Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Don't miss out! 2025 Microsoft Fabric Community Conference, March 31 - April 2, Las Vegas, Nevada. Use code MSCUST for a $150 discount. Prices go up February 11th. Register now.

Reply
thebigwhite
Helper II
Helper II

Is it possbile that a specif user can bypass the RLS security?

We are facing a particular case with an User that even he is assigned to a specific role and is set as "Viewer" seems to by pass the security role. 

It's extremely curious cause with all other users of our domain the role is working fine. 

Are there role on Office 365 that can bypass the security role?

Thanks 

 

1 ACCEPTED SOLUTION

We have republished  the report and re-inserted the user on the workspace.

Now the security is working fine.

I think our supplier had fixed the role which likely was not working correctly.

 

Thanks for your help

 

View solution in original post

6 REPLIES 6
v-shex-msft
Community Support
Community Support

HI @thebigwhite,

I'd like to suggest you check this account to confirm he only has 'read' permission of the related dataset, or the RLS filter effect will be ignored.
Regards,

Xiaoxin Sheng

Community Support Team _ Xiaoxin
If this post helps, please consider accept as solution to help other members find it more quickly.

The account has got only viewer permission and the dataset is not linked to Analysis services (just dataflow).

 

HI @thebigwhite,

Did this user has global admin permission of a group of specific workspaces? How did you RLS configure, have you enabled UPN on this user that mapping this user to other accounts? (if RLS is based on the user mapping table, please also take a look on it to confirm if anything specific on that user)

Regards,

Xiaoxin Sheng

Community Support Team _ Xiaoxin
If this post helps, please consider accept as solution to help other members find it more quickly.

We have republished  the report and re-inserted the user on the workspace.

Now the security is working fine.

I think our supplier had fixed the role which likely was not working correctly.

 

Thanks for your help

 

I am also facing similar issue. one of my user is by-passing RLS applied. User has only viewer access and is not a part on admin/contibutor/member of workspace. 
Also in My model i have a bi-directional many to 1 relationship with 'Applied security at both side'. is this may a possible reason? if yes then why only for a single user?
Can someone suggest?

collinq
Super User
Super User

Hi @thebigwhite ,

 

Is this an Analysis Service live connection?  According to this article, https://docs.microsoft.com/en-us/power-bi/admin/service-admin-rls  "You can't define roles within Power BI Desktop for Analysis Services live connections. You need to do that within the Analysis Services model."  

 

Also, when in Desktop and you select "View as Roles" and select the role that this person is in does it work as expected?  Can you confirm that you only have this person in one single role and not conflicting roles?

 

I would appreciate Kudos if my response was helpful. I would also appreciate it if you would Mark this As a Solution if it solved the problem. Thanks!



Did I answer your question? Mark my post as a solution!

Proud to be a Datanaut!
Private message me for consulting or training needs.




Helpful resources

Announcements
Las Vegas 2025

Join us at the Microsoft Fabric Community Conference

March 31 - April 2, 2025, in Las Vegas, Nevada. Use code MSCUST for a $150 discount!

Jan25PBI_Carousel

Power BI Monthly Update - January 2025

Check out the January 2025 Power BI update to learn about new features in Reporting, Modeling, and Data Connectivity.

Jan NL Carousel

Fabric Community Update - January 2025

Find out what's new and trending in the Fabric community.