Forum Discussion

lauren2021's avatar
lauren2021
Frequent Visitor
5 years ago

Row Level Security to a Shared Report

Hi all,

 

Looking for some help with RLS. I am currently updating a report on the PBI service but am having issues with RLS. I have been able to create various roles on the report itself, (i.e. User1, User2, etc) and am able to add people to their roles on the service, but they don't appear to be working. I am wondering if this is because they have already accessed the report via a shared link in the past, before I applied the RLS to them? The roles work just fine for someone who has not accessed the report already. 

 

I have made sure that these users do not have access to the Workspace itself, as members, viewers, contributors, etc. They are not listed at all and can only access specific reports via the Shared Link option.

 

Any help would be appreciated!

8 Replies

  • Hi lauren2021 

     

    Sharing of a report should not affect the RLS permissions.


    Could you go into the dataset and then Manage permissions and see what permissions those users have?

     

    My guess is that those users have got the BUILD permission on the dataset. If they do have the build permission this will overwrite the RLS.

     

    You can fix this by removing build and make sure that they only have READ access.

    • lauren2021's avatar
      lauren2021
      Frequent Visitor

      Hi GilbertQ 

       

      I went back and double checked, but none of the users that I am having issues with are even listed under the 'Access' or 'Manage Permissions.' I've tried adding someone and changing their access to 'Viewer', but that didn't work either.

       

      Thanks so much for your response!

      • v-easonf-msft's avatar
        v-easonf-msft
        Community Support

        Hi, lauren2021 

        What is your current data source?

        Is it dynamic RLS or static RLS? Has these invalid members been added to a specific group?

        Please recheck the current table filter dax expression in powerbi desktop and validate the role within the Power BI service  before  you add users' email addresses.

         

        In addition, please refer to this documnet  to make sure  that  these  users only have read-only access to reports in the  workspace.

         

        Best Regards,
        Community Support Team _ Eason

  • Hi lauren2021 

     

    Can you confirm that you look at the dataset permissions as shown below in my example?

     

     

    Then once in the permissions make sure that the users only have READ permissions and not Read and Build as shown below

     

     

    • lauren2021's avatar
      lauren2021
      Frequent Visitor

      Yep. I went into Manage Permissions as shown, but the user that I am having issues with aren't on the list at all. It only shows the 6 or so people I have added directly. However, when I share the link to the report with them, they can see everything. They are logged in when they access the report, but it isn't showing them on the list of Permissions

  • Hi lauren2021 

     

    Could you make sure that the same user account has got access to the RLS in the same dataset?

     

    It appears that something else is allowing them to see everything.

  • PC2790's avatar
    PC2790
    Community Champion

    Hi lauren2021,

     

    Can you please advise what importing strategy are you using for your data? Is it Import, Direct query or Live as there are certain limitations with the cloud models for RLS.

    Also, are all the users of your report inside your organisation?

    You can also ask the users to log off and login again and check if they still are able to see all of the data.

    • v-easonf-msft's avatar
      v-easonf-msft
      Community Support

      Hi, lauren2021 

      Could you please tell me whether your problem has been solved?
      If yes, you could accept the helpful answer as solution. You also could share your own solution here. For now, there is no content of description in the thread. If you still need help, please share more details to us.

      Best Regards,
      Community Support Team _ Eason