Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Join us for an expert-led overview of the tools and concepts you'll need to become a Certified Power BI Data Analyst and pass exam PL-300. Register now.

Reply
Sreekanth_B
New Member

How to provide security to business users for a report which contain highly confidential Data

HI Everyone,

 

Want to know how we can provide security to business users to a report that contains highly Confidential & Sensitive Data.
Only Business users should have access to the report. Everyone else should not access/see any data of the report.

Please Suggest. 

Thanks,

Sreekanth 

8 REPLIES 8
Col_Mar
Advocate I
Advocate I

As far as I'm aware, as long as you administer access to the workspace the report is in and make sure the application admins don't have access to that specific 'highly confidential' workspace then the RLS should govern acess to the model/report and you can still set this on an individual user basis

Hi @Sreekanth_B ,

If @Col_Mar  response has resolved your query, please mark it as the "Accepted Solution" to assist others. 

 

Thank you

Hi @Sreekanth_B ,

We haven’t heard from you on the last response and was just checking back to see if you have a resolution yet.do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.

 

Thank you.

Hi @Sreekanth_B ,

We haven’t heard from you on the last response and was just checking back to see if you have a resolution yet.do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.

 

Thank you.

v-dineshya
Community Support
Community Support

Hi @Sreekanth_B ,

Thank you for reaching out to the Microsoft Community Forum.

 

Hi @Col_Mar , Thank you for posting Response in community.

 

HI @Sreekanth_B , As suggested by @Col_Mar , please follow the steps. and follow the Microsoft official document, regarding RLS with Power BI.

 

If @Col_Mar  response has resolved your query, please mark it as the "Accepted Solution" to assist others. 

Thank you

Col_Mar
Advocate I
Advocate I

You would need to add RLS to the data model on Power BI Desktop (if you have a table of users or something equivalent) and then also assigned users to this role in the Power BI Service.  Think of it as two steps, but you can also test the security you create in Power BI Desktop before you publish and assign them in the Power BI Service.
See below:
Row-level security (RLS) with Power BI - Microsoft Fabric | Microsoft Learn

Thanks for Reply, To be More Specifc to my question, Even application ADMINS should not able to see the confidential Data. How can we achive this.

It's not clear what you mean by an application admin that you don't want to see what you're sharing with business users.

* Workspace contributors, members, and admins will be able to see all the data -- they get read access to all content and RLS is not applied to those roles.

* Workspace viewers will be able to see the report, but RLS will be applied to them.

* Tenant Admins won't see the workspace in their list by default -- they would need to be added to the workspace for that content to appear for navigation in the UI.  *HOWEVER* -- they could go add themselves to the workspace in any role via the Tenant Administrator tools.  This will apply to any content in the tenant.  I don't think there's any real way to restrict this from tenant admins.  But most are too busy to go looking for workspaces to nose around in and most already have a lot of access to super secret, super sensitive, super confidential data.  If this is too sensitive to risk the tenant admin possibly getting access, then perhaps this isn't the right platform to share that data.

 

The path forward depends on if you already have a workspace that is appropriately provisioned for the intended users. 

* If no workspace with appropriate permissions exists, then you need to create a new one and only add the appropriate workspace users, or don't add any users to workspace and share the individual item with the specific people who should see it. 

* Very important is to not accidentally create a organizational link to the report by clicking on the "Share" icon for the report and blindly clicking through the prompts, or to inadvertently give users Reshare permissions.

*Give the workspace and the reports boring names to discouraging nosiness. 

*Make sure that it is not set as Discoverable in the settings.  

* Clearly mark the report as Confidential.  Maybe even have a landing page with no data that spells out that it's confidential ,with some verbiage that users should only proceed if they are authorized, and provide a link to a hidden drill-down page with the actual data.

* Consider reviewing the usage reports daily to confirm who is accessing the report.  You may be able to set this up on a subscription.

 

 

Helpful resources

Announcements
Join our Fabric User Panel

Join our Fabric User Panel

This is your chance to engage directly with the engineering team behind Fabric and Power BI. Share your experiences and shape the future.

June 2025 Power BI Update Carousel

Power BI Monthly Update - June 2025

Check out the June 2025 Power BI update to learn about new features.

June 2025 community update carousel

Fabric Community Update - June 2025

Find out what's new and trending in the Fabric community.