Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

The Power BI DataViz World Championships are on! With four chances to enter, you could win a spot in the LIVE Grand Finale in Las Vegas. Show off your skills.

Reply
f13
Regular Visitor

Users can't see report with RLS even if they are part of the group who has access

Hi all!

 

We have a report that utilizes RLS. Our solution is set up in the following way:

  1. Based on email of employees we create a hierarchical path of managers.
    Path = PATH(Employees[EmployeeEmail], Employees[Email])
    it looks something like this: initial1@company.com|initial2@company.com|initial3@company.com.

  2. In Power BI, under Modeling>Manage roles, we create a role called "Manager" where we define the role security in the following way:
    PATHCONTAINS([Path], USERPRINCIPALNAME())

  3. After publishing to a Fabric workspace, we go into the Manage Permissions setting for the semantic model and the report and add the Entra group of the managers.

Until recently, there was no issue with this set-up. The only thing we changed was to move the path calculation from one table to another and we made sure that everything is working in Power BI before publishing it to the workspace.

 

After we have added the Entra group to the permissions (read only) they report that they can't see the report at all and get the following error message:
"The report can't be viewed because the underlying dataset uses row-level security (RLS)."

 

After deleting the report from the workpsace and re-publishing plus re-adding the user group to read permission, this issue is still standing.

1 ACCEPTED SOLUTION
f13
Regular Visitor

Update:

Wihout doing anything the RLS works again.

View solution in original post

2 REPLIES 2
f13
Regular Visitor

Update:

Wihout doing anything the RLS works again.

v-yilong-msft
Community Support
Community Support

Hi @f13 ,

This error suggests that there may be a problem with the way RLS is set up or the way users are recognized within the system, so I think you first need to make sure that the UPN used in the function maps correctly to the user's email address. You can look at this topic: Solved: The report can't be viewed because the underlying ... - Microsoft Fabric Community


Secondly I see that you have raised the following image:

vyilongmsft_0-1717381466163.png

So I think you may want to consider using a card visual object which may give you the effect you are looking for.

 

Since you have tried to delete and republish the report, make sure that when you re-add the user group, you also reconfigure the permissions exactly as they were when you worked on it previously.

 

 

 

Best Regards

Yilong Zhou

If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

Helpful resources

Announcements
Las Vegas 2025

Join us at the Microsoft Fabric Community Conference

March 31 - April 2, 2025, in Las Vegas, Nevada. Use code MSCUST for a $150 discount! Prices go up Feb. 11th.

Feb2025 Sticker Challenge

Join our Community Sticker Challenge 2025

If you love stickers, then you will definitely want to check out our Community Sticker Challenge!

Jan NL Carousel

Fabric Community Update - January 2025

Find out what's new and trending in the Fabric community.