<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Power BI Embedded for customers security question in Developer</title>
    <link>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-for-customers-security-question/m-p/4666412#M60735</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/1265075"&gt;@Erkko&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to the Microsoft Fabric Forum Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In Power BI Embedded you can enforce multi‑tenant isolation by combining a single Dynamic Row‑Level Security (RLS) role in the dataset with an embed token that carries the viewer’s Customer ID. You create one RLS role in Power BI Desktop—e.g. CustomerRole whose filter is [CustomerID] = CUSTOMDATA(). When each user signs in to your SaaS app, your back‑end calls GenerateToken and, in the effectiveIdentity, supplies that role plus a customData value equal to the user’s Customer ID (or a comma‑separated list of IDs for resellers). Because CUSTOMDATA() is populated from the signed token, Power BI automatically filters the dataset so the report renders only the rows whose CustomerID matches the value in the token—no extra code or&lt;/P&gt;
&lt;P&gt;slicers required, and users cannot tamper with the filter. This lets a single published report securely serve every customer while minimizing maintenance and license overhead.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you &amp;amp; best regards,&lt;BR /&gt;Prasanna Kumar&lt;/P&gt;</description>
    <pubDate>Thu, 24 Apr 2025 10:08:25 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2025-04-24T10:08:25Z</dc:date>
    <item>
      <title>Power BI Embedded for customers security question</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-for-customers-security-question/m-p/4666178#M60726</link>
      <description>&lt;P&gt;Hi!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are currently working a project where we embed Power BI in our app for customers. We have all the data in one table and my concern is that is it possible to provide the customer ID from our app with embed token and apply automatically some kind of locked filter to show only data mapped to that provided customer ID?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example of the case:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer A signs in our app and navigates to page where Power BI embedded is. Power BI embedded automatically filters the data belonging to Customer A and hides everything else.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer B signs in the same time and sees only data belonging to Customer B.&lt;BR /&gt;&lt;BR /&gt;I'm new at this so any kind of help is more than welcome. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2025 07:58:30 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-for-customers-security-question/m-p/4666178#M60726</guid>
      <dc:creator>Erkko</dc:creator>
      <dc:date>2025-04-24T07:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: Power BI Embedded for customers security question</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-for-customers-security-question/m-p/4666412#M60735</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/1265075"&gt;@Erkko&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to the Microsoft Fabric Forum Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In Power BI Embedded you can enforce multi‑tenant isolation by combining a single Dynamic Row‑Level Security (RLS) role in the dataset with an embed token that carries the viewer’s Customer ID. You create one RLS role in Power BI Desktop—e.g. CustomerRole whose filter is [CustomerID] = CUSTOMDATA(). When each user signs in to your SaaS app, your back‑end calls GenerateToken and, in the effectiveIdentity, supplies that role plus a customData value equal to the user’s Customer ID (or a comma‑separated list of IDs for resellers). Because CUSTOMDATA() is populated from the signed token, Power BI automatically filters the dataset so the report renders only the rows whose CustomerID matches the value in the token—no extra code or&lt;/P&gt;
&lt;P&gt;slicers required, and users cannot tamper with the filter. This lets a single published report securely serve every customer while minimizing maintenance and license overhead.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you &amp;amp; best regards,&lt;BR /&gt;Prasanna Kumar&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2025 10:08:25 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-for-customers-security-question/m-p/4666412#M60735</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2025-04-24T10:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: Power BI Embedded for customers security question</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-for-customers-security-question/m-p/4666512#M60742</link>
      <description>&lt;P&gt;Thank you for the answer! We will test this one &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2025 11:17:36 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-for-customers-security-question/m-p/4666512#M60742</guid>
      <dc:creator>Erkko</dc:creator>
      <dc:date>2025-04-24T11:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: Power BI Embedded for customers security question</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-for-customers-security-question/m-p/4775724#M62324</link>
      <description>&lt;P&gt;does this work for MS fabric Direct Query or Direct Lake ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 21:59:55 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-for-customers-security-question/m-p/4775724#M62324</guid>
      <dc:creator>FabricISV</dc:creator>
      <dc:date>2025-07-24T21:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Power BI Embedded for customers security question</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-for-customers-security-question/m-p/4797166#M62695</link>
      <description>&lt;P&gt;Hi! We got everything working with the normal PBI reports. However we need support to embed also paginated reports in app. We have looked&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/power-bi/developer/embedded/paginated-reports-row-level-security" target="_blank"&gt;Use row-level security when embedding paginated reports - Power BI | Microsoft Learn&lt;/A&gt;&amp;nbsp;this document when applying the settings. We pass "identities": [ username: ] the CUSTOMDATA() value so that the paginated report would work but instead the customdata() value, the report displays some Power BI session GUID for some reason. Do you have any ideas how to get the paginated report embedding with RLS work properly?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Aug 2025 13:38:55 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Embedded-for-customers-security-question/m-p/4797166#M62695</guid>
      <dc:creator>Erkko</dc:creator>
      <dc:date>2025-08-14T13:38:55Z</dc:date>
    </item>
  </channel>
</rss>

