There should be an option to not cache credentials for data sources from connections with Power BI. This is a security issue and does not go well with customers.
18 Comments
- larry_steinleNew MemberAt least make it obvious when cached credentials are being used, whose credentials are being used and how to remove them from Power BI Desktop.
- larry_steinleNew MemberFound a way to remove the cached credentials. In Power BI Desktop select File, Options and Settings and then Data Source Settings. Find the data source with the cached settings and use the "Clear Permissions" button to reset. Again, it should be obvious to the user when cached credentials are used and which cached credentials are used. Even in the Data Source Settings form we can't tell which credentials are used with each data source.
- Ven
Advocate I
Hi I'm having a similar issue in the Power BI Web interface. In the Power BI Desktop I've created an OData connection and created a report. The dataset uses a parameter for the OData service and that can be entered later when the Content Pack Template is used. I've saved the .PBIX file and then uploaded it to the PBI Web with the upload file to import the data. I've setup the dashboard with the report and from that created a Content Pack Template, making sure I tick the option at the bottom called 'Make this content pack a template'. When using the Content Pack Template on another Group I enter a different OData endpoint for a completely different domain. However it doesn't ask for credentials it automatically connects and loads in the data. That is wrong it should ask me for credentials to access the OData source not use cached ones. - mpurohit1New MemberIf we revoke access to a specific table in database, we need to be sure that the user is unable to query those tables going forward. At this time, if User A shared pbix file with User B, the User B can continue refreshing data with User A's cached credentials which is a problem.
- oz_mikeNew MemberHi caching the credentials has a nasty side effect you may not be aware of. If the site you are on has a change password policy every few months etc..and n lock attempts, once the user changes the password and they open the pbix file it can lock them out as tries to log in multiple times. So the admin guys unlock the file and again , and the user opens the file it lock them out again . So . The work around is for the user to know to clear credentials before they open the file (not obvious) . The power bi file should only attempt once to log on if it fails stop!? or have a setting to force the user to log in each time. ie an option do not store credentials - could be per table level or global. se this link http://community.powerbi.com/t5/Desktop/Power-bi-locks-user-out-of-database-if-password-has-changed/m-p/185765#M81648
- wilsonbeNew MemberThis is particularly important for the databases that don't use Windows Integrated Auth (everything except some SQL Server instances). The credentials should never be silently cached in the file. At best, caching them on the machine can be OK.
- david_molyneux2New MemberHas there been any movement on this idea? I have multiple links to JDE (DB2) and there is a 3 attempt lockout. Every time I open a PBI file it locks me out of 5 servers and I have to go through my service desk to unlock and it's very annoying! To be honest I think the process of one failed attempt then prompt for credentials should be default anyway.
- FredTheFrog
Advocate I
I have multiple links to Oracle databases, and there is also a three-attempt lockout. It's rather frustrating to change my Oracle password, then not be able to open a Power BI file because it will always attempt to use stored credentials before allowing any option to reset/update them. - nallenNew MemberI keep getting locked out of my company's database due to failed log in attempts from my Power BI Desktop models. Including an option to require log in credentials at each refresh would eliminate this problem.
- DHanton1New MemberPowerBI Gateway needs a more sophisticated interface, affording more control to admins to flush the cache if necessary or quickly and easily upgrade all credentials when a user's password is reset (as per IT policies requiring monthly password resets). It doesn't make sense to need to update the password for every single data source used in every single report and dashboard as this is time consuming and means that for the end-users, the Business Intelligence system is effectively inoperable whilst the passwords are being reset. At present, resetting passwords via the online interface seems to not always work, so an offline interface on the Enterprise Gateway makes a lot more sense. If credentials are to be cached, a single credential should be cached for all datasets used by the analyst (e.g. a one-to-many relationship between credential and datasets. This way, the analyst would change their password once, in one place, as required, to maintain security of the system. And in 1 minute from resetting their network password, all of their dashboards and reports would be operational. If multiple credentials are stored by multiple analysts, the manager or admin could then have oversight and control of these. The Enterprise Gateway at present doesn't seem like an Enterprise grade product. Needs a lot of improvement.
Recent ideas
Blocker: Purview must scan Fabric Warehouse tables/columns or we will deprecate Purview
Purview + Fabric Warehouse ≠enterprise‑ready governance. In our environment, the Fabric Warehouse is the system of record, but Purview can only catalog the warehouse container—not the tables or co...Joshua_Hernande7 hours agoNew MemberNew180Views1like1CommentPower Query Parameter create/use when connecting to a dataflow
In power query when you connect to a table in a dataflow there are no options to create or use a parameter for that dataflow. When connecting to SQL there is an option when setting up the connection ...ben_holmes15 hours agoNew MemberNeed Clarification198Views3likes1CommentParameterize Dataflow Gen2 data source connection
Allow the Dataflow Gen2 data source connection GUID to be parameterized and stored in a Variable Library. This would allow the same Dataflow to use different connections depending on the workspace/e...frithjof_v15 hours agoCommunity ChampionNeeds Votes37Views2likes1CommentExpose Power Query as a Standalone Runtime and Command-Line Interface (CLI)
Summary Power Query has evolved into one of Microsoft's most powerful data transformation technologies and is now used across Excel, Power BI, Fabric, Dataflows, Power Platform, and other products. ...juansgr_15 hours agoNew MemberAbandoned27Views0likes2CommentsExpose User Prompt and Agent Response Logs for Fabric Data Agents
Idea: As an engineer responsible for managing and improving Microsoft Fabric Data Agents, I currently have no way to view how users are interacting with the agents I’ve built. While it’s likely that...JoshuaPitzer17 hours agoAdvocate INew1.2KViews26likes2Comments