Forum Discussion

showy123's avatar
showy123
Frequent Visitor
6 months ago
Solved

Power BI Service security model with multiple workspaces, shared dataset, RLS, export and links

Hello everyone, I have a conceptual question regarding the security and permission model in Power BI Service and would like to validate whether my current architecture follows best practices. My ge...
  • rohit1991's avatar
    6 months ago

    Hii showy123 

     

    In Power BI Service, the best-practice security model is to separate content, data, and security: keep shared datasets in a dedicated “data” workspace, apply RLS only on the dataset, and give users access to reports via Apps or report workspaces (Viewer role) rather than direct dataset permissions. Avoid granting Build / Read on datasets unless needed, because export and Analyze in Excel are controlled at the dataset permission + tenant setting level, not by report access. Use Azure AD groups for all access, control exports centrally, and remember that RLS always applies, even when users open reports via links, apps, or Analyze in Excel unless they are dataset Owners/Admins.

  • v-nmadadi-msft's avatar
    6 months ago

    Hi showy123 ,
    Thanks for reaching out to the Microsoft Fabric Community forum.


    Organizing workspaces effectively is a critical part of workspace planning. Different business units and departments may use workspaces in different ways based on their collaboration needs. When creating a new workspace, it’s recommended to take these factors into account to ensure the workspace is set up appropriately.
    You can check them out in this article here:
    Implementation Planning: Workspace-Level Workspaces - Power BI | Microsoft Learn

     

     

     

    I hope this information helps. Please do let us know if you have any further queries.
    Thank you