Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Register now to learn Fabric in free live sessions led by the best Microsoft experts. From Apr 16 to May 9, in English and Spanish.

Reply
Anonymous
Not applicable

Grant users access to App without access to underlying Azure SSAS cube?

We have various Reports published via Apps all linked by live connection to an Azure SSAS cube.

 

Is it possible to grant users access to the App without having to also grant them individual access to the underlying cube? I was hoping the App might have some identity in Azure AD we could use to grant the App itself access to the cube.

 

The problem is that by granting the user access to the cube, as well as using the App, they can also then use Excel or any other tool to access the cube directly.

6 REPLIES 6
GilbertQ
Super User
Super User

Hi there

What if you had to use the User Mapping on the data source in the Manage Gateways in the Power BI Service?

Could that not pass them through directly?




Did I answer your question? Mark my post as a solution!

Proud to be a Super User!







Power BI Blog

Anonymous
Not applicable

There is no gateway as the the Power BI reports published in the Service have a live connection to our Azure Analysis Service tabular models.

Could see how UPN mapping would sort out our problem, but presuambly Dynamic Row-Level Security is going to stop working without access to the actual user ID from the DAX USERPRINCIPALNAME function?

Hi there

Yes that is correct, as long as you have got your Dynamic RLS defined with the UPN the mapping would work seamlessly.

That would be my recommended approach




Did I answer your question? Mark my post as a solution!

Proud to be a Super User!







Power BI Blog

Anonymous
Not applicable

Well it would work, but as I said, we are using Azure based Analaysis Services, hence no gateway, and therefore no UPN mapping.

Hi @Anonymous 

 

If you are using RLS you would always need to store the UPN so that it will then be transferred to AAS so they could be authenticated and then have the RLS applied.





Did I answer your question? Mark my post as a solution!

Proud to be a Super User!







Power BI Blog

Anonymous
Not applicable

I think you have confirmed what I thought, that users accessing a Power BI report/app connected live to an Azure tabular model where no gateway is involved (everything is happening in Azure), have to be granted access to the tabular model as well as the app.

Helpful resources

Announcements
Microsoft Fabric Learn Together

Microsoft Fabric Learn Together

Covering the world! 9:00-10:30 AM Sydney, 4:00-5:30 PM CET (Paris/Berlin), 7:00-8:30 PM Mexico City

PBI_APRIL_CAROUSEL1

Power BI Monthly Update - April 2024

Check out the April 2024 Power BI update to learn about new features.

April Fabric Community Update

Fabric Community Update - April 2024

Find out what's new and trending in the Fabric Community.

Top Solution Authors
Top Kudoed Authors