tlachev2
11 years agoNew Member
Status:
Under Review
SSAS Tabular Connector without Active Directory Sync?
There should be a way to use the SSAS Tabular Connector without AD Sync, e.g. by using CustomData on the connection string.
37 Comments
- nishalitNew MemberThanks for the suggestion, Teo! Is anyone else in a position where they can't use the SSAS Connector because they aren't using AD Synchronization? If so, please add your vote here!
- pinak_kakadiyaNew MemberEven I am also getting error while using connector without ADsync. It would be great if we can connect on premise SSAS tabular models without AD sync on azure.
- fbcideas_migusrNew MemberYes, being able to specify different domain in the connection is key for us.
- fbcideas_migusrNew MemberTrying with SQL Server 2014 Dev on same machine. Getting 400 error after entering friendly name.
- fbcideas_migusrNew MemberGreat suggestion Teo. I agree this would simplify deployment of the Power BI AS Connector in some scenarios. I think this problem is common for demo environments, but not as common for real production environments. That being said, if it's complicated to setup a demo, the deployment may never get to production. I described a workaround here, but it's still quite a bit more involved than it would be with CustomData. http://www.artisconsulting.com/blogs/greggalloway/Lists/Posts/Post.aspx?ID=27
- Young_JohnNew MemberSee my prior comments. I wonder if Teo would be willing to alter this idea to not just be about working without Active Directory Sync, but to also address the scenario where your AAD UPN does not match your on-prem UPN thereby causing the connector to be unsuccessful when connecting to the on-prem SSAS server instance.
- Young_JohnNew MemberI am running in to a problem due to the fact that even though our company has turned on DirSync and we have associated our Office 365 tenant with our AAD account, our AAD account and our on-prem account are still two *different* accounts. Our AAD account uses a suffix that is publicly routable, but our on-prem account uses a non-routable account. Therefore our UPNs are different and the EffectiveUserName that is passed to SSAS on-prem appears as an invalid UPN/account to our on-prem server. Granted, I would like our organization to clean up the mismatch and make our on-prem UPN match the AAD UPN, but that is a massive undertaking. So I'm interested in alternative options that help us easily work around this. Maybe an alternative AAD attribute that would contain our on-prem UPN string could be something we configure in the connector setup. I'm not looking for the ability to put a single, trusted account into the string. I really want individual users to be authenticated. I just need the proper on-prem UPN to be passed through.
- fbcideas_migusrNew MemberAbsolutely - and the need is greater than that. A proxy account may be required by designed, so passing user credentials may not help. Consider the scenario where I have an SSAS model that has no per-user security requirements - it's homogeneous to the entire organization. Managing users on that model could be cumbersome, and an unnecessary step. Or I may be an ISV running a reference model...... I may want to make it available to everyone - much like the way the demo dashboard is done in the current Power BI Preview.
- alim2New MemberCan't wait for this feature. Tableau currently offers connection to SSAS using hard coded Windows user name and password. It is sad to see that two of Microsoft products (Power BI or Power Pivot and SSAS) can't talk to each other!
- BillSchmidtNew MemberI do not know for sure whether my problem is the same but I suspect so. I have done the following: 1. Set up a demo SSAS Tabular database in an Azure VM that is standalone (not connected with my company domain). 2. Made the demo SSAS Tabular database available externally by making its port static, opening up that port for inbound traffic, and creating an Azure endpoint. 3. Tested the connectivity from SQL Management Studio (which has to be opened using a "run as" command, e.g. runas /netonly /user:<
>\< > “C:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio\Ssms.exe”) 4. In Power BI, tried to create a SSAS Tabular data connection. On (4), I ran into a blank screen. There appears to be no way to do, from Power BI, what I was able to do from SQL Management Studio - that is, to connect to this Azure-VM-hosted SSAS database. We had thought the combination of an Azure VM (not domain connected) and some Power BI dashboards would be a perfect, easy and safe way to demonstrate our product to external users, without exposing our home network to hacking, etc. But this looks like it is going nowhere at the moment. Can you comment on whether my problem is the same as what others here are seeing? And can anything be done about it? Thanks.
Recent ideas
Allow NotebookUtils getSecret() to authenticate with Workspace Identity
Current behavior In Microsoft Fabric, notebookutils.credentials.getSecret() authenticates against Azure Key Vault using the identity of the user who executes the notebook. This behavior appli...tmihara3 hours agoNew MemberNew4Views0likes0CommentsSupport Synonyms in Fabric Warehouse
Microsoft SQL Server has a very powerful feature by the way of "synonyms." It allows users and DBAs to do all sorts of powerful magic such as rewiring objects under the hood (e.g. run the code agains...matthias-bi7 hours agoRegular VisitorNew1.3KViews18likes2CommentsExpose Refresh Warnings and Informational Messages via Notifications and API
When a Power BI semantic model refresh completes successfully, the status shows Completed, even when the refresh details contain warnings or informational messages that require attention. Please pro...Jashwanth_K9 hours agoMicrosoft EmployeeNew23Views6likes0CommentsInvoke Pipeline Task - Workspace Identity Authentication
Currently, the Fabric Data Factory Invoke Pipeline task uses the user's credentials who saved the pipeline to then authenticate to the Azure Data Factory to execute the ADF pipeline. When that user'...dzebrowitz13 hours agoAdvocate IPlanned1.8KViews61likes5CommentsFabric Pipeline should run as workspace identity
Currently, Microsoft Fabric pipelines run under the identity of the last user who modified them, which can cause disruptions when tenant administrators make changes to security policies, such as enab...pellitteris13 hours agoAdvocate IINew1.4KViews27likes3Comments