Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Earn the coveted Fabric Analytics Engineer certification. 100% off your exam for a limited time only!

Reply
robinclement
Regular Visitor

Need help with App Workspace and Row Level Security privileges

Hi,

I want to have a scenario that is as follows:

We manage a dataset and a report containing data for multiple customers.
The report is stored in an app workspace and the customer should be able to only view his data. In order to achieve this, Row Level Security has been set up. So far, so good.

However, the customer should also be able to tweak the report if their reporting needs change. They would be able to do this if we add the customer to the app workspace as a member and give them the privilege to edit the reports. And this is where the tricky part comes. Once the customer has been added to the app workspace with those privileges, the customer is also able to access the Row Level Security settings and he would be able to give himself the rights to see all the data.


So, my question is: Is there a way to have Row Level Security enabled, so customers would only be able to see their own data, but also give them the rights to just edit the reports, without being able to edit the Row Level Security settings themselves?

Kind regards,

Robin

1 ACCEPTED SOLUTION

So concluding, it is currently not possible to have a dataset filtered in any way (either by setting a filter or by applying RLS) while giving a member editing permissions. This since the member is either able to reset the filter or by adjusting the RLS applied to him.

 

We miss this feature, shouldn't be that hard! A pity!

View solution in original post

3 REPLIES 3
aferreiro
Regular Visitor

Hi,

 

I had the same issue, and it was because the group security was configured so all members can edit security, manage reports and so on.

 

I found the solution at the end of this post:

https://powerbi.microsoft.com/en-us/documentation/powerbi-admin-rls/

 

"If you have configured the app workspace so that members have edit permissions, the RLS roles will not be applied to them. Users will be able to see all of the data."

 

Hope it helps

So concluding, it is currently not possible to have a dataset filtered in any way (either by setting a filter or by applying RLS) while giving a member editing permissions. This since the member is either able to reset the filter or by adjusting the RLS applied to him.

 

We miss this feature, shouldn't be that hard! A pity!

I was fearing for this answer, but I guess I'll have to accept it for now.

 

Really hoping they will change this someday. I find it strange to have a "God mode yes/no" setting in the workspace settings. In my eyes it shouldn't be that hard to create more granularity in those settings either!

Helpful resources

Announcements
April AMA free

Microsoft Fabric AMA Livestream

Join us Tuesday, April 09, 9:00 – 10:00 AM PST for a live, expert-led Q&A session on all things Microsoft Fabric!

March Fabric Community Update

Fabric Community Update - March 2024

Find out what's new and trending in the Fabric Community.

Top Solution Authors
Top Kudoed Authors