Forum Discussion
Row-Level Security - Unable To Apply Active Directory Group
Hello,
I am able to successfully add a user group for workspace access, however when I attempt to enable that same group and apply them to the "All Access" RLS security dataset role, the group does not intellisense show up in the search bar when I start typing, and when I copy/paste the group name in, Power BI Service does not allow me to save my Active Directory Group to the role and save.
Given "Viewer" role at workspace, and granted "Build Permissions" and re-share permissions on dataset
This screen will not allow me to save and proceed, so I have to cancel
Hi Anonymous ,
It's the "build permission". You can't give build permissions and have RLS work. If you create users in a Workspace as "Viewer" they don't have build permissions by default, so RLS will work. However give them build permissions and RLS will not work.
Hope this helps
Stuart
2 Replies
- AnonymousNot applicable
Hi Anonymous
RLS does not support 365 groups, so you cannot add this group to the RLS member list. This has nothing to do with adding groups in the workspace role. I add the Distribution group in workspace access ,and then I can also add a distribution group in RLS .
Workspace members assigned Admin, Member, or Contributor have edit permission for the dataset and, therefore, RLS doesn’t apply to them.
You can refer to the link below to learn more about the RLS .
https://docs.microsoft.com/en-us/power-bi/admin/service-admin-rls#limitations
Best Regards
Community Support Team _ Ailsa Tao
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.
- BurningsuitResident Rockstar
Hi Anonymous ,
It's the "build permission". You can't give build permissions and have RLS work. If you create users in a Workspace as "Viewer" they don't have build permissions by default, so RLS will work. However give them build permissions and RLS will not work.
Hope this helps
Stuart