Row-level security: powerful, with one sharp edge

Row-level security restricts which rows a user can see, using DAX filter expressions defined in roles on the semantic model. A dynamic pattern that filters on the signed-in user's identity against a security table scales far better than creating a role per region or per customer.

The sharp edge: RLS applies to users who consume content with read access, but it does not restrict people who have edit-level access to the workspace, such as Admin, Member, and Contributor roles. If you put analysts in as members and assume RLS protects the data from them, it does not. Keep sensitive models in workspaces where the people who build content are people allowed to see all of the data.

Treat RLS as a consumption control, not an authoring control. Audience separation belongs in workspace roles and in how content is distributed.

Workspaces, apps, and certified content

Separate where content is built from where it is consumed. Builders work in workspaces; consumers get content through apps or through read-only access, so they never see work in progress. Use endorsement - promoting and certifying semantic models - so people can tell the governed, supported model from someone's experimental copy.

Sensitivity labels from Microsoft Purview can classify content and carry protection through exports, and object-level security can hide specific tables or columns when a whole row filter is not the right tool.

Separate authors from consumers

Distribute through apps or viewer access so unfinished work never reaches the business.

Certify the shared models

One endorsed semantic model beats a dozen near-identical copies with different numbers.

Releases through deployment pipelines

Deployment pipelines give you development, test, and production stages for a workspace's content, with the ability to compare stages and to set rules that swap data sources or parameters between them. That replaces the risky habit of editing the production report directly and hoping.

For teams that want real engineering discipline, pair this with source control: the Power BI Project format and Git integration let you version semantic models and reports, review changes, and roll back. Governance that includes a release process is what lets a BI estate grow without eroding trust in the numbers.

Growing a Power BI estate and worried about security or release hygiene? Talk to us about a governance review.

Key takeaways

  • Row-level security filters rows for consumers using DAX roles, but it does not restrict users with edit-level workspace roles such as Admin, Member, and Contributor.
  • Separate authoring from consumption: build in workspaces, distribute through apps or read-only access.
  • Endorse and certify shared semantic models, and use sensitivity labels and object-level security where needed.
  • Use deployment pipelines and source control so production is never edited directly.