Dynamic Row Level Security in Power BI — Full Tutorial
RADACAD
0:00 / 0:00
Dynamic Row Level Security in Power BI — Full Tutorial
139 496 просмотров · 3 года назад
RADACAD
89,9 тыс. подписчиков
139 496 просмотров · 3 года назад
Static Row-Level Security means creating a separate role for every single user. Ten thousand employees means ten thousand roles. That does not scale.
Dynamic Row-Level Security solves this problem completely — using a single DAX role and a system function to automatically detect who is logged in.
In this full tutorial, I walk through exactly how to set up Dynamic RLS in Power BI, step by step, with a real working example.
🎯 What you will learn in this video:
✅ The difference between Static RLS and Dynamic RLS — and why Dynamic RLS is the right approach for any organisation of meaningful size
✅ How to structure your data model correctly — the sales rep table, the email column, and the relationship that makes RLS work
✅ How to use USERPRINCIPALNAME() and USERNAME() to detect the logged-in user automatically — no hardcoding
✅ How to create a single dynamic role in Power BI's Manage Roles using DAX
✅ How to test your RLS setup using "View As" in Power BI Desktop
✅ How to publish your report and assign users or an Office 365 Security Group to the role
✅ A live side-by-side comparison — the report owner's full view vs. a restricted user's filtered view
✅ Why using an Office 365 group instead of individual users saves you from ongoing manual maintenance
✅ What happens when RLS gets more advanced — many-to-many relationships, hierarchies, and combinations of both
📌 Timestamps:
0:00 Introduction — what is Dynamic Row-Level Security
0:26 The example data model — sales transactions and sales rep tables
1:13 Static vs Dynamic RLS explained
2:01 Setting up the data model and relationships
2:48 Building a simple report to demonstrate the problem
3:34 Creating the USERPRINCIPALNAME() measure
5:48 Creating the dynamic role in Manage Roles
7:10 Testing with View As in Power BI Desktop
7:52 Publishing the report to the Power BI Service
9:22 Adding users to the RLS role in the Power BI Service
9:37 Sharing the report with restricted users
9:43 Live demo — comparing the report owner view vs. a restricted user view
10:51 Why Dynamic RLS avoids manual maintenance when staff change
11:55 When RLS gets complex — many-to-many relationships and hierarchies
12:22 Closing thoughts
📖 Related resources on RADACAD:
🔗 RADACAD Blog — search "Row Level Security": https://radacad.com/?s=row+level+secu...
🔗 RADACAD Blog: https://radacad.com/blog/
🔗 Power BI Training: https://radacad.com/power-bi-training/
🔗 Microsoft Fabric Training: https://radacad.com/microsoft-fabric-...
🌐 RADACAD: https://radacad.com
#PowerBI #RowLevelSecurity #RLS #DynamicRLS #PowerBITutorial #DAX #USERPRINCIPALNAME #PowerBIDeveloper #DataSecurity #PowerBIDesktop #PowerBITips #BusinessIntelligence #DataGovernance #PowerBITraining #SemanticModel