Join us at FabCon Atlanta from March 16 - 20, 2026, for the ultimate Fabric, Power BI, AI and SQL community-led event. Save $200 with code FABCOMM.
Register now!Get Fabric Certified for FREE during Fabric Data Days. Don't miss your chance! Request now
Hi!
We have a serious security issue regarding Power BI Report Server.
We depolyed a power bi report server report URL on a web portal but the URL is easy to catch after inspection on the portal and a user can have access to data of all other customers.
So we would like to avoid direct access to the URL through the web browser.
Authentication mode on Power BI Report Server: SSO (SAML).
Data loading mode: Import.
Has anyone come across this requirement before? Any thoughts or suggested solutions would be greatly appreciated.
Thanks!
And the underlying data source? SSAS Tabular?
Can you clarify the problem? Don't you use RLS?
BR
Hi @lukiz84
I would like to specify that we are using SSO (SAML) authentication mode on Power BI Report Server to avoid double authentication in the web portal, and with this mode we can not use RLS. What we are doing to manage users access to filtered data is adding filters in the Report Server URL.
The problem is that those filters are not hidden and could be modified or deleted from users after URL catching.
With best regards.
Check out the November 2025 Power BI update to learn about new features.
Advance your Data & AI career with 50 days of live learning, contests, hands-on challenges, study groups & certifications and more!
| User | Count |
|---|---|
| 6 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
| User | Count |
|---|---|
| 13 | |
| 7 | |
| 7 | |
| 5 | |
| 4 |