Quick answer: In Power BI Service, open the semantic model’s Row-level security settings, choose Test as role, and then use Now viewing as to test a role or supported user context. The report opens with the selected RLS filters applied. For dynamic RLS, however, Test as role uses your own identity, so it does not fully simulate another user’s authentication context.
Power BI access and RLS
Power BI controls access through workspace and item permissions, while row-level security (RLS) filters which rows users can see in a semantic model. RLS is primarily enforced for users with Viewer-level access; users with workspace Admin, Member, or Contributor roles aren’t restricted by RLS in the same way.
Authentication (Limit access to content)
Authentication and permissions determine whether a user can access the report or semantic model. RLS then limits the data returned to users who are subject to the model’s RLS roles.
Authorization (Limit access to data using RLS in Power BI)
Limit access to data with row-level security (RLS). So, roles can be created in Power BI dataset with specific data access, and users or groups can be added to these roles.
How to implement RLS in Power BI?
Read this quick post to learn how to implement row-level security in PowerBI.
Steps to Test RLS in Power BI Service
1. Launch Power BI Service and open the workspace containing the semantic model.
2. Open the semantic model’s Security / Row-level security settings.
3. Select the ellipsis (…) next to the role you want to test and select Test as role.

4. When the report opens, use Now viewing as to select the role or supported user context you want to test. Power BI displays the active role in the page header.

Available on Microsoft Store
SSRS Reports Migration Wizard
A simple Windows tool for migrating SSRS reports, data sources, and related configurations between report servers.
5. Verify that the report visuals show only the rows permitted by the selected RLS configuration. You can test another role or supported user context from the same view.

This opens the associated report with the selected RLS context applied.
Important for dynamic RLS: Test as role does not fully impersonate another user’s identity. Microsoft notes that dynamic RLS expressions using USERPRINCIPALNAME() or USERNAME() are evaluated using your own identity in this testing experience. To validate what an actual external or guest user sees, sign in as that user and test the report directly.

6. Repeat the test for other roles or reports connected to the same semantic model where supported.
Limitation: Test as role doesn’t support DirectQuery semantic models with single sign-on (SSO), and it doesn’t validate every report feature. For those scenarios, use the appropriate real-user or model-level testing approach.
Pro tips:
1. If you want to test the Power BI report as user user1 for a particular role, user1 must be part of that role under the Row level security page.
2. You can also test Power BI access using Power BI desktop View as an option under the Modeling tab. It is recommended to TEST row level security in Power BI model using Power BI desktop first.
3. You can export all measures and calculated column expressions from Power BI desktop using a PowerShell script. Learn more about it here.
4. Refer to this article if you want to format seconds as h:mm:ss format in Power BI card visual.
We have seen how to test RLS in Power BI using the Power BI test as role feature.
See more
Kunal Rathi
With over 15 years of experience in data engineering and analytics, I've assisted countless clients in gaining valuable insights from their data. As a dedicated supporter of Data, Cloud and DevOps, I'm excited to connect with individuals who share my passion for this field. If my work resonates with you, we can talk and collaborate.






