Forum Discussion

kvnbn's avatar
kvnbn
Advocate I
2 months ago
Solved

Embed Power BI App for guest user

My company serves reports through Apps to our internal employees and external customers, who we register in our Entra ID directory as guest users. People access the App via Power BI Service or the embedded tab on Teams. One of our customers wants to embed the report in their custom application. They are fine with the user owns data model in which end users need to log into Power BI.

 

It is best practice to only share content via a Power BI App, but embedding is not supported for Power BI Apps. Is granting Read permission on the report and providing the "Securely embed this report in a website or portal" iframe the only way that I can request my customer's request? What are the implications of granting Read access to the customer? I understand that this grants them Read access to the semantic model, which is fine because of RLS. I want to know if I am missing anything before proceeding.

 

To reiterate, we are not interested in the app owns data model at this time.

  • Hi,

     

    Yes, for a user owns data scenario, granting Read access to the report and using the "Securely embed" option is typically the correct approach.

     

    A few things to verify before proceeding:

     

    • Guest users must have the appropriate Power BI license, or the workspace must be in Premium/Fabric capacity.
    • Your tenant settings must allow guest access, external sharing, and embedding content in applications.
    • RLS will still be enforced, so users only see the data they're permitted to access.
    • If you only want users to view the report, grant Read access only and avoid Build permissions.
    • Remember that users with direct report access can also open the report in Power BI Service, not just through the embedded application.

     

    Other than those considerations, you're not missing any major concerns. This is the standard approach when you want embedding without moving to an app owns data model.

     

    Hope this helps!!

     

    Thanks!

3 Replies

  • Hi,

     

    Yes, for a user owns data scenario, granting Read access to the report and using the "Securely embed" option is typically the correct approach.

     

    A few things to verify before proceeding:

     

    • Guest users must have the appropriate Power BI license, or the workspace must be in Premium/Fabric capacity.
    • Your tenant settings must allow guest access, external sharing, and embedding content in applications.
    • RLS will still be enforced, so users only see the data they're permitted to access.
    • If you only want users to view the report, grant Read access only and avoid Build permissions.
    • Remember that users with direct report access can also open the report in Power BI Service, not just through the embedded application.

     

    Other than those considerations, you're not missing any major concerns. This is the standard approach when you want embedding without moving to an app owns data model.

     

    Hope this helps!!

     

    Thanks!

  • Hi. That's not the only way. Its app owns data available too. If you are using a license by capacity (fabric, power bi embedded) then you can create a custom web app to embed power bi. You can own the login creating custom login for the external users. They won't need a license and they can be any number of users. The capacity license is applied to the workspaces of the reports you want to show.

    If you don't have a dev team to work in a solution like this, you can check on google there are solutions already done by microsoft partners like https://pibi.com.ar

    You can read more about that here: https://learn.microsoft.com/en-us/power-bi/developer/embedded/embedded-analytics-power-bi

    If you just want to go with users own data then SamInogic explains it very good.

    I hope that helps,

  • v-achippa's avatar
    v-achippa
    Community Support

    Hi kvnbn,

     

    Thank you for reaching out to Microsoft Fabric Community.

     

    Thank you SamInogic and ibarrau for the prompt response.

     

    As we haven’t heard back from you, we wanted to kindly follow up to check if the solution provided by the user's for the issue worked? or let us know if you need any further assistance.

     

    Thanks and regards,

    Anjan Kumar Chippa