Forum Discussion

Anonymous's avatar
Anonymous
Not applicable
2 years ago
Solved

Power BI Permissions Management Process

I am curious what everyone is using to manage permissions in Fabric/Power BI. 

 

When using live pointers to semantic models, users need permissions on both the report and the dataset. The report may be owned by an analyst but the dataset is owned by the IT team. If there is RLS on a dataset that adds another layer to it. With new Fabric permissions coming I can imagine this will add another layer of complexity. 

 

Currently today, we are using Azure Entra ID groups. We have used Power Apps in combination with Approvals for users to request access and data owners to approve. In most cases, we expose reports using a Power BI App. I have audiences set up so if users do not have access to the content of the app they see the embedded Power App with directions on how to request permission. However, some users are still getting links directly to the reports in the workspace and not the app so they click the "Get access to this report". It is causing a lot of confusion. 

Also as we move towards Fabri and OneLake I would like to make sure I am thinking of how to best organize the permissions as we anticipate having to implement a lot of RLS on the data in the lake . 

 

What is everyone else doing? Curious if there are better processes we have not explored. Thanks!

  • Anonymous's avatar
    Anonymous
    2 years ago

    You are currently on the right path, even when Fabric artifacts get integrated. The dataset (semenatic model) and report are not going to change if you use Import mode. If you use Direct Lake, there will be permissions needed for the data but you can still use the save groups you are using now with datasets. That is IF you are going to use Direct Lake. Currently, Import mode is still faster unless you need 'near real-time' data AND you have a very large dataset (like 200+ GB in size, which is pretty large).

1 Reply

  • Anonymous's avatar
    Anonymous
    Not applicable

    You are currently on the right path, even when Fabric artifacts get integrated. The dataset (semenatic model) and report are not going to change if you use Import mode. If you use Direct Lake, there will be permissions needed for the data but you can still use the save groups you are using now with datasets. That is IF you are going to use Direct Lake. Currently, Import mode is still faster unless you need 'near real-time' data AND you have a very large dataset (like 200+ GB in size, which is pretty large).