Forum Discussion
Azure AD Group question - need help
Hi QueenTink
Solution to what ! You have found the solution yourself. The AD Group that consumes the report needs to be added to the App/Audience and given permission to the Dataset. No need to add the AD group to the workspace where the report is located nor to the Central Workspace where the Dataset is located.
We have done this, but it's not working. User1 is in the AD group. The AD group has access to the App and is in the audience for these reports. The AD group has access to the dataset it needs, but User1 is unable to access the data in the report. He gets a message saying he doesn't have access to it.
I verified that User1 was in the AD group and he is. When I granted in direct access to the dataset, he was able to see the report.
My question is, why is it not working based on the AD group?
- aj19732 years agoCommunity Champion
Not sure what do you mean by "I granted in direct access to the dataset". In my understanding of the situation is that members of the group have direct access (Not in the group) to the Central Workspace and when you add User1 to the central WS he can see the report.
I think you need to empty the Central WS and the WS where the Thin report is from all direct users and grant access to the Dataset via AD group ( Like i mentioned in my previous reply)
- QueenTink2 years agoFrequent Visitor
I guess I'm not explaining this well. It is set up just like you said above. But even though User1 was in the AD group, he was getting an error that he needed access to the dataset.
Because I'm trying to figure out what happened, I clicked on the 3 dots next to the dataset, went to manage permissions, and added his name with read permission - the same permission the AD group has. After I did this step, he can see the data and gets no errors.
We have removed all names from the central workspace and all access is granted on a dataset by dataset basis, based on the AD group, not individuals.
- aj19732 years agoCommunity Champion
Well done, but it sounds more like a bug that is happening with this particular User1.
Check with Azure Admin if the user is really added correctly to the group.