<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Power BI Embedded + Data Gateway + SQL server + Import method + RLS in Developer</title>
    <link>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-Data-Gateway-SQL-server-Import-method-RLS/m-p/942565#M22408</link>
    <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was hoping someone could clarify a situation I am in, the goals/overview are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Share reports with our external customers (NOT a B2B scenario)&lt;/P&gt;&lt;P&gt;- Use Power BI Embedded (yes we have developer resources)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Page 162 of the Power BI Enterprise Deployment guide mentions it may be better to create roles for RLS on the data source instead of within the PBIX file - which I definitely agree with. The issue I seem to have is it does not seem possible to pass a role (or any information really) back to the SQL server, it only knows about the SQL account configured on the Data Gateway Data Source.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SQL server &amp;lt;-&amp;gt; Data Gateway + Data Source (access configured using local SQL account)&lt;/P&gt;&lt;P&gt;PBIX file with Roles published - matched to Data Gateway + Data Source&lt;/P&gt;&lt;P&gt;Web App + Service Principal + Role &amp;lt;-&amp;gt; External customer login (Auth is performed, role is passed, appropriate data is displayed)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only account the SQL server ever knows about is the one configured on the Data Gateway Data Source. Can we configure RLS on the SQL server somehow or do we need to look at using a different method (like SSAS as the data source?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope that makes sense, many thanks for any insight.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 10:43:56 GMT</pubDate>
    <dc:creator>Dan_0101</dc:creator>
    <dc:date>2020-02-21T10:43:56Z</dc:date>
    <item>
      <title>Power BI Embedded + Data Gateway + SQL server + Import method + RLS</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-Data-Gateway-SQL-server-Import-method-RLS/m-p/942565#M22408</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was hoping someone could clarify a situation I am in, the goals/overview are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Share reports with our external customers (NOT a B2B scenario)&lt;/P&gt;&lt;P&gt;- Use Power BI Embedded (yes we have developer resources)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Page 162 of the Power BI Enterprise Deployment guide mentions it may be better to create roles for RLS on the data source instead of within the PBIX file - which I definitely agree with. The issue I seem to have is it does not seem possible to pass a role (or any information really) back to the SQL server, it only knows about the SQL account configured on the Data Gateway Data Source.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SQL server &amp;lt;-&amp;gt; Data Gateway + Data Source (access configured using local SQL account)&lt;/P&gt;&lt;P&gt;PBIX file with Roles published - matched to Data Gateway + Data Source&lt;/P&gt;&lt;P&gt;Web App + Service Principal + Role &amp;lt;-&amp;gt; External customer login (Auth is performed, role is passed, appropriate data is displayed)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only account the SQL server ever knows about is the one configured on the Data Gateway Data Source. Can we configure RLS on the SQL server somehow or do we need to look at using a different method (like SSAS as the data source?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope that makes sense, many thanks for any insight.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 10:43:56 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-Data-Gateway-SQL-server-Import-method-RLS/m-p/942565#M22408</guid>
      <dc:creator>Dan_0101</dc:creator>
      <dc:date>2020-02-21T10:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: Power BI Embedded + Data Gateway + SQL server + Import method + RLS</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-Data-Gateway-SQL-server-Import-method-RLS/m-p/942608#M22413</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/184286"&gt;@Dan_0101&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please see the below links&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ideas.powerbi.com/forums/265200-power-bi-ideas/suggestions/14216322-leverage-sql-server-2016-row-level-security-for-po" target="_blank"&gt;https://ideas.powerbi.com/forums/265200-power-bi-ideas/suggestions/14216322-leverage-sql-server-2016-row-level-security-for-po&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://powerbi.microsoft.com/en-us/blog/announcing-single-sign-on-support-when-connecting-to-data-sources-from-the-power-bi-service/" target="_blank"&gt;https://powerbi.microsoft.com/en-us/blog/announcing-single-sign-on-support-when-connecting-to-data-sources-from-the-power-bi-service/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.powerbi.com/t5/Service/RLS-for-SQL-Server-2016-with-Power-BI/td-p/133868" target="_blank"&gt;https://community.powerbi.com/t5/Service/RLS-for-SQL-Server-2016-with-Power-BI/td-p/133868&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:29:40 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-Data-Gateway-SQL-server-Import-method-RLS/m-p/942608#M22413</guid>
      <dc:creator>Jayendran</dc:creator>
      <dc:date>2020-02-21T11:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Power BI Embedded + Data Gateway + SQL server + Import method + RLS</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-Data-Gateway-SQL-server-Import-method-RLS/m-p/942635#M22414</link>
      <description>&lt;P&gt;Thanks for your reply&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/100012"&gt;@Jayendran&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have read most of those and I think there are a couple of things:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) &lt;EM&gt;For each query, the Power BI service includes the&amp;nbsp;user principal name (UPN), which is the fully qualified username of the user currently signed in to the Power BI service&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We do not have accounts for our external customers on our domain - as I understand it userprincipalname() and SSO will not be useful to us?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) We are executing stored procedures to collect our data from the reporting server, thus we are using Import method, not DirectQuery&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) We have a working demo environment that works with the RLS configured within the PBIX file - we just want to shift the roles back to the SQL server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't understand how a piece of data from a non-AD/AAD&amp;nbsp;&lt;STRONG&gt;external&lt;/STRONG&gt; customer can traverse the Data Gateway and be 'viewed' by SQL Server.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:52:13 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-Data-Gateway-SQL-server-Import-method-RLS/m-p/942635#M22414</guid>
      <dc:creator>Dan_0101</dc:creator>
      <dc:date>2020-02-21T11:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: Power BI Embedded + Data Gateway + SQL server + Import method + RLS</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-Data-Gateway-SQL-server-Import-method-RLS/m-p/942642#M22415</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/184286"&gt;@Dan_0101&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ah yes now I get some more detailed requirements, as per the data you gave we can say that you couldn't able to use RLS from your data source.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SSO will not work for your requirement due to&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;SSO is not able to work with external users.&lt;/LI&gt;
&lt;LI&gt;Import mode is only suitable for a single service account sql autentication.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:08:41 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-Data-Gateway-SQL-server-Import-method-RLS/m-p/942642#M22415</guid>
      <dc:creator>Jayendran</dc:creator>
      <dc:date>2020-02-21T12:08:41Z</dc:date>
    </item>
    <item>
      <title>Re: Power BI Embedded + Data Gateway + SQL server + Import method + RLS</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-Data-Gateway-SQL-server-Import-method-RLS/m-p/942647#M22416</link>
      <description>&lt;P&gt;Thank you for clarifying&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/100012"&gt;@Jayendran&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also just re-read this article:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/lt-lt/power-bi/developer/embedded-faq" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/lt-lt/power-bi/developer/embedded-faq&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;With service principal, you can configure&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/lt-lt/power-bi/developer/embedded-row-level-security#on-premises-data-gateway-with-service-principal" target="_blank" rel="noopener"&gt;row-level security (RLS)&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;using an SQL Server Analysis Services (SSAS) on-premises live connection data source. This way you can manage users and their access to data in SSAS when integrating with&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Power BI Embedded&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;using a service principal.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It specifically says SSAS, so I think that if we want to do this we would need to move to using that instead of SQL database.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So many pieces, it is sometimes hard to figure out what supports what &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:04:08 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-Data-Gateway-SQL-server-Import-method-RLS/m-p/942647#M22416</guid>
      <dc:creator>Dan_0101</dc:creator>
      <dc:date>2020-02-21T12:04:08Z</dc:date>
    </item>
  </channel>
</rss>

