Not Supporting SSO for Dataflows Introduces a Security Issue
Dataflows (both Gen 1 and Gen 2) do not support SSO. Unfortunately it simply bypasses SSO, allowing the user to see what the Power BI / Fabric Connection service account has for access. This bypasses security controls and introduces a significant security issue. Please address this issue. Options include:
- Updating your documentation to state that Dataflows bypass the SSO option of your Connection completely.
- Make it so if a Dataflow sources a Connection with the SSO option it errors or fails, instead of silently bypassing it.
- Making SSO work with Dataflows.
- Allow for Dataflow only Connections.
2 Comments
- agustin_martinNew Member
They addressed it by stating in the documentation that only semantic models support sso.
It's quite baffling how Microsoft can promote Dataflows as the solution for reuse and efficiency while ommiting this glaring security issue.
Having the enterprise Gateway ignore sso for dataflows effectively removes any security control for analysts using anything except semantic models.
As it stands, it seems that Microsoft currently does not have a solution for enterprise scenarios where you need:
- Efficient acces to on-prem data
- Access control (security)
Which seem to me quite basic requirements for any data enterprise aspiring solution.
- fbcideas_migusrNew MemberStatus added:New
Recent ideas
Allow Detect Data Changes for Historic Data Outside Incremental Window
In Power BI Incremental Refresh,Detect Data Changes only works inside the incremental refresh window. If historic data gets updated, Power BI cannot detect or refresh it unless I expand the increment...NAGAKEERTHI_Y1 hour agoNew MemberNew113Views1like1CommentImproving complexity of Page Navigator in PowerBI
The page navigator could be improved in multiple ways to help reports that have many pages: Allow scroll in vertical view Allow pages within the navigator (EX: using a right and left carrot to sho...kreid4 hours agoNew MemberNew76Views2likes2Comments