Support FIDO2 (Phishing‑Resistant) Authentication for Power BI On‑Premises Data Gateway
Description / Problem
Our organization has fully enforced phishing‑resistant authentication methods for all employees and administrative accounts, in line with Microsoft security best practices. These include passkeys and FIDO2 hardware security keys (for example, YubiKey).
However, we currently need to maintain Power BI on‑premises data gateway (February 2026 version) as an exception to these policies.
The reason is that the embedded web authentication engine used by the gateway does not support FIDO2 authentication. Because of this limitation, we are unable to enforce phishing‑resistant authentication methods for gateway sign‑in and administration.
Current Behavior
The Power BI on‑premises data gateway currently supports:
- Password‑based authentication, or
- Passwordless authentication using number matching
While number matching improves security, it does not meet the definition of phishing‑resistant authentication required by many enterprise security and compliance standards.
Impact
- Forces organizations to maintain authentication exceptions
- Creates a security gap in otherwise fully phishing‑resistant environments
- Prevents full alignment with Zero Trust and passwordless‑first strategies
- Affects enterprises with strict regulatory, compliance, or security mandates
Requested Enhancement
Please add FIDO2 authentication support (passkeys and hardware security keys) to the Power BI on‑premises data gateway in a future update.
This would allow organizations to:
- Fully enforce phishing‑resistant authentication across all Fabric and Power BI components
- Eliminate password‑based authentication for gateway administration
- Align the gateway with Microsoft’s broader identity and security roadmap
Recent ideas
Enhance Fabric Pipeline Monitoring with Parent-Child Pipeline Lineage and Parameter Visibility
Currently, Microsoft Fabric Pipeline monitoring lacks several capabilities that are available in Azure Data Factory, making troubleshooting and operational support challenging in enterprise environme...dwramreddy10 minutes agoRegular VisitorNew1View0likes0CommentsDynamic ADLS-Gen2 path input for Spark Jobs Main definition file
I would like the ability to add a dynamic input box on a spark job definition's "Main Definition File" "ADLS-Gen2 path". this would be useful to set base and variable paths across all spark jobs...mfink_db4 hours agoNew MemberNew238Views2likes2CommentsReintroduce Tenant/Capacity Switch to Control "Users can create Plan items" Post-GA
During the Preview phase of Fabric Plan items, administrators had access to a dedicated tenant/capacity setting: "Users can create Plan items". With General Availability (GA), this granular administr...Sri-Surendra_Ku7 hours agoNew MemberNew106Views14likes1CommentSupport Fabric SQL Database with workspace-level inbound Private Link
Fabric SQL Database supports tenant-level Private Link but not workspace-level Private Link. Securing a small number of databases therefore requires enabling Private Link across the entire tenant, in...WorkFull229 hours agoAdvocate INew12Views1like0Comments