Forum Discussion
Row level security - Access Denied - Users / AD Group already added to Security in the Service
Hi
I have an issue with Row level Security on one of my reports. I have been looking at numerous other posts for solutions and they don't quite match.
- I have a report which has Role Level Security which is accessed via a workspace app. It is accessed by an AD group
- They can open the reports but not the reports as they get the following message -
- Just to confirm the users who access it have just been added to the AD group and this has been updated recently.
- The Original users from the same group can open the reports from the same app, access and see the reports without any issues
Just to confirm I have gone to the service and went to "Manage Permissions", "Security" and ensured the that group has been mapped to the correct role.
I looked in the report and can see the role is available in the report (although I this is an intial look as the report is not mine.
Has anyone any ideas how to resolve RLS? Should I readd the group maybe to refresh the group perhaps so it picks up the new users? As it working for the original users in the same group.
Any ideas would be appreciated.
Thanks
Karen
10 Replies
- Lodha_Jaydeep
Solution Sage
Hi KarenL7,
Can you check to see if in the Entra Admin Center you can see the newly added users?
Till than you can have it tested as,
1) Add the Direct UPN/Email in the RLS instead adding group and test the Report by role. From Dataset
2) Please ensure you added the correct DAX for the RLS. It should something like,
[UserEmail] = USERPRINCIPALNAME()
3) Users were added in the correct group not the others.
4) The errror you are facing is on the App? If yes App has been published after the RLS were updated?
Also, if you can provide the used DAX It will help to check more.
https://learn.microsoft.com/en-us/fabric/security/service-admin-row-level-securityI hope this helps, please consider as an accepted solution if helps or give some kudos. Also, let me know your outcome from the options mentioned!
- KarenL7
Advocate V
Thanks for coming back to me.
1. I can confirm that the users are accessing the report via a workspace app.
2. I have checked the group in AD - the users have been correctly added.
3. Yes the app was published before these users were added
With this last point in mind - I will check and update the app and ask them to check again, as this may be a sync issue? I may even readd the group to security to update this - before I update the app.
I cannot really check much DAX as it not my report - but I will try the other solutions first and come back
Thanks
Karen- Lodha_Jaydeep
Solution Sage
Hi KarenL7,
Thannks for reply, As you mentioned it's not the case as I mentioned then it might be sync issue. Can you ask them to hard refresh the browser page (Ctrl+Shift+R) and check to see if report loads.
- ibarrau
Super User
Hi. If you are sure the new member is viewer of the workspace or the power bi app, it's in the security of the semantic model and has read access to semantic model... then it's matter of time. This changes are not instantly applied sometimes and the users could also have cache in the browser (ask them to click shift + F5). Be patient, try again later and come back to let us know.
Regards
- KarenL7
Advocate V
Hi ibarrau
Thanks for coming back to me.
Yes I think it is a matter of time or a sync issue - this did not occur to me really - it just frustated me that the some users in the same group had access and some didnt.
I have even thought about readding the group and republishing the app and see what that does,
I will come back to you and let you know.
thanks for your help
Karen
- AnonymousNot applicable
Hi KarenL7 ,
Just checking if there is any update on this.After republishing the app and re-adding the group, are the new users able to access the report now?
It would be helpful to know whether the issue was due to a sync delay or if it is still happening.
Please let us know the outcome. If the issue is still there, reach out here and we will be happy to help further.Regards,
Community Support Team.