Join us at FabCon Atlanta from March 16 - 20, 2026, for the ultimate Fabric, Power BI, AI and SQL community-led event. Save $200 with code FABCOMM.
Register now!The Power BI Data Visualization World Championships is back! Get ahead of the game and start preparing now! Learn more
Hello,
Our team discovered that Premium workspace "Viewers" can interact with underlying data using Copilot "Preview" toggle effectively getting to any data outside of visuals created. This can circumvent when you're dealing with sensitive content. We are looking for ideas on how to effectively govern this feature for our tenant. I wonder how many AD Groups can be allowed in the tenant settings to Include or Exclude Groups for Copilot feature?
How is everyone planning to rollout this feature by including or excluding certain AD Groups?
TIA
-Pawan
If you have RLS on your model Copilot will not return results that the user isn't allowed to see. RLS is a great way to restrict data so that everyone only sees what they are able to see.
Proud to be a Super User! | |
Agreed if all users behaved responsibly when it comes to dealing with senstive data. Looking for some ideas not dependent on user/developer assumptions. 🙂 We have a large tenant with over 1000 workspaces.
One suggestion from Micrsoft partners was to disable Q&A feature within a semantic model, that will turn off the Copilot feature but, its not feasible to set these for so much inventory.
Try disabling or limiting this setting to just a certain security group. This is available in the Admin Portal > Tenant Setttings
Update: you are already aware of this. Anyway this is how my clients deal with it. Regarding how many security groups, try nested security groups, due to the possible limit of entry you can put in the box.
The Power BI Data Visualization World Championships is back! Get ahead of the game and start preparing now!