Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Earn a 50% discount on the DP-600 certification exam by completing the Fabric 30 Days to Learn It challenge.

Reply
mjfulke
Employee
Employee

More information on encryption methods used by the Enterprise Gateway

Hello,  

 

I need to provide more detailed information on how the enterprise gateway securely transmits data over servicebus.  Before the security team will approve use of the Enterprise Gateway we need more about the methods and protocols used on the non-standard ports

 

Information provided at https://powerbi.microsoft.com/en-us/documentation/powerbi-gateway-enterprise/#ports is good but they need to know specifically what is being used to encrypt communication over 9350-9354 and more details about AMQP over 5671-5672 (is it using Kerberos and SSL). The more detail the better...   Thank you

4 REPLIES 4
Greg_Deckler
Super User
Super User

Oh, one other thing, and I believe it is on port 9350 but may have that specific port wrong, but if you see data going to Brazil over that port, that is likely telemetry data and you can turn that off when you configure the gateway.


Follow on LinkedIn
@ me in replies or I'll lose your thread!!!
Instead of a Kudo, please vote for this idea
Become an expert!: Enterprise DNA
External Tools: MSHGQM
YouTube Channel!: Microsoft Hates Greg
Latest book!:
The Definitive Guide to Power Query (M)

DAX is easy, CALCULATE makes DAX hard...

Thanks for your reply.

Greg_Deckler
Super User
Super User

Here are a few things to consider looking at:

 

  1. Reference link to the trust center article. It is a listing of ISO, HIPAA and other security/privacy certifications of Power BI by independent auditors: https://powerbi.microsoft.com/en-us/blog/power-bi-added-to-microsoft-trust-center/
  2. Power BI Security article with the link to whitepaper: https://powerbi.microsoft.com/en-us/documentation/powerbi-admin-power-bi-security/
  3. Local Enterprise Gateway service communicates with Power BI Service via secure connection to a designated range of IP addresses.  The Gateway creates outbound connection to Azure Service Bus and there are no inbound ports.  You can find more details here: https://powerbi.microsoft.com/en-us/documentation/powerbi-gateway-enterprise/#Ports
  4. I know that the Power BI team is available for deep dives on the Enterprise Gateway, you might try contacting Sergei Gundorov, sergeig@microsoft.com, and ask if you could set one up. 

Follow on LinkedIn
@ me in replies or I'll lose your thread!!!
Instead of a Kudo, please vote for this idea
Become an expert!: Enterprise DNA
External Tools: MSHGQM
YouTube Channel!: Microsoft Hates Greg
Latest book!:
The Definitive Guide to Power Query (M)

DAX is easy, CALCULATE makes DAX hard...

One other tidbit of information, and this is specific to iOS but perhaps similar encryption methods are used by the gateway, for the iOS app,

 

  • Local cache of security tokens are encrypted by ADAL and OS (Keychain in particular).
  • Local cache of other stuff is encrypted as long as Intune enforces overall drive encryption.

Follow on LinkedIn
@ me in replies or I'll lose your thread!!!
Instead of a Kudo, please vote for this idea
Become an expert!: Enterprise DNA
External Tools: MSHGQM
YouTube Channel!: Microsoft Hates Greg
Latest book!:
The Definitive Guide to Power Query (M)

DAX is easy, CALCULATE makes DAX hard...

Helpful resources

Announcements
RTI Forums Carousel3

New forum boards available in Real-Time Intelligence.

Ask questions in Eventhouse and KQL, Eventstream, and Reflex.

MayPowerBICarousel

Power BI Monthly Update - May 2024

Check out the May 2024 Power BI update to learn about new features.

LearnSurvey

Fabric certifications survey

Certification feedback opportunity for the community.

Top Solution Authors
Top Kudoed Authors