Get certified for free when you join Fabric Data Days 2026 and dive into Fabric, Power BI, SQL, AI, and other essential data skills.
Join nowJuly 28 - August 9 | Final Round of the Power BI Dataviz World Championships. This is your chance. Learn more
Hi
I have currently started using Org Apps with audiences, and we have been deploying them.
When they deploy to the workspace, they automatically pick up the permissions from the workspace - some groups have viewer permissions, admin etc. However, as we have audiences we would like the option to remove groups from the audience as there are many - audience has slightly changed from workspace app.
Is this possible? For example we only want the users in the audience to view the reprot, and not to include every single workspace group as well to view the report as well in the specified audience.
Hope that makes sense! Happy to clarify.
Thanks
Karen
Solved! Go to Solution.
Hi @KarenL7,
It is not possible to prevent someone with viewer permissions on the workspace from viewing the report. Viewer grants them access to see all reports in the workspace.
If you want permissions to be handled solely by audiences, I recommend removing individual workspace permissions.
Proud to be a Super User! | |
Makes sense, and it's a common trip-up. The short version: you can't remove those workspace groups from the audience, because their access isn't coming from the audience at all. It's coming from their workspace role.
Anyone with a workspace role (admin, member, contributor or viewer) automatically gets access to the app and its audiences. Audience membership only adds people on top of that, it can't subtract someone who already has workspace access. So the viewer groups you're seeing in the audience are there because they're workspace viewers, not because of the audience settings.
The fix is at the workspace level, not the audience. Keep workspace roles limited to the people who actually build and maintain the reports, and take the consumer groups out of the workspace viewer role. Then give those consumers access only through the specific audience. Once a group's only route to the content is the audience, the audience genuinely controls who sees what.
So: pull the consumer groups out of the workspace roles, add them to the audience instead, and the workspace-wide access falls away.
Out of interest, how big is the org, and how are you licensing the viewers, all on Pro, or on an F capacity?
Makes sense, and it's a common trip-up. The short version: you can't remove those workspace groups from the audience, because their access isn't coming from the audience at all. It's coming from their workspace role.
Anyone with a workspace role (admin, member, contributor or viewer) automatically gets access to the app and its audiences. Audience membership only adds people on top of that, it can't subtract someone who already has workspace access. So the viewer groups you're seeing in the audience are there because they're workspace viewers, not because of the audience settings.
The fix is at the workspace level, not the audience. Keep workspace roles limited to the people who actually build and maintain the reports, and take the consumer groups out of the workspace viewer role. Then give those consumers access only through the specific audience. Once a group's only route to the content is the audience, the audience genuinely controls who sees what.
So: pull the consumer groups out of the workspace roles, add them to the audience instead, and the workspace-wide access falls away.
Out of interest, how big is the org, and how are you licensing the viewers, all on Pro, or on an F capacity?
Hi @DataTako
Yes you are correct, I think we saw this with the workspace app - but it was not as obvious as it is in the new structure in the org app. So we will remove them from the workspace - but we will need to do this in new areas going forward as we are just moving over to org apps now as we still have some people accessing via the workspace.
Everyone is able to view reports we do not have this issue so we will use this solution going forward.
Thanks for your help.
Karen
Hi @KarenL7,
It is not possible to prevent someone with viewer permissions on the workspace from viewing the report. Viewer grants them access to see all reports in the workspace.
If you want permissions to be handled solely by audiences, I recommend removing individual workspace permissions.
Proud to be a Super User! | |
Thank you for your reply, yes this is a very good idea to remove workspace permissions - I think we should do this from now on - we are just moving over to org apps and have been so used to adding in workspace permissions as a normal route that we will do this.
Even with the workspace app we used we did not seem to have many issues - with the new structure in the org app you can really see the permission structure.
Thanks
Karen
Join us in Barcelona for FabCon and SQLCon, the Fabric, Power BI, SQL, and AI community event. Save €200 with code FABCMTY200.
If you love stickers, then you will definitely want to check out our community sticker challenge, Barcelona edition!
Check out the July 2026 Power BI update to learn about new features.
| User | Count |
|---|---|
| 14 | |
| 9 | |
| 9 | |
| 8 | |
| 6 |