Forum Discussion
PBI sharing with external users!!!
- 4 years ago
It is, and licensing needs vary. I suggest you start here - Share Power BI reports and dashboards with coworkers and others - Power BI | Microsoft Docs
dear edhans ,
maybe you can answer that question rightaway: if I share the report by sending the link via email to an external person, who does not exist in my AAD at all. Can that person access the report?
I have a premium workspace.
I go to the report - share - email --> outlook: I enter the external email address.
That person is not in our Azure AD at all, not as guest, nothing, never been invited.
What happens? Does that person login to Power BI and can see the report? Is that person in my AAD then automatically a guest? Or still, need to be invited first?
Sorry but I can't walk through the full test myself. What I found interesting is that when I go to the report --> share --> enter there the email first time, it tells me that I cannot share outside my organization. So I click the email button and send the link by email. When I go again to the share the report, I enter the same email and there is no more message, I can share directly, but still that email is not in my AAD. Hopefully I don't confuse you with all the text, my main question is above 🙂
BR, Roman
When you share data with an external user, they get added to the AAD as a guest if you have permissions to share and guest sharing is enabled. THey will have to authenticate. MS will usually send them a separate code to their email. It prevents that recipient from forwarding the URL to someone else. If the 3rd person clicks on the link, the authentication from MS goes back to the original guest, not whomever has the link. But it depends on what your Office 365 admin and Power BI admin have enabled in the various and overlapping sharing permissions for your tenant.
- romgut4 years agoAdvocate III
Thank you so much!
I checked our settings and in our tenant everything related to AAD guests / Invite externals is enabled to entire organization, except editing, it's enabled for a specific security group only.
From your answer I understood that with those settings, it's enough to send the link to an external person. The AAD entry will happen in the background (that would be the best case for me). Is that corect?