Not Supporting SSO for Dataflows Introduces a Security Issue
Dataflows (both Gen 1 and Gen 2) do not support SSO. Unfortunately it simply bypasses SSO, allowing the user to see what the Power BI / Fabric Connection service account has for access. This bypasses security controls and introduces a significant security issue. Please address this issue. Options include:
- Updating your documentation to state that Dataflows bypass the SSO option of your Connection completely.
- Make it so if a Dataflow sources a Connection with the SSO option it errors or fails, instead of silently bypassing it.
- Making SSO work with Dataflows.
- Allow for Dataflow only Connections.
2 Comments
- agustin_martinNew Member
They addressed it by stating in the documentation that only semantic models support sso.
It's quite baffling how Microsoft can promote Dataflows as the solution for reuse and efficiency while ommiting this glaring security issue.
Having the enterprise Gateway ignore sso for dataflows effectively removes any security control for analysts using anything except semantic models.
As it stands, it seems that Microsoft currently does not have a solution for enterprise scenarios where you need:
- Efficient acces to on-prem data
- Access control (security)
Which seem to me quite basic requirements for any data enterprise aspiring solution.
- fbcideas_migusrNew MemberStatus added:New
Recent ideas
Bring Back separating Power BI artifacts on a per web page basis
Previously, the ability to have different artifacts open on different web tabs was enabled. This was beneficial if you wanted to differentiate what environments you were in, working across three diff...zoe-dean47 minutes agoNew MemberNew43Views8likes0CommentsREST API Should expose credentials used in connections
When a consultant leaves a client, it's important to clean up any connections that may have the consultants credentials embedded within. I'm able to use the Fabric CLI to get the managed connections ...PeterDaniels59 minutes agoAdvocate IIINew14Views5likes0CommentsExpose full activity-level error details in Workspace Monitoring Eventhouse
Microsoft Fabric Workspace Monitoring exposes activity-level pipeline telemetry in FabricDataPipelinesActivityRunsLogs, including PipelineRunId, OperationId, ActivityIterationCount, ActivityName, Act...MarcoOnnis1 hour agoNew MemberNew1View0likes0CommentsSQL Analytics Endpoint host name - CNAME or defined alias
The host name for a SQL Analytics endpoint is ugly. They look like this: random_ugly_alphanumeric-random_ugly_alphanumeric.datawarehouse.fabric.microsoft.com The first segment looks like it...Mike_Diehl3 hours agoNew MemberNew29Views2likes1Comment