Forum Discussion
Best practices for managing user groups
- 4 years ago
Pivot your thought process from Power BI structure to business needs.
Use a separate user management tool that handles onboarding/training/periodic review and expiry/offboarding.
Provide extracts of that tool (user lists) to your Power BI developers so they can use these lists in the RLS and OLS design.
for Premium capacity: Do not give access to workspaces/reports/dashboards. Only give access to apps, and try to only give access through distribution lists.
Hi mmcanelly ,
There are four types of workspace roles including Admin, Member, Contributor and Viewer. Different role has different permissions to the workspace content. For more details, you could refer to Roles in the new workspaces in Power BI - Power BI | Microsoft Docs.
To Edit the content such as reports, dashboards, users need to be Admin/Member/Contributors in the workspace. For Viewers, they only have view/read permission to these content. So if you could add users to different groups and make these groups one of these four workspaces roles, then these users are allowed to do the operations showed as above. There are four types of groups can be added to workspace as well. For the differences on these groups, please have a look at this official document: Compare groups - Microsoft 365 admin | Microsoft Docs.
As for Build/ Read permission to dataset, to access the report data, users need Read permission to the dataset and all these four kinds of workspaces roles will have such kind of permission. As for Build permission, users can create new content based on it, such as reports, dashboards. Per the design, members that are at least a Contributor role in the workspace will automatically have Build permissions to the workspace datasets. In addition, there are other ways of granting Build permissions. Build permission for shared datasets - Power BI | Microsoft Docs
- Dataset owners can assign Build permission to specific users or security groups on the Manage permissions page.
- An admin or member of the workspace where the dataset resides can decide during app publishing that users with permission for the app also get Build permission for the underlying datasets.
- Say you have Reshare and Build permission on a dataset. When you share a report or dashboard built on that dataset, you can specify that the recipients also get Build permission for the underlying dataset.
If you have a clue with these design, it will make your Power BI experience better.
If there is any post helps, then please consider Accept it as the solution to help the other members find it more quickly. If I misunderstand your needs or you still have problems on it, please let me know. Thanks a lot!
Best Regards,
Community Support Team _ Caiyun