Note

Access to this page requires authorization. You can try signing in or .

Access to this page requires authorization. You can try .

Manage semantic model access permissions (preview)

Manage semantic model access permissions in Power BI to keep your sensitive data secure. The semantic model manage permissions page enables you to monitor and control who has access to your semantic model through two tabs:

  • Direct access: Monitor, add, modify, or delete access permissions for specific people or groups (distribution groups or security groups).
  • Shared report links: Review and remove links that were generated for sharing reports, which may also grant access to your semantic model.

This article explains how to use the manage permissions page to control access to your semantic model.

Note

To access a semantic model's manage permissions page, you must have an Admin or Member role in the workspace where the semantic model is located.

Open the semantic model manage permissions page

To open the semantic model manage permissions page:

These actions open the semantic models manage permissions page. The manage permissions page has two tabs to help you manage semantic model access.

Manage direct access

The direct access tab lists users who have been granted access. For each user, you can see their email address and the permissions they have.

Managing permissions granted through an app

Permissions on the semantic model granted through an app are indicated by the word "App" followed by the permissions enclosed in parentheses, as shown in the following image:

👁 Screenshot of app permissions on semantic models Direct access tab.

You can't modify permissions granted through an app directly from the Direct access tab. You must first remove them from the app configuration. To remove such permissions:

  1. Edit the app and unselect the relevant permissions on the Permissions tab of the app's configuration settings.

  2. Republish the app.

  3. Go to the Direct access tab of the semantic model's manage semantic model permissions page as described in Manage direct access. The user still has the permissions granted via the app before update, but now they're not tied to the app (note that the parentheses are gone). Now you can remove whatever permissions you desire.

    👁 Screenshot of editing former app permissions.

Manage links generated for report sharing

The shared report links tab lists links that have been created to shared reports that are based on your semantic model. Such links might also grant access to the report's underlying semantic model, and so these links are listed here. You can see what permissions the link carries and who created the link. You can also delete the link from the system if you so desire.

Warning

Deleting a link removes it from the system. Users who use the link to access a report may lose access to that report.

👁 Screenshot of shared report links tab on the semantic model manage permissions page.

Related content


Feedback

Was this page helpful?

Additional resources