Forum Discussion
Power BI direct access, Azure AD access interaction
Hi,
I have launched a report on a Power BI workspace for my org.
Security is governed by users being allocated into azure AD groups that restrict data.
Issue is that some users have not be assigned into any of these AD groups and therefore are requesting direct read access to the report itself (therefore there is a list of users wanting to gain access to the report).
The process is to then inform these users to apply for access into their appropriate security group.
To help me manage the report going forward (as this report will have a lot of active users),
If I decline the user access requests (within the Manage Permissions > Pending section of the report) and instead have the users allocated into a security group, will this block their UPN from accessing the report even if they do exist within an Azure AD group?
Thanks,
Michael
1 Reply
- jaweher899
Impactful Individual
If a user is a member of an Azure AD group that has access to a report, and then they submit a direct access request to the report, declining the request will not prevent the user from accessing the report if they still have access through the Azure AD group.
However, if you add the user to the appropriate Azure AD group that already has access to the report, the user should be able to access the report without requiring a direct access request.
To manage access to the report going forward, it's best to continue to use Azure AD groups to control access rather than direct access requests. This will help ensure that the appropriate users have access to the report while also making it easier for you to manage permissions. You can also periodically review the membership of the Azure AD groups to ensure that the right people have access to the report.