<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Embedding Power BI Report Server reports with iframe - is it safe? in Report Server</title>
    <link>https://community.fabric.microsoft.com/t5/Report-Server/Embedding-Power-BI-Report-Server-reports-with-iframe-is-it-safe/m-p/3100900#M29035</link>
    <description>&lt;P&gt;Thanks for answer!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both PBIRS and the web application we implelemnt the iframe from are internal systems, and will not communicate outside the organisation. It seems like the &lt;SPAN&gt;authentication&amp;nbsp;&lt;/SPAN&gt;works fine with iframe and PBIRS..&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Feb 2023 08:49:38 GMT</pubDate>
    <dc:creator>jakob82</dc:creator>
    <dc:date>2023-02-27T08:49:38Z</dc:date>
    <item>
      <title>Embedding Power BI Report Server reports with iframe - is it safe?</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Embedding-Power-BI-Report-Server-reports-with-iframe-is-it-safe/m-p/3098840#M29021</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wonder if it is recommended to use iframe when embedding reports from Power BI Report Server to our Blazor WASM application? I have always heard that you should avoid using iframes, but from what i understand, iframes are the only alternative? What are the guidelines? Is it possible to refer to some Microsoft documentation that says it is secure?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 20:11:06 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Embedding-Power-BI-Report-Server-reports-with-iframe-is-it-safe/m-p/3098840#M29021</guid>
      <dc:creator>jakob82</dc:creator>
      <dc:date>2023-02-24T20:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: Embedding Power BI Report Server reports with iframe - is it safe?</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Embedding-Power-BI-Report-Server-reports-with-iframe-is-it-safe/m-p/3099903#M29032</link>
      <description>&lt;P&gt;iframes will not give your users a seamless authentication experience and will not allow your hosting application to transfer context over (you can mitigate that somewhat with report URL filters.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The standard way would be to use full Power BI embedded (in your&amp;nbsp; case "user owns data") but I don't how how that applies to PBIRS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/power-bi/developer/embedded/embedded-analytics-power-bi" target="_blank"&gt;Power BI embedded analytics overview - Power BI | Microsoft Learn&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2023 13:47:03 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Embedding-Power-BI-Report-Server-reports-with-iframe-is-it-safe/m-p/3099903#M29032</guid>
      <dc:creator>lbendlin</dc:creator>
      <dc:date>2023-02-26T13:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: Embedding Power BI Report Server reports with iframe - is it safe?</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Embedding-Power-BI-Report-Server-reports-with-iframe-is-it-safe/m-p/3100900#M29035</link>
      <description>&lt;P&gt;Thanks for answer!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both PBIRS and the web application we implelemnt the iframe from are internal systems, and will not communicate outside the organisation. It seems like the &lt;SPAN&gt;authentication&amp;nbsp;&lt;/SPAN&gt;works fine with iframe and PBIRS..&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 08:49:38 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Embedding-Power-BI-Report-Server-reports-with-iframe-is-it-safe/m-p/3100900#M29035</guid>
      <dc:creator>jakob82</dc:creator>
      <dc:date>2023-02-27T08:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: Embedding Power BI Report Server reports with iframe - is it safe?</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Embedding-Power-BI-Report-Server-reports-with-iframe-is-it-safe/m-p/3104886#M29056</link>
      <description>&lt;P&gt;Using iframes are the only option with PBIRS, it does not support the same embedding options as the cloud service. I think that one of the big concerns with iframes are XSS attacks, but since PBIRS does not store and render unvalidated user data I *think* the attack vectors are limited there. For example I am not aware of any way that a user could enter javascript into a report parameter and have that execute so that it could do malicious things on the host site.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 23:43:13 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Embedding-Power-BI-Report-Server-reports-with-iframe-is-it-safe/m-p/3104886#M29056</guid>
      <dc:creator>d_gosbell</dc:creator>
      <dc:date>2023-02-28T23:43:13Z</dc:date>
    </item>
  </channel>
</rss>

