Read-only API for Power BI usage and audit data without requiring tenant admin roles
π¦ Request Summary
Provide a supported, least-privilege API or role to access Power BI usage and audit data (user, report, workspace, timestamp, etc...) without requiring tenant-wide admin roles, enabling secure and automated governance, analytics, and compliance reporting.
π¦ Background & Business Need
Need to analyze Power BI usage and adoption for governance, cost optimization, security auditing, and compliance purposes.
Typical requirements include understanding:
- Who accessed which Power BI report
- When the access occurred
- Which workspace and dataset were involved
- What type of connection was used (Import, DirectQuery, Live, AS)
Currently, the Power BI Activity Events API is the only supported source that provides this level of detail. However, accessing this API requires assigning Power BI Service Administrator or Fabric Administrator roles to the calling identity (user or service principal).
In many enterprises, especially those with:
- Strict security controls
- Segregation-of-duties policies
- Internal and external audit requirements
- Regulated environments (finance, healthcare, government)
granting tenant-wide admin roles to automation identities or analytics teams is not acceptable, even for read-only reporting purposes.
As a result, organizations face a difficult trade-off between:
- Achieving visibility into Power BI usage, or
- Maintaining least-privilege and compliance standards
This challenge is common across organizations of all sizes and industries.
π¦ Expected Benefits
Introducing a read-only, least-privilege access model for Power BI usage data would deliver significant benefits:
- β Enables secure, automated usage and adoption analytics
- β Reduces need for broad tenant admin role assignments
- β Aligns with enterprise security and compliance best practices
- β Improves governance, capacity planning, and cost management
- β Supports audit and monitoring requirements without elevated risk
- β Benefits all customers, from small tenants to large regulated enterprises
Such an enhancement would allow customers to fully leverage Power BI and Fabric telemetry while maintaining strong security boundaries, and would encourage broader adoption of Microsoft-recommended governance practices.
Recent ideas
Default Scrollable Time-Series Charts to Most Recent Data
Currently, Power BI time-series charts always open scrolled to the earliest (leftmost) date by default, which is inconvenient for reports where users are interested in the most recent (rightmost) dat...CStillwell15 minutes agoNew MemberNew15Views2likes1CommentOption to Stop Fabric Planning Billing Session After Plan Item Deletion
Currently, a Fabric Planning session remains active for 30 days once triggered. If a user creates a Plan item only for testing and deletes it the next day, the billing session still continues and c...v-dugumarrir11 hour agoMicrosoft EmployeeNew44Views10likes1CommentAllow Managed Private Endpoint to be disabled/enabled per notebook
Could notebooks have an option to use or not use the workspace's Managed Private Endpoint (MPE)? MPE can significantly increase notebook startup time, even for notebooks that don't need private conn...frithjof_v1 day agoCommunity ChampionNew25Views1like0Comments