This time we’re going bigger than ever. Fabric, Power BI, SQL, AI and more. We're covering it all. You won't want to miss it.
Learn moreJoin the FabCon + SQLCon recap series. Up next: Power BI, Real-Time Intelligence, IQ and AI, and Data Factory take center stage. All sessions are available on-demand after the live show. Register now
Hello Everyone,
I have a few questions regarding best practices for data encryption and decryption in Power BI:
Best Practices for Encrypt-Decrypt in Power BI:
Decrypting Encrypted Data from Azure SQL in Power BI:
Name | Values |
| Zcsa1u28y22ucn0cqn3225v | 100 |
| xny7q85tv9rnq2umr0yj2qic | 200 |
| cqnhc3cq985t3v3v305qmc2 | 300 |
I appreciate any insights or guidance you can provide on these topics.
Thank you!
Solved! Go to Solution.
Hi @ZiyadSyauqi ,
According to a statement in the Power BI security white paper:
https://learn.microsoft.com/en-us/power-bi/guidance/whitepaper-powerbi-security
By default, all data retained by Power BI is encrypted using Microsoft-managed keys. Customer data stored in Azure SQL databases is fully encrypted using Azure SQL's Transparent Data Encryption (TDE) technology. Customer data stored in Azure Blob Storage is encrypted using Azure Storage Encryption.
In addition, organizations can use Power BI Premium to encrypt static data imported into the semantic model using their own keys. This method is often described as Bring Your Own Key (BYOK). Utilizing BYOK helps ensure that customer data is not exposed even in the event of a service operator error-something that cannot be easily achieved using transparent server-side encryption. For more information, see Bring Your Own Encryption Key for Power BI.
Best Regards,
Liu Yang
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.
Hi @ZiyadSyauqi ,
According to a statement in the Power BI security white paper:
https://learn.microsoft.com/en-us/power-bi/guidance/whitepaper-powerbi-security
By default, all data retained by Power BI is encrypted using Microsoft-managed keys. Customer data stored in Azure SQL databases is fully encrypted using Azure SQL's Transparent Data Encryption (TDE) technology. Customer data stored in Azure Blob Storage is encrypted using Azure Storage Encryption.
In addition, organizations can use Power BI Premium to encrypt static data imported into the semantic model using their own keys. This method is often described as Bring Your Own Key (BYOK). Utilizing BYOK helps ensure that customer data is not exposed even in the event of a service operator error-something that cannot be easily achieved using transparent server-side encryption. For more information, see Bring Your Own Encryption Key for Power BI.
Best Regards,
Liu Yang
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.
i have encrypted data in snowflake can i decrypt in power bi service on the fly while i use direct query or can i achive by having udf at report server level .as of now i use cognos bi and snowflake encrypted data where i am creating udf to decrypt on the fly in cognos while using direct query .need same functionality in power bi can we do it with byok pls confirm
Check out the April 2026 Power BI update to learn about new features.
If you have recently started exploring Fabric, we'd love to hear how it's going. Your feedback can help with product improvements.
A new Power BI DataViz World Championship is coming this June! Don't miss out on submitting your entry.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |