AshishChougala's avatar
AshishChougala
Icon for Microsoft Employee rankMicrosoft Employee
7 hours ago
Status:
New

Enable per-user security for shared gateway connections using service accounts

When a shared gateway connection uses a highly privileged service account, all source queries run with that account’s permissions. Users cannot see the stored credentials, but report developers who can use the connection may access any data available to the service account.

Currently, gateway permissions control who can use the connection, but cannot restrict source access by user, Microsoft Entra group, workspace, or semantic model.

Please add granular security controls that allow administrators to:

  • Restrict source objects by user, group, workspace, or artifact.
  • Approve which artifacts can use a shared connection.
  • Separate refresh permission from permission to create new connections or bindings.
  • Enforce the individual user’s source permissions for Import-mode development and refresh.

This would enable secure self-service reporting with centrally managed credentials, without requiring DirectQuery or multiple gateway connections.

No CommentsBe the first to comment

Recent ideas