Register now to learn Fabric in free live sessions led by the best Microsoft experts. From Apr 16 to May 9, in English and Spanish.
So right now I've a dashboard dedicated for A department. Moving forward, B and C department also wants the same dashboard.
The solution that I've come out is by appending data from B and C to A dashboard and apply RLS.
However, the issue is B and C wants the same dashboard as A but at the same time also requests several new visuals and new pages to A dashboard. For this issue, the solution that I was suggested is to list out all the pages in Excel Sharepoint including the new ones and restrict it to B & C users only. The thing is, B & C is a huge department and might involve thousands of users. It seems impossible to list every B & C users and pages that they can have access. Way forward, the Excel will be hard to maintain especially when there are new joiners.
To simplify:
1. RLS is applied to A, B & C department.
2. B & C department requests for different visuals and to add several new pages to A department's dashboard.
3. How to apply RLS for new pages and visuals in B & C dashboard when the users for both departments are in huge volume.
Really need some help and recommendations on how can I solve this.
Solved! Go to Solution.
The RLS is attached to the model, not the dashboards. You can make different dashboards using the same model and they will all get the RLS that is applied to the model. So I would reccomend a dashboard for each department all pointing to the same model.
For large organizations it is far easier to use active directory security groups to assign users to RLS roles. You assign the security groups to the role rather than the individual users.
My guess would be that your organization already has security groups for the departments so you can use the ones in place.
When a new user is added to one of the security groups that is assigned to a role in the model RLS, they will automatically have the RLS applied to them. The same is true if they change security groups, the would get the RLS from their new role.
You can also use the active directory groups to share the dashboards so each group would only see their dashboard and new users assinged to the active directory groups would automatically get access and have the RLS applied.
The RLS is attached to the model, not the dashboards. You can make different dashboards using the same model and they will all get the RLS that is applied to the model. So I would reccomend a dashboard for each department all pointing to the same model.
For large organizations it is far easier to use active directory security groups to assign users to RLS roles. You assign the security groups to the role rather than the individual users.
My guess would be that your organization already has security groups for the departments so you can use the ones in place.
When a new user is added to one of the security groups that is assigned to a role in the model RLS, they will automatically have the RLS applied to them. The same is true if they change security groups, the would get the RLS from their new role.
You can also use the active directory groups to share the dashboards so each group would only see their dashboard and new users assinged to the active directory groups would automatically get access and have the RLS applied.
Covering the world! 9:00-10:30 AM Sydney, 4:00-5:30 PM CET (Paris/Berlin), 7:00-8:30 PM Mexico City
Check out the April 2024 Power BI update to learn about new features.
User | Count |
---|---|
110 | |
94 | |
81 | |
66 | |
58 |
User | Count |
---|---|
150 | |
119 | |
104 | |
87 | |
67 |