Row-level security: filtering the data each person can see down to permitted rows. Power BI models apply it through DAX rules on roles, which bind just Viewers and anyone holding Read or Build; Fabric Warehouse instead uses a T-SQL policy that calls a predicate function.
Also called row-level security.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains RLS in context, with comparison tables and the common traps.
Terms in this definition
- Power BI
Microsoft's analytics and reporting service. It reaches data held on-premises through the on-premises data gateway.
- APPLY
Evaluates a table-valued expression for every row on its left, inside
FROM. Think ofOUTER APPLYas a left outer join andCROSS APPLYas an inner join. - DAX
Short for Data Analysis Expressions, the formula language you write measures, calculated columns and row-level security rules in, within tabular semantic models in Power BI, Excel Power Pivot or Analysis Services.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Fabric Warehouse
A relational data warehouse in the classic style, offered as a Fabric item, that supports T-SQL fully, transactions included.
- T-SQL
The dialect of SQL that Microsoft uses for Azure SQL and SQL Server. Azure Monitor logs are queried with KQL instead.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- Predicate function
The logic behind row-level security. Written as an inline TVF, it yields a row only when the user should see or change the data; tables are bound to it through a security policy, which applies it either to filter rows out or to block writes.
Related terms
- Analyze feature
Right-click a point on a line or bar chart to get machine-learning explanations of why it rose, fell or is distributed differently, with the contributing categories ranked against the previous point. Models using DirectQuery or row-level security can't use it.
- Bi-directional relationship
Here filters travel from either table to the other. That helps with many-to-many bridges, but because it can hurt performance and produce ambiguous paths, Microsoft Learn suggests turning it on only when needed or using CROSSFILTER in a measure. Row-level security still filters one way unless the setting to apply security filters both ways is chosen.
- Compute permissions
Access rules that live inside one Fabric engine and govern only queries run through it. They include T-SQL GRANT or DENY, masking and row-level security on a warehouse or SQL analytics endpoint, and DAX-based security in a semantic model.
- Cross-filter direction
Controls whether filters flow one way or both ways along a relationship. Two-way filtering can slow queries and make filter paths ambiguous, and row-level security ignores it unless Apply security filter in both directions is ticked.
- Direct Lake on SQL
A Direct Lake variant that relies on the SQL analytics endpoint of a single item to discover tables and check permissions. Queries switch to DirectQuery when they hit SQL views, row-level security defined on the endpoint or exceeded guardrails, subject to the DirectLakeBehavior setting.
- Dynamic M query parameters
Connects a column in the model with an M parameter, so that when a viewer picks something in a slicer or filter, that choice is written into the DirectQuery source query. It can't be used alongside row-level security or aggregations.
- EffectiveUserName
Set in a connection string, it lets you query through the XMLA endpoint as somebody else, which is useful when testing RLS. That person must hold both Build and Read on the semantic model.
- Embed in SharePoint Online
Shows a report, or one visual from it, inside a modern SharePoint Online page by way of the Power BI web part; the link comes from File, Embed report in the service. Access rules and RLS continue to apply, and anyone viewing it needs a Pro or PPU licence, except when that content is hosted on F64 (or larger) or Premium.