Enable Robust 'Test as Role' Impersonation for DirectQuery Models with SSO Data Sources
Business Problem:
For enterprise departments, data governance and security are paramount. We rely on DirectQuery with Single Sign-On (SSO) to enforce granular, source-level security on our most sensitive data (e.g., in Azure Synapse, Snowflake, or Azure SQL). While this architecture is powerful for security, it creates a significant bottleneck in our development lifecycle.
Currently, the "Test as role" feature in the Power BI Service is incompatible with SSO-enabled DirectQuery sources. This prevents our developers and analysts from being able to efficiently validate the security context of a report before deployment.
Current Limitation & Workaround:
The current workaround involves provisioning dedicated test user accounts, managing their permissions in both Power BI and the underlying data source, and performing manual end-to-end testing by logging in as each user. This process is cumbersome, slow, does not scale well, and significantly increases the friction and time required to deploy or update critical financial reports.
Proposed Solution:
Enhance the Power BI Service to allow authorized administrators and developers to use the "Test as role" functionality with SSO-enabled DirectQuery models. This would require a trusted impersonation or delegation mechanism where the Power BI Service can simulate a user's identity through to the data source for the express purpose of testing.
Implementing this feature would dramatically accelerate the development and validation of secure, enterprise-grade analytics solutions on Power BI and Microsoft Fabric, reinforcing its position as a trusted platform for sensitive data.
Recent ideas
Access Variable Library in Semantic Models
Enable the Variable Library as a centralized location for storing all environment‑specific variables, allowing us to adjust them for promotion scenarios (e.g., from dev to prod) without relying on de...FreddyH7 hours agoAdvocate IINew919Views31likes2CommentsEnhance Fabric Pipeline Monitoring with Parent-Child Pipeline Lineage and Parameter Visibility
Currently, Microsoft Fabric Pipeline monitoring lacks several capabilities that are available in Azure Data Factory, making troubleshooting and operational support challenging in enterprise environme...dwramreddy8 hours agoRegular VisitorNew8Views0likes0CommentsDynamic ADLS-Gen2 path input for Spark Jobs Main definition file
I would like the ability to add a dynamic input box on a spark job definition's "Main Definition File" "ADLS-Gen2 path". this would be useful to set base and variable paths across all spark jobs...mfink_db12 hours agoNew MemberNew238Views2likes2CommentsReintroduce Tenant/Capacity Switch to Control "Users can create Plan items" Post-GA
During the Preview phase of Fabric Plan items, administrators had access to a dedicated tenant/capacity setting: "Users can create Plan items". With General Availability (GA), this granular administr...Sri-Surendra_Ku15 hours agoNew MemberNew106Views14likes1Comment