Forum Discussion
Power BI security levels
- 2 years ago
I can explain some basics regarding Power BI.
All local Power BI files are secured on those clients obviously.
When you upload a file to the Power BI Service (app.powerbi.com) - the reports and semantic models will live in a workspace. A workspace is like a folder where you can apply permissions to access.
You can also build apps (mostly used for distributing reports with a big audience) or even share reports and models individually (without granting workspace level permission).
All of the mentioned above I would call security on an artifact level (either you have access or you dont)
Then we also have more granular security e.g. row-level security.
Even though 100 people have access to a report, app or a model, they might not be allowed to see all data. This is where we can apply RLS (row-level security).
You can build these RLS roles in Power BI Desktop and then assign users or Entra groups to these roles.
E.g. Region = "West" so that some people only see data for this region.
Object-level security is when you want to hide one KPI e.g. inside a visual - it is not used as much as RLS.
Let me know if that helps you understand a little better how it works in Power BI.
I can explain some basics regarding Power BI.
All local Power BI files are secured on those clients obviously.
When you upload a file to the Power BI Service (app.powerbi.com) - the reports and semantic models will live in a workspace. A workspace is like a folder where you can apply permissions to access.
You can also build apps (mostly used for distributing reports with a big audience) or even share reports and models individually (without granting workspace level permission).
All of the mentioned above I would call security on an artifact level (either you have access or you dont)
Then we also have more granular security e.g. row-level security.
Even though 100 people have access to a report, app or a model, they might not be allowed to see all data. This is where we can apply RLS (row-level security).
You can build these RLS roles in Power BI Desktop and then assign users or Entra groups to these roles.
E.g. Region = "West" so that some people only see data for this region.
Object-level security is when you want to hide one KPI e.g. inside a visual - it is not used as much as RLS.
Let me know if that helps you understand a little better how it works in Power BI.
- Viktorija072 years agoNew Member
It helps me understand it better.
When you said: "You can also build apps (mostly used for distributing reports with a big audience)" you mean PowerApps app?
User needs to have Power BI license to see workspace/reports/models if I shared those with them?
Do you know if I use something in Power BI that is from ERP (Dynamics 365 F&O), does the user need license for both Power BI and ERP? Can they have only Power BI license to see workspace, models and reports?
- Brunner_BI2 years agoImpactful Individual
By apps I mean an app inside Power BI which is one or a collection of reports.
You can see it on the left in the main navigation when you are in the Power BI Service.
Every user who wants to consume or is being shared something needs a license - unless you buy a Premium Capacity which is expensive.
Only if you have Office 365 E5 the Power BI Pro license is included.
If a user has no license they can only see their "My workspace"