Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Register now to learn Fabric in free live sessions led by the best Microsoft experts. From Apr 16 to May 9, in English and Spanish.

Reply
msommerf
Helper III
Helper III

RLS not working using AD Group across multiple domains.

I have a dataset to which I created roles for example:

RoleName - Operating_Company="Company1"

 

I test this role in PBI Desktop and it works fine. Data is filtered by Operating Company.

The report is then Published.

 

I add security to the report in the Power BI Service adding in an Active Directory Security Group which has the reveant users included.

 

I test this functionality and it works fine, Again in test, data is filtered by Operating Company.

 

When a user from my domain accesses the report, the data is filtered correctly, but when a user from a different domain accesses the report, no data is displayed and all visuals display a cross in them. Both users are in the same AD Security Group.

 

Users in the AD Security Group have viewer access to the Workspace.

 

Is this an issue with the way the AD groups have been created as it appears not to work for users outside of my domain?

Any assistance appreciated.

 

 

2 ACCEPTED SOLUTIONS
v-lid-msft
Community Support
Community Support

Hi @msommerf ,

 

The RLS with AD Security Group works fine on my side as following, do you mean add the group as the role? Or use the dynamic RLS role?

 

12.25.PNG12.5.PNG13.PNG14.5.PNG14.PNG15.PNG

 

Best regards,

Community Support Team _ Dong Li
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

Community Support Team _ Dong Li
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

View solution in original post

Many thanks for responding on this.

 

I have solved the issue.

I removed the AD Groups which were created and setup O365 Distribution Lists and added my users to the list.

The RLS is now working correctly across all domains.

Kind regards

Mark.

View solution in original post

2 REPLIES 2
v-lid-msft
Community Support
Community Support

Hi @msommerf ,

 

The RLS with AD Security Group works fine on my side as following, do you mean add the group as the role? Or use the dynamic RLS role?

 

12.25.PNG12.5.PNG13.PNG14.5.PNG14.PNG15.PNG

 

Best regards,

Community Support Team _ Dong Li
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

Community Support Team _ Dong Li
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

Many thanks for responding on this.

 

I have solved the issue.

I removed the AD Groups which were created and setup O365 Distribution Lists and added my users to the list.

The RLS is now working correctly across all domains.

Kind regards

Mark.

Helpful resources

Announcements
Microsoft Fabric Learn Together

Microsoft Fabric Learn Together

Covering the world! 9:00-10:30 AM Sydney, 4:00-5:30 PM CET (Paris/Berlin), 7:00-8:30 PM Mexico City

PBI_APRIL_CAROUSEL1

Power BI Monthly Update - April 2024

Check out the April 2024 Power BI update to learn about new features.

April Fabric Community Update

Fabric Community Update - April 2024

Find out what's new and trending in the Fabric Community.