- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sharepoint online data security
Hi,
I had a request from a user who tried to share their report with a colleague, but they were unable to view the data in the report.
The source for the report was an excel file held in sharepoint online, so I suggested that their colleague needed to be granted access to the sharepoint file in order to access the report.
I understand that this could cause an issue if the user wanted their report to be viewed but not the source file, but in this incident it wasn't an issue.
However, whilst looking at a report for another user, I noticed that some of the visuals were referencing a source in a sharepoint online location.
Now I could see the data in the visual in the service version and the pbix version of the report, but when I went onto data source settings and copied the link to their sharepoint site, I saw that I did not have access to the site.
Does anyone know how it is possible for someone to view data in a report where they don't have access the source file in sharepoint online?
We were looking into data source credentials in the service version of the report, and were trying to work out if it was to do with the report itself always having the creators sign in credentials added so that anyone they share the report with can view it?
Any help would be greatly appreciated, although not looking for RLS solutions please!
Cheers,
Will
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Don't forget that the connection user scope does not need to match the scope of the report user. In fact, this is one of the min causes for accidental oversharing (exactly the things that RLS is attempting to restrict).
To make matters even more interesting you can be given access to a file in a sharepoint but NOT to the actual sharepoint site. Now that is truly messed up 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @willatkinson ,
May I ask if you have gotten this issue resolved?
If it is solved, please mark the helpful reply or share your solution and accept it as solution, it will be helpful for other members of the community who have similar problems as yours to solve it faster .
Thank you very much for your kind cooperation!
Best Regards,
Dengliang Li.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Don't forget that the connection user scope does not need to match the scope of the report user. In fact, this is one of the min causes for accidental oversharing (exactly the things that RLS is attempting to restrict).
To make matters even more interesting you can be given access to a file in a sharepoint but NOT to the actual sharepoint site. Now that is truly messed up 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So does this mean someone can view data in a report, even if they don't have access to the sharepoint site?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, if the connection owner has access.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Oh ok thanks thats good to know. How do you configure this in the report in the PBI service?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do these authentication methods affect this?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not sure what you mean. Only OAuth2 is supported.

Helpful resources
Subject | Author | Posted | |
---|---|---|---|
10-16-2024 04:34 AM | |||
03-05-2024 01:48 PM | |||
06-17-2024 08:13 AM | |||
10-05-2023 03:59 PM | |||
07-21-2022 08:41 AM |