Read-only API for Power BI usage and audit data without requiring tenant admin roles
π¦ Request Summary
Provide a supported, least-privilege API or role to access Power BI usage and audit data (user, report, workspace, timestamp, etc...) without requiring tenant-wide admin roles, enabling secure and automated governance, analytics, and compliance reporting.
π¦ Background & Business Need
Need to analyze Power BI usage and adoption for governance, cost optimization, security auditing, and compliance purposes.
Typical requirements include understanding:
- Who accessed which Power BI report
- When the access occurred
- Which workspace and dataset were involved
- What type of connection was used (Import, DirectQuery, Live, AS)
Currently, the Power BI Activity Events API is the only supported source that provides this level of detail. However, accessing this API requires assigning Power BI Service Administrator or Fabric Administrator roles to the calling identity (user or service principal).
In many enterprises, especially those with:
- Strict security controls
- Segregation-of-duties policies
- Internal and external audit requirements
- Regulated environments (finance, healthcare, government)
granting tenant-wide admin roles to automation identities or analytics teams is not acceptable, even for read-only reporting purposes.
As a result, organizations face a difficult trade-off between:
- Achieving visibility into Power BI usage, or
- Maintaining least-privilege and compliance standards
This challenge is common across organizations of all sizes and industries.
π¦ Expected Benefits
Introducing a read-only, least-privilege access model for Power BI usage data would deliver significant benefits:
- β Enables secure, automated usage and adoption analytics
- β Reduces need for broad tenant admin role assignments
- β Aligns with enterprise security and compliance best practices
- β Improves governance, capacity planning, and cost management
- β Supports audit and monitoring requirements without elevated risk
- β Benefits all customers, from small tenants to large regulated enterprises
Such an enhancement would allow customers to fully leverage Power BI and Fabric telemetry while maintaining strong security boundaries, and would encourage broader adoption of Microsoft-recommended governance practices.
Recent ideas
Accessibility issue in the Share dialog of embedded Power BI reports
Accessibility issue in the Share dialog of embedded Power BI reports I would like to share an accessibility finding identified while testing an embedded Power BI report published as part of the cont...ugartema2 hours agoNew MemberNew8Views1like0CommentsAbility to Isolate Fabric Workspaces Across Browser Tabs and Windows - Power Bi Service
When opening a Fabric workspace in a new browser tab, I cant keep different workspaces open across multiple tabs. The workspace context appears to be shared between tabs. For example: Tab 1 = Dev...aashraysood3 hours agoMicrosoft EmployeeNew108Views9likes2CommentsEventhouse Event Hub Ingestion: Respect retrieval start date during preview sampling
In the Eventhouse / KQL Database "Get Data" (One-Click) ingestion wizard for Azure Event Hubs, the preview/inspection engine samples messages starting from the oldest retained events in the partition...dskiftesvik3 hours agoNew MemberNew4Views0likes0CommentsSupport VNet data gateway connections in Power BI Report Builder (Get data / Power Query)
Power BI Report Builder can't use a VNet data gateway connection. In Get data (Power Query), the Data gateway field shows "none" and can't be changed, so the query goes straight to the source over th...ilia_ryzhkov10 hours agoNew MemberNew21Views2likes0CommentsOption to set custom width for gridlines OR fixed outer padding
When designing reports, using the align and distribute evenly options in the format pane are useful, however when designing report pages with fixed bleeds between visuals I have to follow these steps...IolaWhiteley18 hours agoAdvocate IINew9Views0likes0Comments