Forum Discussion
Gateway with different creds to Datasource
- Anonymous8 years ago
Easiest way is to think of it like this:
While you are in Power BI Desktop, you have some locally stored credentials that are used to make the connection. If you save your PBIX file and pass it to someone else, the credentials are not stored in the PBIX file itself, but in the local cache of your Power BI Desktop application. This new person would need to enter their own credentials to access the DirectQuery data, or run a refresh (Import).
When you publish to the Power BI Service, again no credentials are sent along with the file. Since the cloud is outside your network, unless your data source is also in the cloud, it has no direct connection to your data source.
An On-Premise Data Gateway acts as a secure bridge. It gets installed on hardware inside your network and you make a specific connection to the Office 365 tenant. Under "Manage Gateways" in the Power BI Service, you can add Data Sources, their credintials, and which users can access this data source. This is now avaiable to be used by any project that contains that data source and is being configured by someone on the access list. (small note, a project that wants to use a gateway needs to ensure that every data source is within the gateway, or is a cloud data source).
When you go into the "Schedule Refresh" of your Power BI Dataset on the Service, you must select a gateway. If its configured correctly you will see it appear in the gateway listing. Whenever this refreshes (import) or connects (direct query), it will talk only to the gateway. The gateway itself will handle the authentication and passing the data between the cloud and your network. The report itself doesn't need any credentials.
The credentials while in the cloud are all managed via "Manage Gateways" and work irrespective of how you publish a project/dataset into the Power BI Service.
No I have my domain admin creds there. This is my problem, if I run as and use my domain admin creds then I can't publish to my persoanl gateway because it puts it to the wrong O365 acocunt (although power BI desktop is fine).
maybe it just can't be done..
When you say publish, do you mean publish to your 'My Workspace'? I think i've been confused this whole time because you've been using the term 'Personal Gateway', which is a software program you could load into your computer to act as a bridge between the office 365 cloud and your internal network. The main version that is used now is the On-Premise Data Gateway, which can handle the personal setting.
When you publish a project, you are publishing to the Power BI Service, you don't publish to a gateway. Once your report and dataset is within the Power BI Service, you might need a gateway to connect the Office 365 dataset to your on-premise data source. That is where the gateway comes in and that is where you load in credentials to handle what user account that is. This account can be different to the account that owns the personal workspace.
- Anonymous8 years agoNot applicable
Easiest way is to think of it like this:
While you are in Power BI Desktop, you have some locally stored credentials that are used to make the connection. If you save your PBIX file and pass it to someone else, the credentials are not stored in the PBIX file itself, but in the local cache of your Power BI Desktop application. This new person would need to enter their own credentials to access the DirectQuery data, or run a refresh (Import).
When you publish to the Power BI Service, again no credentials are sent along with the file. Since the cloud is outside your network, unless your data source is also in the cloud, it has no direct connection to your data source.
An On-Premise Data Gateway acts as a secure bridge. It gets installed on hardware inside your network and you make a specific connection to the Office 365 tenant. Under "Manage Gateways" in the Power BI Service, you can add Data Sources, their credintials, and which users can access this data source. This is now avaiable to be used by any project that contains that data source and is being configured by someone on the access list. (small note, a project that wants to use a gateway needs to ensure that every data source is within the gateway, or is a cloud data source).
When you go into the "Schedule Refresh" of your Power BI Dataset on the Service, you must select a gateway. If its configured correctly you will see it appear in the gateway listing. Whenever this refreshes (import) or connects (direct query), it will talk only to the gateway. The gateway itself will handle the authentication and passing the data between the cloud and your network. The report itself doesn't need any credentials.
The credentials while in the cloud are all managed via "Manage Gateways" and work irrespective of how you publish a project/dataset into the Power BI Service.
- UserInterface8 years agoAdvocate I
If your confused its definatly my fault :)
My understanding is that when I publish to my workspace it will be useless without a gateway that hold the datasource information. So basicly it would all be blank because O365 has no way to see the data without the gateway (like a template thats got no data).
So I am trying to publish my report using my domain user creds (so it goes to my O365 workspace) but then have the datasource (which I thought was stored on the gateway) connect using my domain admin details as that is what has access to the SQL.I'm now assuming that most of that is wrong.. haha
- UserInterface8 years agoAdvocate I
Actually, i'm sure what I am trying to do just can't be done now.
- UserInterface8 years agoAdvocate I
I'm still wrapping my head around part of that but most I get.
I have a gateway running on my local machine (testing) and it says that it is connected and can see outside, but O365 doesn't see it. For this reason I haven't managed to see what settigs are avalible in manage gateway.
So this part "Under "Manage Gateways" in the Power BI Service, you can add Data Sources, their credintials, and which users can access this data source. ", dosen't seem possible to me.Agaiin, I thought that by entering in my email address when creating to connector that was all that is required to have it show in O365.
I think i need to have a play with some different sources (where i can use my domain user account) so that I can see what should be happening..
- Anonymous8 years agoNot applicable
Do you have this option in your Power BI Service? (Click Cog Icon)
- UserInterface8 years agoAdvocate I
Yes but it shows the error above (top one) 'You don't have any gateways' even though I can see that my gateway says connected.
Maybe its a networking issue (even though it says connected). I might see if I can dig into that further.
Screen below to show you what i see. In red is the service (app.powerbi.com) and on top is my gateway showing all is OK. Also checked the logs and they all say connected.
- Anonymous8 years agoNot applicable
The account you used to register the gateway is the same account you use to log onto Office365/Power BI?
- UserInterface8 years agoAdvocate I
Yep.. i think i'll have to have a good dig into it.
Initially i thought it was just going to be as simple as adding creds somewhere. Now i'm thinking it could be anything.
I might try an push them to set up a full gateway, with DB rights.. Maybe if I get off the personal one it will fix it. - UserInterface8 years agoAdvocate I
I think that I have convinced them to put in a proper managed gateway somewhere so i'll let this drop and start pushing them for that.
Thanks for all your help!
- Anonymous7 years agoNot applicable
What about connecting via gateway to Teradata? Each user in our warehouse has different AD group access which drives their security. Query banding so to speak.
So if I set up a gateway with my credentials and I have high access, everyone will also receive high. How do you pass through credentials to a gateway?
- inshanemagic2 years agoFrequent Visitor
This was super helpful and very simple to understand! Thanks!