Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

The Power BI Data Visualization World Championships is back! Get ahead of the game and start preparing now! Learn more

Reply
MarkDuslak
New Member

Public Web Report Data Security Through PowerQuery Transformation

I have been struggling to find a definitive result on whether creating a public report opens the chance for data misuse, breaches, etc.

For context, I work in higher education and we are seeking to create a public report to provide community access to aggregated college data (graduation rates, enrollment, etc.). Our current model has tables with personally identifiable information (PII) (e.g. names, addresses, phone, email).

If I remove these columns through PowerQuery, restrict drill-downs, and use only explicit measures instead of implicit measures in the report, are these enough safeguards to prevent someone from accessing the PII? I'm planning to use a data connection to our Student Information System that refreshes daily, but I have spoken to colleagues who recommend using a static dataset and updating it manually once a year. Are there any additional security issues posed by using data that is directly connected to our Student Information System that I should consider?

1 ACCEPTED SOLUTION

@MarkDuslak I would say that as long as you strip out all the PII you should be good. Something that you can consider is the pre-aggregate the data into tables using Power Query. I don't see any risk just having it refresh in the Service. The Service encrypts the credentials and it isn't exposed in any way publicly.



Follow on LinkedIn
@ me in replies or I'll lose your thread!!!
Instead of a Kudo, please vote for this idea
Become an expert!: Enterprise DNA
External Tools: MSHGQM
YouTube Channel!: Microsoft Hates Greg
Latest book!:
DAX For Humans

DAX is easy, CALCULATE makes DAX hard...

View solution in original post

3 REPLIES 3
Greg_Deckler
Community Champion
Community Champion

@MarkDuslak You are going to use an Import mode semantic model, correct?



Follow on LinkedIn
@ me in replies or I'll lose your thread!!!
Instead of a Kudo, please vote for this idea
Become an expert!: Enterprise DNA
External Tools: MSHGQM
YouTube Channel!: Microsoft Hates Greg
Latest book!:
DAX For Humans

DAX is easy, CALCULATE makes DAX hard...

@Greg_Deckler ,Yes. Import mode, not direct query or composite.  I should've been more detailed in the original explanation.  Our student information system is an Oracle database.  That data is queried via SQL and tables are created.  The tables are housed in an Azure blob and are imported to Powerbi.

@MarkDuslak I would say that as long as you strip out all the PII you should be good. Something that you can consider is the pre-aggregate the data into tables using Power Query. I don't see any risk just having it refresh in the Service. The Service encrypts the credentials and it isn't exposed in any way publicly.



Follow on LinkedIn
@ me in replies or I'll lose your thread!!!
Instead of a Kudo, please vote for this idea
Become an expert!: Enterprise DNA
External Tools: MSHGQM
YouTube Channel!: Microsoft Hates Greg
Latest book!:
DAX For Humans

DAX is easy, CALCULATE makes DAX hard...

Helpful resources

Announcements
Power BI DataViz World Championships

Power BI Dataviz World Championships

The Power BI Data Visualization World Championships is back! Get ahead of the game and start preparing now!

December 2025 Power BI Update Carousel

Power BI Monthly Update - December 2025

Check out the December 2025 Power BI Holiday Recap!

FabCon Atlanta 2026 carousel

FabCon Atlanta 2026

Join us at FabCon Atlanta, March 16-20, for the ultimate Fabric, Power BI, AI and SQL community-led event. Save $200 with code FABCOMM.