Forum Discussion
Gateway keeps using old SQL Server data source (StrongDM suffix) even after parameter change
- 8 months ago
Hi Bhargava_B
Your summary is accurate. This issue is not related to parameters, dataset identity, or StrongDM. The underlying problem is due to TLS certificate trust enforcement by the Power BI On‑Premises Data Gateway.
Unlike Power BI Desktop, SSMS, or paginated reports, the gateway does not respect TrustServerCertificate=True or encryption overrides in M queries. When refreshing, the Power BI Service expects the SQL Server certificate chain to be fully trusted by the Windows OS on the gateway VM. If the root or intermediate CA is missing or not trusted, the gateway fails the TLS handshake and shows a “certificate chain was issued by an authority that is not trusted” error.
There is no supported workaround on the Power BI side. To resolve this, install the proper root and intermediate certificates on the gateway VM, or use a SQL Server certificate from a trusted CA. Once the certificate chain is trusted, the gateway and dataset refreshes will work as expected.
If you have any more questions, please let us know and we’ll be happy to help.
Regards,
Microsoft Fabric Community Support Team
Hi Bhargava_B
Your summary is accurate. This issue is not related to parameters, dataset identity, or StrongDM. The underlying problem is due to TLS certificate trust enforcement by the Power BI On‑Premises Data Gateway.
Unlike Power BI Desktop, SSMS, or paginated reports, the gateway does not respect TrustServerCertificate=True or encryption overrides in M queries. When refreshing, the Power BI Service expects the SQL Server certificate chain to be fully trusted by the Windows OS on the gateway VM. If the root or intermediate CA is missing or not trusted, the gateway fails the TLS handshake and shows a “certificate chain was issued by an authority that is not trusted” error.
There is no supported workaround on the Power BI side. To resolve this, install the proper root and intermediate certificates on the gateway VM, or use a SQL Server certificate from a trusted CA. Once the certificate chain is trusted, the gateway and dataset refreshes will work as expected.
If you have any more questions, please let us know and we’ll be happy to help.
Regards,
Microsoft Fabric Community Support Team
Hi v-karpurapud ,
Thank you for the information, I have set up a call with My Infra(admin) team to discuss this, I will post the outcome post discussions.
Thank you
Bhargava
- v-karpurapud8 months ago
Community Support
Hi Bhargava_B
Thank You for the update. Looking forward to your response.