Read-only API for Power BI usage and audit data without requiring tenant admin roles
π¦ Request Summary
Provide a supported, least-privilege API or role to access Power BI usage and audit data (user, report, workspace, timestamp, etc...) without requiring tenant-wide admin roles, enabling secure and automated governance, analytics, and compliance reporting.
π¦ Background & Business Need
Need to analyze Power BI usage and adoption for governance, cost optimization, security auditing, and compliance purposes.
Typical requirements include understanding:
- Who accessed which Power BI report
- When the access occurred
- Which workspace and dataset were involved
- What type of connection was used (Import, DirectQuery, Live, AS)
Currently, the Power BI Activity Events API is the only supported source that provides this level of detail. However, accessing this API requires assigning Power BI Service Administrator or Fabric Administrator roles to the calling identity (user or service principal).
In many enterprises, especially those with:
- Strict security controls
- Segregation-of-duties policies
- Internal and external audit requirements
- Regulated environments (finance, healthcare, government)
granting tenant-wide admin roles to automation identities or analytics teams is not acceptable, even for read-only reporting purposes.
As a result, organizations face a difficult trade-off between:
- Achieving visibility into Power BI usage, or
- Maintaining least-privilege and compliance standards
This challenge is common across organizations of all sizes and industries.
π¦ Expected Benefits
Introducing a read-only, least-privilege access model for Power BI usage data would deliver significant benefits:
- β Enables secure, automated usage and adoption analytics
- β Reduces need for broad tenant admin role assignments
- β Aligns with enterprise security and compliance best practices
- β Improves governance, capacity planning, and cost management
- β Supports audit and monitoring requirements without elevated risk
- β Benefits all customers, from small tenants to large regulated enterprises
Such an enhancement would allow customers to fully leverage Power BI and Fabric telemetry while maintaining strong security boundaries, and would encourage broader adoption of Microsoft-recommended governance practices.
Recent ideas
Need an option to save PBIP files without data (the .abf files)
We need an option to save the PBIP without saving the ABF file, just like the PBIT file is saved without data. As it is now, we will violate company security policies that don't allow storing data ...heve1 hour agoNew MemberNew608Views39likes6CommentsiOS Shortcuts Support for Direct Access to Power BI Reports
We are looking to deploy several Power BI reports to support emergency response activities. The intended users are primarily non-technical staff who do not use Power BI currently, but who would benef...Default81293 hours agoFrequent VisitorNew3Views0likes0CommentsSupport Fabric Workspace Identity for custom APIs
Currently, Fabric Workspace Identity cannot be used to authenticate against custom APIs protected by Microsoft Entra ID. Azure Managed Identities support requesting an access token for a specific AP...frithjof_v7 hours agoCommunity ChampionNew62Views5likes0CommentsAllow the target pipeline reference in Invoke Pipeline / ExecutePipeline to be set dynamically
Problem Today, the Invoke Pipeline activity (and legacy ExecutePipeline) requires picking the target pipeline statically at design time β a fixed Workspace/Pipeline selection in the UI, which serial...JONATHANHAUN21 hours agoNew MemberNew9Views0likes0CommentsReset Bookmark Navigator Selection to the Default Published View on Browser Refresh
In Power BI Service, when a user selects a bookmark through a Bookmark Navigator, the bookmark identifier is appended to the report URL. If the user refreshes the browser page, the report reloads in ...vivek1234422 hours agoMicrosoft EmployeeNew6Views0likes0Comments