logo
search
Data Protection Issues

How to Set Up Row-Level Security in Power BI Datasets

Tauseeq MagsiTauseeq Magsi Sep 27, 2026 869 views

Question details

The user wants to understand how to design and implement row-level security (RLS) for a Power BI report and dataset.

How to Set Up Row-Level Security for a Power BI Dataset
Product
Power BI
Device & OS
not provided
Scenario
A company needs to restrict data access within a Power BI dataset so that different users only see the data they are authorized to view.
Observed behavior
The goal is to successfully configure roles, define DAX filters, publish the model, and properly assign security groups or users to those roles.
Before you start

Ensure you have the latest version of Power BI Desktop installed and that you have administrative or member permissions in the Power BI workspace where you plan to publish the dataset.

Solution 1Recommended

Configure RLS Roles and Assign Users

Define security roles and DAX filters locally in Power BI Desktop, then manage user assignments in the Power BI service.

Row-level security (RLS) allows you to restrict data access for given users. Filters restrict data access at the row level, and you can define filters within roles. Setting this up requires a two-part process: defining the rules in Power BI Desktop and mapping accounts in the Power BI service.

1
Create roles in Power BI Desktop

Open your report in Power BI Desktop. Navigate to the 'Modeling' tab on the top ribbon and select 'Manage roles'.

2
Define DAX filters

In the Manage roles window, click 'Create' to add a new role. Select the table you want to restrict, and input a DAX expression to filter the data (e.g., [Region] = "East"). Click 'Save' when finished.

3
Publish the dataset

Save your Power BI Desktop file. Go to the 'Home' tab and click 'Publish' to upload the report and dataset to your desired workspace in the Power BI service.

4
Assign users in Power BI Service

Log into the Power BI service online. Go to your workspace, find the published dataset, click the 'More options' (three dots) menu, and select 'Security'. Add the email addresses or security groups of the users to the appropriate roles and save.

Configure RLS Roles and Assign Users
Additional Support: If you encounter complex DAX filtering issues or dynamic RLS challenges, you can consult Microsoft's official RLS guidance or ask in the Microsoft Fabric Power BI Community.
Free Microsoft Office alternative

Analyze and Protect Data Seamlessly with WPS Office

While Power BI is excellent for enterprise-level business intelligence and complex row-level security, everyday data analysis and secure reporting can be easily managed with WPS Spreadsheet. It offers a lightweight, highly compatible alternative to Microsoft Office for your daily spreadsheet needs.

  1. 1. Download and Install: Get WPS Office for free from the official website and install it on your device.
  2. 2. Open Your Data File: Launch WPS Spreadsheet and easily open your existing Excel or CSV data reports.
  3. 3. Secure Your Data: Navigate to the 'Review' tab to set passwords, protect sheets, or lock specific cells from unauthorized edits.
Fully compatible with Microsoft Excel (.xlsx, .xls) and CSV data formats.Built-in document encryption and password protection features to secure sensitive data.Lightweight software that loads quickly for efficient daily data processing and charting.Familiar user interface ensuring a seamless migration from Microsoft Office.
microsoft office alternative - wps office

Frequently Asked Questions

Can I test my row-level security roles before publishing to the Power BI service?

Yes. In Power BI Desktop, you can go to the 'Modeling' tab and select 'View as'. This allows you to select a specific role you created and see the report exactly as a user assigned to that role would see it.

Does row-level security apply to workspace administrators?

No. By default, row-level security does not restrict users who have Admin, Member, or Contributor permissions in the workspace where the dataset is stored. RLS primarily restricts users who are assigned the 'Viewer' role.

How do I implement dynamic row-level security?

Dynamic RLS can be set up using DAX functions like USERNAME() or USERPRINCIPALNAME() inside your role filters. This automatically filters the dataset based on the login credentials of the user accessing the report, eliminating the need to create dozens of static regional roles.

Why can't I see the 'Security' option on my dataset in the Power BI service?

The 'Security' option will only appear if you are the owner of the dataset or have Admin/Member privileges in that workspace. Additionally, ensure the dataset was published from Power BI Desktop with roles properly defined.