Forum Discussion
Composite Model - Access Restrictions Problem
Hi Ole111
I think you may use Dierect Query for Power BI dataset function, then upload a loacl table. Then your connection mode will transfor to Mixed mode.
For reference: considerations-and-limitations
-
RLS rules will be applied on the source on which they are defined, but will not be applied to any other datasets in the model. RLS defined in the report will not be applied to remote sources, and RLS set on remote sources will not be applied to other data sources.
If you load your dataset into model, the rls won't work any more. You will need to set an other RLS for your new report.
Could you tell me what is the kind of your data source?
Please download the latest version of desktop and try again.
And please check the connection mode of your report and try to republish your report.
Best Regards,
Rico Zhou
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.
- Ole1115 years agoHelper II
Hi Anonymous
Thanks for the response.
The model had been created exactly as you wrote:
- Connected to Power BI Dataset (Direct Query)
- Added a table through inserting data (the mode had changed to Mixed)
As for desktop version it is the latest one.
Reading the documentation you refer to I wander how the RLS inheritance really behaves?:
“RLS rules will be applied on the source on which they are defined, but will not be applied to any other datasets in the model.”
Ho does it relate to information got when trying to test security status:
“Any previously defined RLS security is no longer working. You will need to re-create RLS in Power BI Desktop.”
Does ‘not working’ refer only to the new tables in composite model? If so, is there any way to give an access to the summary report based on source report for users who have RLS restrictions set in the source report?
- Anonymous5 years agoNot applicable
Hi Ole111
The RLS 's workload is as below.
1. Manage role in Power BI Desktop.
2. Publish report and add users into Role in Security from Dataset.
I try to load a dataset with RLS into model by Direct Query for Power BI Dataset. There is no roles I set for the dataset in Manage role.
So, if we use this function, we need to create RLS again in Power BI Desktop.
Best Regards,
Rico Zhou
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.
- Ole1115 years agoHelper II
Hi Anonymous
I have an impression that my point maybe unclear.
The RLS is set in source detailed report and I do not want to set any RLS in a new summary report.
The situation I face is following. Financial Report shows full P&L. Most of people have an access to data down to Gross Margin level (no access to overhead cost data). The new Summary Report should show to everybody summary of Revenue, Gros Margin and Operational Result (after overhead deduction) – thus no need for any RLS.
But if I use a Direct Query to Financial Report dataset to get key captions from P&L (with no details) as a result only people with no RLS restriction in Financial Report can see the Summary Report. Everybody included in RLS scheme in Financial Report can see only greyed-out placeholders of visuals (including year and month slicers) in the Summary Report.
So my understanding is that RLS restriction from the source report is inherited by the new report and people who cannot see the Operational Result in source file are not allowed to see anything in the Summary Report because it includes the Operational Result line.
Then my point is to find a way to show to everybody just a few key numbers from P&L using the model created for Financial Report where majority of the users can see only the part of the P&L.
Kind regards
- joarobert4 years agoFrequent Visitor
I have the same issue.
This seems like the key question:
"Does ‘not working’ refer only to the new tables in composite model?"
If the existing RLS is transferred, then it is a bit weird that there is no information about it here. But I hope it is. Did you get to test this on your data?- Ole1114 years agoHelper II
Indeed there is no information about any inherited RLS roles. The manage roles pane is blank:
You can only create the new roles, and only for a newly added tables (not from source model):
In the service, when getting into security option, there is such an information:
All in all, quite confusing.
Regards,
Dariusz