<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Power BI On Premise Report Server X-Frame-Options in Report Server</title>
    <link>https://community.fabric.microsoft.com/t5/Report-Server/Power-BI-On-Premise-Report-Server-X-Frame-Options/m-p/2489539#M23963</link>
    <description>&lt;P&gt;As what I observed, the on-premises PBI version and SSRS 2016+ version have this response header (X-Frame-Options) added on. However, the PBI.com does not have the same header. On the other hand, the older SSRS version 2014 or earlier do not have the same header. If it is the security concern, it should apply across the versions. Also, AD FS 2019 is still allowing to remove the header (&lt;A href="https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/customize-http-security-headers-ad-fs" target="_blank"&gt;https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/customize-http-security-headers-ad-fs&lt;/A&gt;). I need to know how to remove the header for on-premises PBI and SSRS 2019 since we are hosting them internally and locked down all the securities. Any help will be appreciated.&lt;/P&gt;</description>
    <pubDate>Mon, 02 May 2022 21:14:19 GMT</pubDate>
    <dc:creator>jwu</dc:creator>
    <dc:date>2022-05-02T21:14:19Z</dc:date>
    <item>
      <title>Power BI On Premise Report Server X-Frame-Options</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Power-BI-On-Premise-Report-Server-X-Frame-Options/m-p/1676733#M18216</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;We are trying to access parent HTML elements using Custom Visualization but cannot access them because X-Frame-Options security.&lt;BR /&gt;&lt;BR /&gt;We tried to add Content-Security-Policy in the web config file available at the following location, but it is not working any suggestion.&lt;/P&gt;&lt;P&gt;C:\Program Files\Microsoft Power BI Report Server\PBIRS\ReportServer&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 09:19:05 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Power-BI-On-Premise-Report-Server-X-Frame-Options/m-p/1676733#M18216</guid>
      <dc:creator>vlemon</dc:creator>
      <dc:date>2021-02-19T09:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: Power BI On Premise Report Server X-Frame-Options</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Power-BI-On-Premise-Report-Server-X-Frame-Options/m-p/1679763#M18251</link>
      <description>&lt;P&gt;This is by design. Custom visuals run inside a restricted "sandbox" and they are not allowed to interact with any of the parent html elements&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 04:28:04 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Power-BI-On-Premise-Report-Server-X-Frame-Options/m-p/1679763#M18251</guid>
      <dc:creator>d_gosbell</dc:creator>
      <dc:date>2021-02-22T04:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: Power BI On Premise Report Server X-Frame-Options</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Power-BI-On-Premise-Report-Server-X-Frame-Options/m-p/2489539#M23963</link>
      <description>&lt;P&gt;As what I observed, the on-premises PBI version and SSRS 2016+ version have this response header (X-Frame-Options) added on. However, the PBI.com does not have the same header. On the other hand, the older SSRS version 2014 or earlier do not have the same header. If it is the security concern, it should apply across the versions. Also, AD FS 2019 is still allowing to remove the header (&lt;A href="https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/customize-http-security-headers-ad-fs" target="_blank"&gt;https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/customize-http-security-headers-ad-fs&lt;/A&gt;). I need to know how to remove the header for on-premises PBI and SSRS 2019 since we are hosting them internally and locked down all the securities. Any help will be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2022 21:14:19 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Power-BI-On-Premise-Report-Server-X-Frame-Options/m-p/2489539#M23963</guid>
      <dc:creator>jwu</dc:creator>
      <dc:date>2022-05-02T21:14:19Z</dc:date>
    </item>
  </channel>
</rss>

