what ! You have found the solution yourself. The AD Group that consumes the report needs to be added to the App/Audience and given permission to the Dataset. No need to add the AD group to the workspace where the report is located nor to the Central Workspace where the Dataset is located.
- QueenTinkFrequent Visitor
We have done this, but it's not working. User1 is in the AD group. The AD group has access to the App and is in the audience for these reports. The AD group has access to the dataset it needs, but User1 is unable to access the data in the report. He gets a message saying he doesn't have access to it.
I verified that User1 was in the AD group and he is. When I granted in direct access to the dataset, he was able to see the report.
My question is, why is it not working based on the AD group?
- aj1973Community Champion
Not sure what do you mean by "I granted in direct access to the dataset". In my understanding of the situation is that members of the group have direct access (Not in the group) to the Central Workspace and when you add User1 to the central WS he can see the report.
I think you need to empty the Central WS and the WS where the Thin report is from all direct users and grant access to the Dataset via AD group ( Like i mentioned in my previous reply)