Forum Discussion

nickwild's avatar
nickwild
Regular Visitor
5 months ago

Cross-tenant Power BI issue – Desktop cannot see external workspace / thin reports cannot bind

This is a cross-tenant Power BI / Entra B2B scenario involving a franchisor setup with RLS.

Context

We provide reporting for a franchisor where each franchisee only sees their own data via RLS (email-based).

Originally:

  • Reports hosted in our tenant

  • Franchisees added as B2B guests

Issue: their Power BI licences in their home tenant are not recognised, so they cannot access reports unless licensed in our tenant

To avoid this, we moved everything to the client tenant.


Current setup (client tenant)

  • Semantic model (dataset) deployed successfully

  • API ingestion + refresh working

Workspace permissions correctly assigned

All good so far.


Problem

We cannot deploy or connect thin reports.

  1. Power BI Desktop issue

    • Logged in with account that has access to client tenant

    • Can see workspace in Power BI Service (browser)

    • BUT Desktop only shows home tenant workspaces

    • Client tenant workspace / dataset not visible

    • Thin report issue

      • Existing thin PBIX files cannot be uploaded (security errors)

      • Cannot rebind to new dataset

Cannot connect Desktop to semantic model to recreate reports


Key question

Is this:

  • a limitation of Power BI Desktop with cross-tenant access?

  • a Fabric / tenant setting (B2B / external semantic model sharing) issue?

or are thin reports not supported across tenants at all?


Goal

We want a standard architecture:

 

 
Client Tenant
Workspace
├ Semantic Model
├ Thin Reports
└ RLS per franchisee
 

Without needing to:

  • license users in our tenant

  • rebuild every report manually


Any guidance appreciated

Particularly interested if anyone has:

  • successfully deployed thin reports across tenants

  • used external semantic model sharing (Fabric) in this scenario

  • or knows why Desktop does not surface external tenant workspaces

6 Replies

  • Hi nickwild 

     

    There was some great suggestions by Miguel. What I also typically recommend to customers is it is very painful when doing cross tenant sharing and authentication and ideally it solves a lot of issues and headaches if you have accounts in the tenant where the semantic models are stored. Just some friendly advice to avoid a whole lot of headaches and wasted time.

    • nickwild's avatar
      nickwild
      Regular Visitor

      Thanks for your reply GilbertQ yes I quite agree and that was what we were trying to resolve by transferring over the reports in our account to the clients without having to re-athour them (hence trying to log on to the other tenant with PowerBI desktop).

      We do not want the volume of clientn licenses in our account for billing purposes so just trying to find a working solution. We may have fixed it, but stil not quite sure yet 😊

      Thanks for your advice it is much appreciated

  • Hi nickwild,

     

    Based on my previous experience Power BI thin reports are supported in cross-tenant access however the way you acces the other tenant is very important, when you login to the Power BI desktop app you must select the sign in option at the boottom of the sign in panel and then sign in to an organisation and then enter the domain after this the login will be done with the necessary email account:

     

     

     

    Be aware that based on my experience I have had troubles that the login is asked several times while you are login, so in the middle of a work session you may need to login again but at that time you only need the email and password not the domain again.

     

    When you want to return to your tenant just logout and then do the normal login.

     

    One question concerning the thin reports that you already have and are built on top of your tenant if you try to open then logged in to your customer tenant they will not open so you will have a bit of an issue to solve it you just need to use the new PBIP format (project) and then edit the connection string to the correct one. If you need some guidance on this please let me know.

    • nickwild's avatar
      nickwild
      Regular Visitor

      Hi MFelix ,

       

      Thanks for your response. This is realy helpful and did indeed help me to log in to the other tenant. However I was doing this to try to fix my core problem I mentioned in the context which this has not solved.

      My main issue mentioned in the orginal context 

      We provide reporting for a franchisor where each franchisee only sees their own data via RLS (email-based).

      Originally:

      • Reports hosted in our tenant

      • Franchisees added as B2B guests

      Issue: their Power BI licences in their home tenant are not recognised, so they cannot access reports unless licensed in our tenant.

      These licenses in the the client's own tenant (issued to both ms and non-ms email addresses registered as members ) were not been seen. 

       

      I think in retrospect this may have been to do with the location of the User not being populated, but although they are now working I am not sure if this is because of the trial linceses for Powerbi that the client gets for signing up or whether they are still not been seen properly.

      I am not sure whether you have any thoughts on this?

      Many thanks again for your advice

  • Anonymous's avatar
    Anonymous
    Not applicable

    Hi nickwild,

     

    Thank you for reaching out to the Microsoft Fabric Forum Community, and special thanks to MFelix and GilbertQ  for prompt and helpful responses.

    Just following up to see if the Response provided by community members were helpful in addressing the issue. if the issue still persists Feel free to reach out if you need any further clarification or assistance.

     

    Best regards,
    Prasanna Kumar