cancel
Showing results for 
Search instead for 
Did you mean: 
0

RLS security does not apply on exported data when tested by role in Power BI Service

Hello Team,

 

Please log the following bug.

 

We have noticed that when RLS security is applied in a report and published on service, to test it we use the Test By Role option present under Datasets > Security option. 

When the report opens, it perfectly applies the security, however, when you export the data from visual, the exported data contains all the rows present in the dataset, thus completely ignoring the security mechanism.

 

Here is an example to repro this.

 

I have following sample dataset:

 

Capture.PNG

 

Now, my email address which is obfuscated has access to India Geo only.

When I go to Power BI Service, datasets > Security > Test By Role, the report loads fine showing only one entry of mine i.e for India role.

Capture.PNG

 

Now, when I export this data in excel, it gives me all the rows as original dataset which is totally blowing up the security part.

 

Capture.PNG

 

Please bring this into the notice of the Dev Team. This feature is very important for our customers to test security in reports before sharing sensitive data out. However, these kind of flaws really drop the confidence in them for this product.

-Prateek Raina

 

 

 

 

 

Status: Delivered
Comments
Moderator

@prateekraina,

Do you export summarized data from the visual? I create a rls role using username() function and export data in Power BI Service, RLS is not ignored. How do you create the RLS role in your PBIX file?
2.PNG1.PNG

Regards,
Lydia

Moderator
Status changed to: Needs Info
 
New Contributor

Hi @v-yuezhe-msft,

 

I am afraid that you have missed the whole point of the issue I am speaking about.
This bug appears when you test the report using"Test as Role" feature present under Dataset > Security.

 

See below screenshots:

Capture5.PNG

Capture4.PNG

 

Capture3.PNG

 

As requested, I have created two roles:

1. India - [Geo] = 'India'

2. US - [Geo] = 'US'

 

Refer

below screenshots:

 

India

Capture1.PNG

 

US

Capture2.PNG

 

Then I added my email address to India role.
Now when you use Test as Role feature and choose India as the Role, I do see a single row which is perfect. However, when I export the data from that visual all the rows are displayed.

 

I hope you can now repro this issue. Let me know in case any other information is required.

 

-Prateek Raina

 

Moderator

@prateekraina,

I can reproduce this issue, I will consult this issue internally.

Regards,
Lydia

Moderator

@prateekraina,

I got response from PG:

"This is by design. It is just to test the role but not to apply the same filter for exporting."



Regards,
Lydia

Moderator
Status changed to: Delivered