Enable Robust 'Test as Role' Impersonation for DirectQuery Models with SSO Data Sources
Business Problem:
For enterprise departments, data governance and security are paramount. We rely on DirectQuery with Single Sign-On (SSO) to enforce granular, source-level security on our most sensitive data (e.g., in Azure Synapse, Snowflake, or Azure SQL). While this architecture is powerful for security, it creates a significant bottleneck in our development lifecycle.
Currently, the "Test as role" feature in the Power BI Service is incompatible with SSO-enabled DirectQuery sources. This prevents our developers and analysts from being able to efficiently validate the security context of a report before deployment.
Current Limitation & Workaround:
The current workaround involves provisioning dedicated test user accounts, managing their permissions in both Power BI and the underlying data source, and performing manual end-to-end testing by logging in as each user. This process is cumbersome, slow, does not scale well, and significantly increases the friction and time required to deploy or update critical financial reports.
Proposed Solution:
Enhance the Power BI Service to allow authorized administrators and developers to use the "Test as role" functionality with SSO-enabled DirectQuery models. This would require a trusted impersonation or delegation mechanism where the Power BI Service can simulate a user's identity through to the data source for the express purpose of testing.
Implementing this feature would dramatically accelerate the development and validation of secure, enterprise-grade analytics solutions on Power BI and Microsoft Fabric, reinforcing its position as a trusted platform for sensitive data.
Recent ideas
Support Synonyms in Fabric Warehouse
Microsoft SQL Server has a very powerful feature by the way of "synonyms." It allows users and DBAs to do all sorts of powerful magic such as rewiring objects under the hood (e.g. run the code agains...matthias-bi2 hours agoRegular VisitorNew1.3KViews18likes2CommentsExpose Refresh Warnings and Informational Messages via Notifications and API
When a Power BI semantic model refresh completes successfully, the status shows Completed, even when the refresh details contain warnings or informational messages that require attention. Please pro...Jashwanth_K4 hours agoMicrosoft EmployeeNew21Views6likes0CommentsInvoke Pipeline Task - Workspace Identity Authentication
Currently, the Fabric Data Factory Invoke Pipeline task uses the user's credentials who saved the pipeline to then authenticate to the Azure Data Factory to execute the ADF pipeline. When that user'...dzebrowitz9 hours agoAdvocate IPlanned1.8KViews61likes5CommentsFabric Pipeline should run as workspace identity
Currently, Microsoft Fabric pipelines run under the identity of the last user who modified them, which can cause disruptions when tenant administrators make changes to security policies, such as enab...pellitteris9 hours agoAdvocate IINew1.4KViews27likes3CommentsBring Back separating Power BI artifacts on a per web page basis
Previously, the ability to have different artifacts open on different web tabs was enabled. This was beneficial if you wanted to differentiate what environments you were in, working across three diff...zoe-dean10 hours agoNew MemberNew56Views8likes0Comments