Forum Discussion

PBI_Developer2's avatar
PBI_Developer2
Frequent Visitor
2 months ago
Solved

Share semantic model with limited access

Hello Community,

 

In Power BI, is there a way to grant functional teams (Finance, Logistics, etc.) access to a semantic model so they can build reports and create measures in the Service, but without giving them permissions to edit or alter the semantic model itself?
 
Thank you.
  • Yes, but with one important distinction.

     

    If you want Finance, Logistics, etc. to build their own reports from the semantic model without being able to change the semantic model itself, give them Build permission on the semantic model, but do not give them Contributor/Member/Admin access to the workspace that contains the semantic model.

     

    Recommended pattern:
    1. Keep the certified/shared semantic model in a controlled workspace.
       Only the BI/data team should have Contributor/Member/Admin there.

    2. Grant the functional teams Build permission on the semantic model.
       This lets them build reports, use Analyze in Excel, and create content based on the model.

     

    3. Let each team build reports in their own workspace.
       For example:
       - Finance Reporting workspace
       - Logistics Reporting workspace
       - Sales Reporting workspace

     

    4. Do not grant Write permission on the semantic model.
       Write permission is what allows users to republish or modify the semantic model.

     

    Important nuance:
    If users want to create measures inside the central semantic model, then that is editing the model and requires higher permissions. If they only need team-specific reporting logic, the safer approach is to let them build their own reports or downstream/composite models without changing the certified model.

     

    So short answer:
    - Build permission = yes, they can build reports from the model.
    - Write / workspace Contributor = no, avoid this if you do not want them to alter the model.
    - Keep semantic model workspace locked down.
    - Give teams their own report workspaces.

     

    Useful Microsoft guides:
    Build permission for shared semantic models:
    https://learn.microsoft.com/en-us/power-bi/connect-data/service-datasets-build-permissions

     

    Semantic model permissions:
    https://learn.microsoft.com/en-us/power-bi/connect-data/service-datasets-permissions

     

    Share access to a semantic model:
    https://learn.microsoft.com/en-us/power-bi/connect-data/service-datasets-share

     

    Manage semantic model access permissions:
    https://learn.microsoft.com/en-us/power-bi/connect-data/service-datasets-manage-access-permissions

     

    Create reports based on semantic models from different workspaces:
    https://learn.microsoft.com/en-us/power-bi/connect-data/service-datasets-discover-across-workspaces
     

    🔍Parchitect
    Solutions Architect · Microsoft Fabric Specialist

    💡Helpful? Kudos are appreciated.
    ✔️Solved? Mark as Solution so others can find it faster.

5 Replies

  • Rupa01's avatar
    Rupa01
    Icon for Solution Sage rankSolution Sage

    Hi PBI_Developer2,

     

    Yes — this is absolutely possible using Build permission on the semantic model.

    • Grant users Build access to the semantic model, and Contributor access in a separate workspace where they can create reports.
    • Do not give them Write permission or higher roles in the semantic model workspace.

    This setup allows users to - 

    • Build reports and dashboards on top of the semantic model.
    • Create their own measures in report context.
    • Not modify the underlying semantic model.

    📌 Microsoft reference:
    Build permission for shared semantic models

    "When you give users Build permission, they can build new content on the semantic model, such as reports and dashboards."

     

    💡 Helpful? Give a Kudos 👍 — keep the community growing
     Solved your issue? Mark as Solution ✔️ — help others find it faster

    Best regards,
    Rupasree Achari | BI & Fabric Analytics Engineer
  • Yes, but with one important distinction.

     

    If you want Finance, Logistics, etc. to build their own reports from the semantic model without being able to change the semantic model itself, give them Build permission on the semantic model, but do not give them Contributor/Member/Admin access to the workspace that contains the semantic model.

     

    Recommended pattern:
    1. Keep the certified/shared semantic model in a controlled workspace.
       Only the BI/data team should have Contributor/Member/Admin there.

    2. Grant the functional teams Build permission on the semantic model.
       This lets them build reports, use Analyze in Excel, and create content based on the model.

     

    3. Let each team build reports in their own workspace.
       For example:
       - Finance Reporting workspace
       - Logistics Reporting workspace
       - Sales Reporting workspace

     

    4. Do not grant Write permission on the semantic model.
       Write permission is what allows users to republish or modify the semantic model.

     

    Important nuance:
    If users want to create measures inside the central semantic model, then that is editing the model and requires higher permissions. If they only need team-specific reporting logic, the safer approach is to let them build their own reports or downstream/composite models without changing the certified model.

     

    So short answer:
    - Build permission = yes, they can build reports from the model.
    - Write / workspace Contributor = no, avoid this if you do not want them to alter the model.
    - Keep semantic model workspace locked down.
    - Give teams their own report workspaces.

     

    Useful Microsoft guides:
    Build permission for shared semantic models:
    https://learn.microsoft.com/en-us/power-bi/connect-data/service-datasets-build-permissions

     

    Semantic model permissions:
    https://learn.microsoft.com/en-us/power-bi/connect-data/service-datasets-permissions

     

    Share access to a semantic model:
    https://learn.microsoft.com/en-us/power-bi/connect-data/service-datasets-share

     

    Manage semantic model access permissions:
    https://learn.microsoft.com/en-us/power-bi/connect-data/service-datasets-manage-access-permissions

     

    Create reports based on semantic models from different workspaces:
    https://learn.microsoft.com/en-us/power-bi/connect-data/service-datasets-discover-across-workspaces
     

    🔍Parchitect
    Solutions Architect · Microsoft Fabric Specialist

    💡Helpful? Kudos are appreciated.
    ✔️Solved? Mark as Solution so others can find it faster.

  • Hi PBI_Developer2 ,

    You can provide users with limited access by following this workflow: In your semantic model file on the desktop, ensure "Discourage DirectQuery connection" is unchecked. If this is checked, users will be unable to connect to the semantic model in DirectQuery mode. (Enable this only if you want users to use your semantic model as a source while adding a new table or object for data blending.)

    • In Workspace A, publish the semantic model and assign users to the Viewer role (not Contributor or higher).
    • On the semantic model, enable Build permissions (Read, Build, etc.) by right-clicking and selecting "Manage permissions."


    • Create a new Workspace B and add the users as Contributors; they will use this workspace to save their reports.
    • Users can now access the semantic model in Workspace A to build reports, which will be saved in Workspace B.


    Thanks 

     

     

  • v-aatheeque's avatar
    v-aatheeque
    Icon for Community Support rankCommunity Support

    Hi PBI_Developer2 

    We wanted to follow up to check if you’ve had an opportunity to review the previous responses. If you require further assistance, please don’t hesitate to let us know.

     

    • v-aatheeque's avatar
      v-aatheeque
      Icon for Community Support rankCommunity Support

      Hi PBI_Developer2 

      Have you had a chance to look through the responses shared earlier? If anything is still unclear, we’ll be happy to provide additional support.