Forum Discussion
Power Automate – Export PBI Thin Report (Shared Semantic Model) with Dynamic RLS- Supported or Not ?
- 4 months ago
1) The Export to File for Reports API fully supports thin reports connected to shared Power BI semantic models.
2) The limitation applies only to external Analysis Services connections — Azure Analysis Services and on-premises SSAS via live connection. A thin report pointing to a Power BI semantic model within the same tenant is treated as a native Power BI connection, not an external live connection, and is fully supported by the export API.
3) Yes, for dynamic RLS based on USERPRINCIPALNAME() this is the correct and only supported pattern. The API accepts an effectiveIdentity parameter where you pass the target user's UPN. The export engine then evaluates RLS as that user and returns only their permitted data. But you need to parameterize UPN otherwise it would use your own credential which probably would break RLS configuration.
Alternatively, you could use dynamic subscriptions instead of power automate which is probably the easiest way to do.
https://learn.microsoft.com/en-us/power-bi/collaborate-share/power-bi-dynamic-report-subscriptions
- Yes
- The limitation applies to external semantic models, specifically; SQL Server Analysis Services (SSAS) and Azure Analysis Services (AAS). The export API cannot impersonate users across external engines or enforce RLS security across service boundaries.
- Yes, the safest pattern is loop per user + pass identity.
- In Power Automate:
- Iterate over users
- Call Export to File for Power BI reports
- In Power Automate:
- Use the EffeciveIdentity (or “userbame) field in the connector)
- Set it to the user’s UPN
- As always MS documentation is a bit fragmented and you have to piece it together from multiple places but you should find your clarity in MS saying that Power BI datasets are supported and Live connections are not supported; think of Power BI datasets as internal and live connections being external.