Forum Discussion

gopowerbi's avatar
gopowerbi
Frequent Visitor
9 years ago
Solved

Powe BI Security Whitepaper

Hallo everyone,

 

I have a question regarding the document that Power BI published regarding its security.

In the document is mentioned that Power BI does store the data on "Azure BLOB" and the metadata on "Azure SQL Server".

 

In the "Data Storage and Movement" chapter it is written that the data is either stored "at rest" or "in process".

 

  1.  "in process" is referring to LiveQueries such as Azure SQL Server LiveQonnection.

  2. "at rest" is referred to "imported" data such as Excel files or Data Sources like SAP BW, OData etc.
     

BUT:

  - when we connect to CRM Dynamics Online, does Power BI extract the data, transform it and load it into Azre BLOB, or does it only make a reference to the data source on CRM Dynamics Onine?

 

  - is the below quoted text from the "Power BI Security Whitepaper" file true?

 

"Non-Direct Query queries do not include credentials for the underlying data, and the underlying data is loaded into the Power BI service unless it is on-premises data accessed through a Power BI Gateway, in which case the query only stores references to on-premises data."  ->  That would mean that if a company accesses to its SAP data via "Power BI Gateway on-premise", the MASTER DATA of SAP would NOT be stored in Azure BLOB?

 

Thank you in advance

  • gopowerbi - Yes, that is my understanding as well (your summary at the end). I think that's why Anonymous and I were so certain that the second highlighted statement had to be incorrect. If it was indeed as stated, then Anonymous and I have spent the last couple years fundamentally not understanding how Power BI works!

9 Replies

  • Greg_Deckler's avatar
    Greg_Deckler
    Icon for Community Champion rankCommunity Champion

    For Desktop, I do not see any other way for CRM Online other than that it imports it into its data model. Otherwise, if it just stores a reference, what would be the purpose of a refresh?

     

    The other part of the whitepaper you quote is very confusing and doesn't seem correct at all. Again, what would be the purpose of a refresh?

    • gopowerbi's avatar
      gopowerbi
      Frequent Visitor

      The puprose of a refresh is to have your data as updated as you want (schedule daily/weekly/... refresh). Why would you need a refresh if you get the data instantly when you run the query/open a dashboard or refresh? Besides that, there is the possibility to create a LiveConnection between Azure SQL Server ( = cloud) and Power BI. I understood it in this way: by getting your data through a live connection, the data is stored into the cloud but temporary.

       

      Regarding to "Power BI Security Whitepapre"  in the first sentence of this link you can download the word document. In the chapter "Data Storage and Movement" is written the text I quoted above, which is about the location of the data you work with.

       

      My post is not about whether the data is refreshed or not but about the security of it. I do not have many doubts about power bi cloud security, but there may be some people in a company who are sceptical about all the cloud history and do not want to "publish" sensitive data onto the cloud.

       

       

      • Anonymous's avatar
        Anonymous
        Not applicable

        gopowerbiGreg_Deckler The highlighted portion that is causing confusion is wrong. I reached out to a contact at Microsoft and they will get the change implemented in the white paper soon. Taking that out, the rest of the white paper does a good job explaining all the "States" of data at rest or in transition.