Forum Discussion
Gateway with different creds to Datasource
- Anonymous8 years ago
Easiest way is to think of it like this:
While you are in Power BI Desktop, you have some locally stored credentials that are used to make the connection. If you save your PBIX file and pass it to someone else, the credentials are not stored in the PBIX file itself, but in the local cache of your Power BI Desktop application. This new person would need to enter their own credentials to access the DirectQuery data, or run a refresh (Import).
When you publish to the Power BI Service, again no credentials are sent along with the file. Since the cloud is outside your network, unless your data source is also in the cloud, it has no direct connection to your data source.
An On-Premise Data Gateway acts as a secure bridge. It gets installed on hardware inside your network and you make a specific connection to the Office 365 tenant. Under "Manage Gateways" in the Power BI Service, you can add Data Sources, their credintials, and which users can access this data source. This is now avaiable to be used by any project that contains that data source and is being configured by someone on the access list. (small note, a project that wants to use a gateway needs to ensure that every data source is within the gateway, or is a cloud data source).
When you go into the "Schedule Refresh" of your Power BI Dataset on the Service, you must select a gateway. If its configured correctly you will see it appear in the gateway listing. Whenever this refreshes (import) or connects (direct query), it will talk only to the gateway. The gateway itself will handle the authentication and passing the data between the cloud and your network. The report itself doesn't need any credentials.
The credentials while in the cloud are all managed via "Manage Gateways" and work irrespective of how you publish a project/dataset into the Power BI Service.
If your confused its definatly my fault :)
My understanding is that when I publish to my workspace it will be useless without a gateway that hold the datasource information. So basicly it would all be blank because O365 has no way to see the data without the gateway (like a template thats got no data).
So I am trying to publish my report using my domain user creds (so it goes to my O365 workspace) but then have the datasource (which I thought was stored on the gateway) connect using my domain admin details as that is what has access to the SQL.
I'm now assuming that most of that is wrong.. haha
Actually, i'm sure what I am trying to do just can't be done now.
- UserInterface8 years agoAdvocate I
I'm still wrapping my head around part of that but most I get.
I have a gateway running on my local machine (testing) and it says that it is connected and can see outside, but O365 doesn't see it. For this reason I haven't managed to see what settigs are avalible in manage gateway.
So this part "Under "Manage Gateways" in the Power BI Service, you can add Data Sources, their credintials, and which users can access this data source. ", dosen't seem possible to me.Agaiin, I thought that by entering in my email address when creating to connector that was all that is required to have it show in O365.
I think i need to have a play with some different sources (where i can use my domain user account) so that I can see what should be happening..
- Anonymous8 years agoNot applicable
Do you have this option in your Power BI Service? (Click Cog Icon)
- UserInterface8 years agoAdvocate I
Yes but it shows the error above (top one) 'You don't have any gateways' even though I can see that my gateway says connected.
Maybe its a networking issue (even though it says connected). I might see if I can dig into that further.
Screen below to show you what i see. In red is the service (app.powerbi.com) and on top is my gateway showing all is OK. Also checked the logs and they all say connected.
- Anonymous8 years agoNot applicable
The account you used to register the gateway is the same account you use to log onto Office365/Power BI?
- UserInterface8 years agoAdvocate I
Yep.. i think i'll have to have a good dig into it.
Initially i thought it was just going to be as simple as adding creds somewhere. Now i'm thinking it could be anything.
I might try an push them to set up a full gateway, with DB rights.. Maybe if I get off the personal one it will fix it. - UserInterface8 years agoAdvocate I
I think that I have convinced them to put in a proper managed gateway somewhere so i'll let this drop and start pushing them for that.
Thanks for all your help!