Forum Discussion

MDB0609's avatar
MDB0609
Regular Visitor
1 year ago
Solved

Need help with Security Groups implementation in PBI RLS

Hi all,   Hope you are doing well! I need help on setting up the security groups (setup in MS Entra Admin center) in my RLS. So, basically trying to ease up the process of acess provisioning.  So...
  • v-karpurapud's avatar
    1 year ago

    Hello MDB0609 

    Thank you for reaching out to the Microsoft Fabric Community Forum.

     

    Thank you Anonymous for your prompt response.


    We understand your concerns regarding the implementation of security groups in Power BI RLS. This issue typically arises due to caching and synchronization delays between Microsoft Entra ID  and the Power BI Service. I would recommend the following steps:


    1. Caching Delay in Power BI Service

    • Power BI caches security group memberships for performance reasons. Even if a user is removed from the Security Group , they might still have access for a period.
    • Request the user to sign out and sign back into Power BI to clear cached credentials.

     

    2. Delay in Entra ID Group Sync

    • Although Microsoft documentation states a 5-minute sync time, it may take up to an hours in some cases.
    • Verify if the group membership has been updated in the Microsoft Entra Admin Center.

     

    3. Role-Based Security (RLS) Not Applied Correctly

    • Sometimes, removing a user from an SG does not remove their access if they have direct access via other means (such as being assigned to a workspace or report).

     

    4. Check other security roles and direct assignments.

    • In Power BI Service, go to Workspace → Manage Permissions.
    • Verify if the user has explicit access to the report, dataset, or workspace.

    5. Dataset Permissions vs. Workspace Permissions

    • Even if RLS is applied correctly, if the user is a Contributor/Admin in the Workspace, they can bypass RLS.

     

    If the issue persists, feel free to reach out for further assistance!

     

    If my response has resolved your query, please mark it as the Accepted Solution to help others. Additionally, I would appreciate a 'Kudos' if you found my response helpful.

     

    Thank you!