Forum Discussion

jdusek92's avatar
jdusek92
Advocate III
7 years ago
Solved

RLS for group

Hello,

I have successfully set up RLS report filtering via [mail] = userprincipalname() .

It all works fine while adding individual users to:

  • My Workspace/REPORTS/Report/Share

and

  • My Workspace/DATASETS/Dataset/Security/Role/add user

 

But when I add a group the permissions are not set up correctly and the user cannot view the report/data

I checked in AD that the tested user is member of that group.

 

Is this the intened behaviour or did I miss any step here?

 

What can I do to share the report to a group while still having the RLS rule [mail] = userprincipalname() applied?

 

EDIT:

 

Scenario:

I want to create some kind of HR self service report for employees where every individual employee will see only HIS/HER data.

The data is basically just transformed output from our HR system.

I have already prepared the data set - a single table with data of all employees

There is a column with Office 365 email address that corresponds with userprincipalname()

 

Therefore the goal is not to use RLS to limit specific AD groups to access only its rows (like Group USA Office to see only USA data)

The goal is to limit every user to see only his/her data - one row of data will only be access by one user (not by the whole group)

 

sharing the report to specific users and assigning them to RLS role works fine.

I want to share to a whole AD group while still each member will only see his/her data.

 

 

Thank you

 

 

  • GilbertQ thank you very much for your input.

     

    It was a false alert, the user I tested on has not been in the group I shared the report and dataset to.

     

2 Replies