Forum Discussion
RLS using USERPRINCIPAL Name - for 50+ users - need to add them all individually?
- 2 years ago
In Dynamic RLS you usually have a single role. That role has ideally only distribution lists as members , usually PDLs maintained by an external tool.
The issue is we still have to go into the service security and add ever user individually to that role.
Not sure I understand that part. Usually all you need to do is refresh your semantic model to pull in the new user mapping information.
You can consider using Direct Query with SSO passthrough
Maybe I misunderstood how RLS works but I thought that everyone who needs to be secured - in addition to being in the database - and filtered via RLS - they also need to be added to the role in PBI service for the given semantic model's security here:
ie. this is not the last step:
...still need everyone to be added individually to PBI service role. Not great as we have 50 or so users so far and there will be many more in the future. And cannot assign a group to a role - and have it work.
- lbendlin2 years ago
Super User
In Dynamic RLS you usually have a single role. That role has ideally only distribution lists as members , usually PDLs maintained by an external tool.