Forum Discussion
PowerBI Deployment process - prohibit user from publishing to upper-level environment workspaces
- 5 years ago
Hi, yjlee1212
In the process of deploying the pipeline, a new workspace will be generated every time it enters the next stage. For the content, they are related, but for the permissions of the workspace, they don't have to be related, you can define them separately according to your needs. In theory, for those who can deploy pipelines, higher permissions should to be granted at each stage. So for users with only viewer permissions, it can only view the contents of the corresponding workspace.
Reference: Manage who can deploy to production
Best Regards
Janey Guo
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.
Hi, yjlee1212
In the pbi service, users can publish reports in the workapce and my workspace created by themselves, and the workapce created by others must have permission to enter and view the report. So if you don’t want users to publish reports, you can remove users from the workspace or only grant viewer permissions.
Reference: Organize work in the new workspaces in Power BI - Power BI | Microsoft Docs
Best Regards
Janey Guo
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.
Hello v-janeyg-msft ,
Thank you for looking into my question. I have a follow-up question to the solution you showed me. If I configure all users with viewer access to `test` and `production` workspaces, can people still deploy reports from `development` workspaces to the other two workspaces via the Deployment pipeline? It would be great to know how the configuration in Workspace and the Deployment pipeline work together.
Thanks again!
Yong-Jin
- v-janeyg-msft5 years ago
Community Support
Hi, yjlee1212
In the process of deploying the pipeline, a new workspace will be generated every time it enters the next stage. For the content, they are related, but for the permissions of the workspace, they don't have to be related, you can define them separately according to your needs. In theory, for those who can deploy pipelines, higher permissions should to be granted at each stage. So for users with only viewer permissions, it can only view the contents of the corresponding workspace.
Reference: Manage who can deploy to production
Best Regards
Janey Guo
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.