A regional manager can see every region even though you configured row-level security. What would you check?
Instruction: Use a department, customer or region that fits your actual work. Be clear whether you designed RLS, tested it, or only supported an existing model.
Updated
Example Answer
I'd check the person's effective permissions before changing the DAX rule. Power BI row-level security applies to workspace Viewers, including Viewers with Build permission. It doesn't restrict Admins, Members or Contributors, because those roles have edit rights. If the manager is a report consumer, I'd correct inappropriate edit access through the approved access process.
I'd then check their RLS role memberships, including groups, and the relationships that carry the security filter into the sales table. Multiple RLS roles can combine their permitted rows, so an extra role may broaden access instead of restricting it.
Finally, I'd test the expected region and a region they must not see using an authorized Viewer account. I wouldn't use a report filter or a hidden page as a security fix.
Make it your own
Use a department, customer or region that fits your actual work. Be clear whether you designed RLS, tested it, or only supported an existing model.
Why this works
Addresses the common permission cause before debugging model logic and includes a negative access check instead of treating visible filtering as proof of security.
Interviewer follow-up
If a user belongs to two RLS roles, does the more restrictive role win?
No. RLS role filters are additive: the user can see the union of the permitted rows. I'd avoid a design that depends on one role denying access granted by another, and test direct and group-based role combinations explicitly.
References
Related Questions
-
easy
-
easy
-
medium
-
medium
-
medium
-
medium