Forum Discussion
Prompt all users to enter AD credentials when accessing PBIRS reports
- 5 years ago
Yes, kiosk PCs are a slightly different use case. If you want EVERYONE that connects to PBIRS to be prompted then you could switch from using Windows auth to using Basic auth (see https://docs.microsoft.com/en-us/sql/reporting-services/security/configure-basic-authentication-on-the-report-server?view=sql-server-ver15 ) Note: you should make sure you have HTTPS configured when using basic auth as the credentials are sent in clear text as part of the request.
The only issue then is that there is no "logout" button in the report portal, so the only way to "logout" is to close ALL browser windows. Closing just the current tab is not enough.
I'm pretty sure that the decision of whether to prompt for credentials is made by the client machine, by default if the url is detected as being in the Intranet or Trusted Sites zones (which you configure either using Group Policy or in the Internet Options on the client machines). If you configured the PBIRS url to be in the Intranet zone the browsers will no longer pass through the credentials. If you only require this as a once off another option is to try using an private/incognito window in your browser.
We have checked on making changes to the PBIRS URLs group policies, the URLs do already exist in a trusted zone and unfortunately we can't have them moved to the internet zone instead.
The only option I am looking into now is changing the settings at the IIS level to make sure every user is prompted to enter credentials before viewing any report on PBIRS. (The reason for this decision is that we have multiple associates from different levels sharing the same PC, and we need to prompt everyone)
There seem to be a way through IIS, but I am still struggling finding a direct documentation or steps to accomplish that.
Really appreciate any help!
- d_gosbell5 years ago
Super User
Abdelmajid wrote:
The reason for this decision is that we have multiple associates from different levels sharing the same PC, and we need to prompt everyone
I don't think you should be trying to fix this at the PBIRS level. I think you should just get your associates to log out from windows when they finished with the shared PC's. That way when they want to access a report they log in to windows then just access PBIRS and the normal windows auth works. Then when they have finished they log out (they can leave the PC switch on to save the next person from having to boot up).
That way everything they do on that PC is done using their login. So if you have any security or other issues you can directly trace this back to a specific user.
- Abdelmajid5 years ago
Helper I
Thanks. Our case is a little different. We have many shared PCs at the stores and they are always ON using a generic kiosk account.
if users try to access the PBIRS url in the current scenario, the accesss uses the generic Kiosk as the login account to authenticate.
Since PBIRS is using the default Windows authentication and picking up the user from the machine, we have to somehow force the PBIRS url to ignore the PC credentials and just force every user to enter credentials when when getting the prompt box.
have done some research and seems doable using IIS, just don't have the proper documented steps for that.
- d_gosbell5 years ago
Super User
Yes, kiosk PCs are a slightly different use case. If you want EVERYONE that connects to PBIRS to be prompted then you could switch from using Windows auth to using Basic auth (see https://docs.microsoft.com/en-us/sql/reporting-services/security/configure-basic-authentication-on-the-report-server?view=sql-server-ver15 ) Note: you should make sure you have HTTPS configured when using basic auth as the credentials are sent in clear text as part of the request.
The only issue then is that there is no "logout" button in the report portal, so the only way to "logout" is to close ALL browser windows. Closing just the current tab is not enough.