Register now to learn Fabric in free live sessions led by the best Microsoft experts. From Apr 16 to May 9, in English and Spanish.
I also posted this as an Idea in Issues, but I'm also posting here to see if I can attach an example in the comments. Here's the original message. (Edit: It does not seem possible to attach a dashboard to a post or comment. Has this always been the case?)
I have been using row-level security to pass a user's role to the dashboard, allowing me to restrict visibility of elements in different ways throughout the dashboard based on the user's role. Since the Fall 2021 update, PowerBI seems to ignore the row-level security of a table in certain situations, specifically within calculated columns.
If it's possible to attach a dashboard, I can upload an example, but here's how to duplicate it:
After all that is set up, go to "Modeling" -> "View As" and set your role to User. You will see that [_UserRoles] will correctly change to "1 - User", but the [Viewable] calculated column will incorrectly stay mapped to 1 for each row in FilterTable. I was previously using this logic to filter the table to [Viewable] = 1, but now all the rows are showing up to everyone. My understanding is that this is because the [Viewable] calculated column is now ignoring the Row-Level Security on the UserRoles table.
Edit: After further testing, I am now sure Security Roles are not working properly. Putting measures in the table directly will show the correct value (in compliance with RLS), but using them inside a calculated columns allows you to see data you shouldn't. This could allow users to view data they should not be allowed to see.
@SamKrygsheld
You can save it in an online doc and share the link, make sure everyone with the link can access. Thanks.
Paul
Alright, here's a link: https://1drv.ms/u/s!AgTnvCMB7gUGg85-nj4Yeb1ZYDQIBw?e=9XrAyM
I tried but not able to create a proper model with provided steps, it is appreciated if you could just create a short sample pbix without sensitive information.
Paul Zheng _ Community Support Team
If this post helps, please Accept it as the solution to help the other members find it more quickly.
I have a pbix ready. Do you have a secure file upload or another way I can get it to you? I don't see an option to attach it to these posts.
@SamKrygsheld
We have an active Power BI Embedded service with hundreds of users. This afternoon a user complained that they could see other users' data - that's never happened before. The PBIX file has not been updated, and an inspection of the website code has not revealed any changes (and no changes have been made today).
I have reinstalled a version of the PBIX from July and the problem persists, so I'm fairly certain it's not the recent update of the Desktop software. Evidence is starting to point to MS code running Embedded in the Service.
I saw on one of your posts that Microsoft are investigating. They are welcome to get in touch with me (if they read this), although to be honest I don't think we can tell them much as we haven't changed anything today.
We have had to take down the service this evening. We will have to tell our users at 8am GMT tomorrow that there is no service. This would be the first time since we began 3+ years ago. I am hoping that Microsoft are urgently looking into this.
Please let me know if you find out anything else, thanks! And thanks for posting.
BTW, i don't use calculated columns in the RLS model part of the PBIX.
Covering the world! 9:00-10:30 AM Sydney, 4:00-5:30 PM CET (Paris/Berlin), 7:00-8:30 PM Mexico City
Check out the April 2024 Power BI update to learn about new features.
User | Count |
---|---|
108 | |
100 | |
78 | |
64 | |
58 |
User | Count |
---|---|
148 | |
111 | |
94 | |
84 | |
67 |