Enable Workload Identity Federation (WIF) Authentication for Google Cloud Storage in Power BI
Hello,
Currently, Power BI connects to Google Cloud Storage using HMAC credentials, which require manual key management and pose security and scalability challenges. I propose adding support for Workload Identity Federation (WIF) as an authentication method to enhance security, simplify credential management, and align with modern cloud identity practices.
Advantages of WIF Authentication
Improved Security:
WIF eliminates the need for long-lived HMAC keys by using short-lived, automatically rotated tokens via identity providers.No Key Rotation Hassles:
Credentials are federated dynamically, removing the need to manually rotate or store HMAC keys.Centralized Identity Management:
Integrates with enterprise identity providers, enabling fine-grained access control and auditability.Scalability:
Ideal for large-scale deployments where managing static keys becomes impractical.Compliance-Friendly:
Supports modern security standards and helps meet compliance requirements for cloud-native environments.
Limitations of HMAC Authentication
Manual Key Management:
Requires storing and rotating static access keys, which increases operational overhead.Security Risks:
Static keys are vulnerable to leakage and misuse if not handled securely.Limited Integration:
Does not integrate well with identity providers or support federated access models.Audit Complexity:
Tracking access and usage is harder compared to federated identity systems.Conclusion
Adding WIF support for Google Cloud Storage in Power BI would significantly improve security, reduce administrative burden, and align with best practices for cloud identity management. This enhancement would benefit organizations looking to modernize their data access architecture while maintaining robust governance.
Thanks,
Surendhar
Recent ideas
Allow us to rename fabric data agents published to m365
If we use deployment pipelines to promote fabric data agents between dev, test/UAT, and prod fabric workspaces, we need to keep the name of the fabric agent the same in each workspace. If we want to ...PeterDaniels5 hours agoAdvocate IIINew183Views0likes2CommentsMake workspace and item session persistence optional
Description The new persistent session behavior in Microsoft Fabric should be optional rather than forced. Currently, Fabric remembers the workspaces and items that were open in my previous session...TeemuMultanen6 hours agoAdvocate INew294Views47likes2CommentsSupport Encrypted Sensitivity-Labeled Excel Files in Power Query
Description Currently, Power Query Online and Power Query in Excel are unable to access encrypted Excel files. Excel files with sensitivity types other than Public or Non-Business can be encrypted a...ewarstdhyjugkhi7 hours agoMicrosoft EmployeeNew22Views6likes0Comments