Forum Discussion
Need help with Security Groups implementation in PBI RLS
- 1 year ago
Hello MDB0609
Thank you for reaching out to the Microsoft Fabric Community Forum.
Thank you Anonymous for your prompt response.
We understand your concerns regarding the implementation of security groups in Power BI RLS. This issue typically arises due to caching and synchronization delays between Microsoft Entra ID and the Power BI Service. I would recommend the following steps:
1. Caching Delay in Power BI Service- Power BI caches security group memberships for performance reasons. Even if a user is removed from the Security Group , they might still have access for a period.
- Request the user to sign out and sign back into Power BI to clear cached credentials.
2. Delay in Entra ID Group Sync
- Although Microsoft documentation states a 5-minute sync time, it may take up to an hours in some cases.
- Verify if the group membership has been updated in the Microsoft Entra Admin Center.
3. Role-Based Security (RLS) Not Applied Correctly
- Sometimes, removing a user from an SG does not remove their access if they have direct access via other means (such as being assigned to a workspace or report).
4. Check other security roles and direct assignments.
- In Power BI Service, go to Workspace → Manage Permissions.
- Verify if the user has explicit access to the report, dataset, or workspace.
5. Dataset Permissions vs. Workspace Permissions
- Even if RLS is applied correctly, if the user is a Contributor/Admin in the Workspace, they can bypass RLS.
If the issue persists, feel free to reach out for further assistance!
If my response has resolved your query, please mark it as the Accepted Solution to help others. Additionally, I would appreciate a 'Kudos' if you found my response helpful.
Thank you!
Hello MDB0609
Thank you for reaching out to the Microsoft Fabric Community Forum.
Thank you Anonymous for your prompt response.
We understand your concerns regarding the implementation of security groups in Power BI RLS. This issue typically arises due to caching and synchronization delays between Microsoft Entra ID and the Power BI Service. I would recommend the following steps:
1. Caching Delay in Power BI Service
- Power BI caches security group memberships for performance reasons. Even if a user is removed from the Security Group , they might still have access for a period.
- Request the user to sign out and sign back into Power BI to clear cached credentials.
2. Delay in Entra ID Group Sync
- Although Microsoft documentation states a 5-minute sync time, it may take up to an hours in some cases.
- Verify if the group membership has been updated in the Microsoft Entra Admin Center.
3. Role-Based Security (RLS) Not Applied Correctly
- Sometimes, removing a user from an SG does not remove their access if they have direct access via other means (such as being assigned to a workspace or report).
4. Check other security roles and direct assignments.
- In Power BI Service, go to Workspace → Manage Permissions.
- Verify if the user has explicit access to the report, dataset, or workspace.
5. Dataset Permissions vs. Workspace Permissions
- Even if RLS is applied correctly, if the user is a Contributor/Admin in the Workspace, they can bypass RLS.
If the issue persists, feel free to reach out for further assistance!
If my response has resolved your query, please mark it as the Accepted Solution to help others. Additionally, I would appreciate a 'Kudos' if you found my response helpful.
Thank you!