Join us at FabCon Atlanta from March 16 - 20, 2026, for the ultimate Fabric, Power BI, AI and SQL community-led event. Save $200 with code FABCOMM.
Register now!The Power BI Data Visualization World Championships is back! Get ahead of the game and start preparing now! Learn more
Hi All,
I have identified anomalies when attempting to apply Row Level Security to specific email addresses only. This is across three domains [ .com | .com.au | .co.uk ]
To replicate the scenario I created a simple test / proof of concept. One table. One Security Role. One Measure.
The Security Users table is sourced from an Excel workbook. Seven email addresses across the three domains:
I have created a single role called Security. This is applied to the Security Users table as [Principal] = USERPRINCIPALNAME()
I have created a measure to sanity check: mUserPrincipalName = USERPRINCIPALNAME()
Desktop Row Level Security logic works as expected. "View As" etc. Publishes to the service fine.
All email addresses are valid in the service, have been added to the Security group:
The problem:
Naturally this leads to the idea that it is a domain specific issue, but not sure where to look?
Any adivce would be appreciated.
Thanks in advance.
The only way RLS is overwritten if the users are members in the workspace and have one of these following roles:
1-admin
2-member
3-contributor
If they are assigned with any of these, RLS will show everything. Can you check if they are members of the workspace? They could also be hidden in a security group.
The Power BI Data Visualization World Championships is back! Get ahead of the game and start preparing now!
| User | Count |
|---|---|
| 56 | |
| 55 | |
| 32 | |
| 18 | |
| 14 |