Forum Discussion

Cookistador's avatar
Cookistador
Super User
2 years ago
Solved

Configuration with Kerberos?

Hello eveeryone,

 

For a few days, I'm trying to configure my gateway with Kerberos

We followed the official microsft documentation
https://learn.microsoft.com/en-us/power-bi/connect-data/service-gateway-sso-kerberos

With the two followings options:

Option A: Run the gateway Windows service as a domain account with SPN

Option A: Standard Kerberos constrained delegation

 

But the issue is, Power BI did not delegate, the service account has been added in a group which has access to the sql server, if I let the account in the group everyone has access to the report (The rights are not delegated) and if I removed the account from this group, no one has access to the report...

In the data gateway configuration, I selected USE SSO via Kerberos for DirectQuery queries, but it is changed nothing

And if I test the single sign on (SSO) in power BI Services with an user who has access to the database via it returns:

 

The on-premise data gatewau service account failed to impersonnater the user

DW_GWPipeline_Gateway_ImpersonationError

 

Any idea of what I could try ?

 

Many thanks for your help 🙂

 

1 Reply