Forum Discussion

azocc's avatar
azocc
Frequent Visitor
1 year ago
Solved

Windows 11 Credential Guard and Credential Manager

We have a multidomain environment and have been using Credential Manager/Windows Credentials for PowerBI Desktop connections.  After installing Windows 11 (with Credential Guard on by default) were running into authentication failure because Credential Manager isn't working.  If the user logs into SSMS, it uses the credential manager and is visible as the user connected.  With PowerBI desktop, the credential manager isnt' working.   We can use "alternate credentials" in the connection to bypass this. For security reasons, we won't be disabling Credential Guard.   Anyone else having this problem?

  • Hi azocc 

    In a multidomain environment with Windows 11’s Credential Guard enabled, using Credential Manager for Power BI Desktop connections can indeed present challenges. Here’s a breakdown of potential solutions:

    1. Use Alternate Credentials: This is a viable workaround, allowing users to manually input credentials for authentication in Power BI Desktop. This approach bypasses the Credential Manager dependency without requiring Credential Guard to be disabled.

    2. Kerberos Constrained Delegation (KCD): KCD can help in some multidomain setups by securely delegating authentication. However, implementing KCD may require extensive configuration and might not fully resolve the issue for Power BI Desktop with Credential Guard enabled.

    3. Check Group Policy Settings: Ensure Credential Guard’s settings in Group Policy are configured appropriately. In some cases, policies can be adjusted to allow compatibility with specific applications, but this would require IT admin assistance and testing.

    4. Update Power BI Desktop: Make sure you’re using the latest version of Power BI Desktop, as updates may include fixes for compatibility issues related to enhanced security features like Credential Guard.

    If none of these solutions fully address the issue, it may be necessary to contact Microsoft Support for more customized assistance, as Credential Guard’s constraints with multi-domain authentication in Power BI Desktop may need direct intervention from Microsoft.

    You can submit a support request here: Power BI Support.

    If this post helps, then please consider Accepting it as the solution to help the other members find it more quickly.

3 Replies

  • Hi azocc 

    In a multidomain environment with Windows 11’s Credential Guard enabled, using Credential Manager for Power BI Desktop connections can indeed present challenges. Here’s a breakdown of potential solutions:

    1. Use Alternate Credentials: This is a viable workaround, allowing users to manually input credentials for authentication in Power BI Desktop. This approach bypasses the Credential Manager dependency without requiring Credential Guard to be disabled.

    2. Kerberos Constrained Delegation (KCD): KCD can help in some multidomain setups by securely delegating authentication. However, implementing KCD may require extensive configuration and might not fully resolve the issue for Power BI Desktop with Credential Guard enabled.

    3. Check Group Policy Settings: Ensure Credential Guard’s settings in Group Policy are configured appropriately. In some cases, policies can be adjusted to allow compatibility with specific applications, but this would require IT admin assistance and testing.

    4. Update Power BI Desktop: Make sure you’re using the latest version of Power BI Desktop, as updates may include fixes for compatibility issues related to enhanced security features like Credential Guard.

    If none of these solutions fully address the issue, it may be necessary to contact Microsoft Support for more customized assistance, as Credential Guard’s constraints with multi-domain authentication in Power BI Desktop may need direct intervention from Microsoft.

    You can submit a support request here: Power BI Support.

    If this post helps, then please consider Accepting it as the solution to help the other members find it more quickly.

  • Anonymous's avatar
    Anonymous
    Not applicable

    Hi, azocc 

    Have you tried the Ritaf1983's methods and are the methods provided by Ritaf1983 applicable to your situation?


    If you are experiencing a problem that has not been resolved, please provide us with more information (excluding sensitive information) and we will do our best to resolve the problem for you.

     

     

    I hope my suggestions give you good ideas, if you have any more questions, please clarify in a follow-up reply.
    Best Regards,
    Fen Ling,
    If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

    • azocc's avatar
      azocc
      Frequent Visitor

      We're using option 1, options 2 and 3 are not going to be options for us.  Option 4, we're already in the latest PowerBI desktop.  This issue also is a problem in Excel with PowerQuery.  I consifder this a bug that needs addressing by Microsoft.  I'll wait but I retire in 3 years and I'm not optimistic.