Forum Discussion
Dynamic RLS with USERPRINCIPALNAME() works in Service “View as role”, but real users can’t access un
- 10 months ago
Hi YogeshWaran2010,
1: yes, once RLS is enabled, only members with a role will be able to view data.
2: use AD groups
3: It is by design that users with workspace level roles contributor and higher bypass RLS.
Workspace members assigned Admin, Member, or Contributor have edit permission for the semantic model and, therefore, RLS doesn’t apply to them.
Row-level security (RLS) with Power BI - Microsoft Fabric | Microsoft Learn
If you found this helpful, consider giving some Kudos. If I answered your question or solved your problem, mark this post as the solution
Hi YogeshWaran2010,
Once a group is made in Entra ID, it can be added just like a user to the RLS role in a semantic model.
This way users are added/removed via entra and not on the report individually. THis is useful when you have multiple reports with the same user groups.
Entra ID groups can also be set up to be dynamic and rules can be applied to automatically assign membership.
If you found this helpful, consider giving some Kudos. If I answered your question or solved your problem, mark this post as the solution