Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

The Power BI Data Visualization World Championships is back! Get ahead of the game and start preparing now! Learn more

Reply
Kvingur
New Member

Security group with workspace member role - does not have access to report using RLS

Hi

I have a workspace where I added a security group with the member role. 

 

The workspace has a dataset with Row Level Security. According to the role guide, only the viewer role uses RLS but for other roles in the workspace, RLS does not apply. So I thought the members of the security group would be able to see and access the report and dataset with RLS. 

However, the members of the security group, they had no access to the report or dataset until I added the security group as a role member in the RLS security setup for the dataset. 

 

Are security group members handled differently to individual users in a workspace regarding access to datasets with RLS?

1 ACCEPTED SOLUTION
nilendraFabric
Super User
Super User

Hello @Kvingur 

RLS behaves differently depending on the workspace role assigned to users or groups.

 

  • RLS only applies to users with the Viewer role in a workspace. Users with AdminMember, or Contributor roles are not subject to RLS and can access all data in the dataset without restrictions
  • This means that if a security group is assigned the Member role in a workspace, its members will have full access to all data in the dataset, bypassing any RLS filters.
  • When you added the security group with the Member role in the workspace, RLS was not applied because this role bypasses RLS.
  • However, since they were not explicitly assigned to an RLS role in the dataset, they could not access any data due to lack of proper permissions

 

Best practices:

  • Use Viewer roles for users or groups that need restricted access based on RLS filters.
  • Assign security groups directly to RLS roles within the dataset’s security settings. This ensures that all members of the group inherit the appropriate row-level permissions dynamically

 

Please accept the answer if this helps 

 

View solution in original post

2 REPLIES 2
Kvingur
New Member

Thank you very much for the good answer @nilendraFabric  🙂 This explains it.

nilendraFabric
Super User
Super User

Hello @Kvingur 

RLS behaves differently depending on the workspace role assigned to users or groups.

 

  • RLS only applies to users with the Viewer role in a workspace. Users with AdminMember, or Contributor roles are not subject to RLS and can access all data in the dataset without restrictions
  • This means that if a security group is assigned the Member role in a workspace, its members will have full access to all data in the dataset, bypassing any RLS filters.
  • When you added the security group with the Member role in the workspace, RLS was not applied because this role bypasses RLS.
  • However, since they were not explicitly assigned to an RLS role in the dataset, they could not access any data due to lack of proper permissions

 

Best practices:

  • Use Viewer roles for users or groups that need restricted access based on RLS filters.
  • Assign security groups directly to RLS roles within the dataset’s security settings. This ensures that all members of the group inherit the appropriate row-level permissions dynamically

 

Please accept the answer if this helps 

 

Helpful resources

Announcements
Power BI DataViz World Championships

Power BI Dataviz World Championships

The Power BI Data Visualization World Championships is back! Get ahead of the game and start preparing now!

December 2025 Power BI Update Carousel

Power BI Monthly Update - December 2025

Check out the December 2025 Power BI Holiday Recap!

FabCon Atlanta 2026 carousel

FabCon Atlanta 2026

Join us at FabCon Atlanta, March 16-20, for the ultimate Fabric, Power BI, AI and SQL community-led event. Save $200 with code FABCOMM.