How to Set Up Row-Level Security in Power BI Datasets
Question details
The user wants to understand how to design and implement row-level security (RLS) for a Power BI report and dataset.

- Product
- Power BI
- Device & OS
- not provided
- Scenario
- A company needs to restrict data access within a Power BI dataset so that different users only see the data they are authorized to view.
- Observed behavior
- The goal is to successfully configure roles, define DAX filters, publish the model, and properly assign security groups or users to those roles.
Ensure you have the latest version of Power BI Desktop installed and that you have administrative or member permissions in the Power BI workspace where you plan to publish the dataset.
Configure RLS Roles and Assign Users
Define security roles and DAX filters locally in Power BI Desktop, then manage user assignments in the Power BI service.
Row-level security (RLS) allows you to restrict data access for given users. Filters restrict data access at the row level, and you can define filters within roles. Setting this up requires a two-part process: defining the rules in Power BI Desktop and mapping accounts in the Power BI service.
Open your report in Power BI Desktop. Navigate to the 'Modeling' tab on the top ribbon and select 'Manage roles'.
In the Manage roles window, click 'Create' to add a new role. Select the table you want to restrict, and input a DAX expression to filter the data (e.g., [Region] = "East"). Click 'Save' when finished.
Save your Power BI Desktop file. Go to the 'Home' tab and click 'Publish' to upload the report and dataset to your desired workspace in the Power BI service.
Log into the Power BI service online. Go to your workspace, find the published dataset, click the 'More options' (three dots) menu, and select 'Security'. Add the email addresses or security groups of the users to the appropriate roles and save.

Analyze and Protect Data Seamlessly with WPS Office
While Power BI is excellent for enterprise-level business intelligence and complex row-level security, everyday data analysis and secure reporting can be easily managed with WPS Spreadsheet. It offers a lightweight, highly compatible alternative to Microsoft Office for your daily spreadsheet needs.
- 1. Download and Install: Get WPS Office for free from the official website and install it on your device.
- 2. Open Your Data File: Launch WPS Spreadsheet and easily open your existing Excel or CSV data reports.
- 3. Secure Your Data: Navigate to the 'Review' tab to set passwords, protect sheets, or lock specific cells from unauthorized edits.

Frequently Asked Questions
Can I test my row-level security roles before publishing to the Power BI service?
Yes. In Power BI Desktop, you can go to the 'Modeling' tab and select 'View as'. This allows you to select a specific role you created and see the report exactly as a user assigned to that role would see it.
Does row-level security apply to workspace administrators?
No. By default, row-level security does not restrict users who have Admin, Member, or Contributor permissions in the workspace where the dataset is stored. RLS primarily restricts users who are assigned the 'Viewer' role.
How do I implement dynamic row-level security?
Dynamic RLS can be set up using DAX functions like USERNAME() or USERPRINCIPALNAME() inside your role filters. This automatically filters the dataset based on the login credentials of the user accessing the report, eliminating the need to create dozens of static regional roles.
Why can't I see the 'Security' option on my dataset in the Power BI service?
The 'Security' option will only appear if you are the owner of the dataset or have Admin/Member privileges in that workspace. Additionally, ensure the dataset was published from Power BI Desktop with roles properly defined.




