March 31 - April 2, 2025, in Las Vegas, Nevada. Use code MSCUST for a $150 discount! Early bird discount ends December 31.
Register NowBe one of the first to start using Fabric Databases. View on-demand sessions with database experts and the Microsoft product team to learn just how easy it is to get started. Watch now
We want the Azure Power BI service to refresh data from our Azure SQL databases. The Azure SQL servers are protected and don't allow all networks.
This is possible by using a Power BI Data Gateway as expalained in https://devblogs.microsoft.com/premier-developer/secure-access-to-azure-sql-servers-for-power-bi/
We have an Azure VM where we installed the on-premises Power BI data gateway. This VM is also secured and doesn't have internet access.
The server does NOT HAVE A PROXY configured.
We opened all the required ports for the gateway as requested in https://docs.microsoft.com/en-us/data-integration/gateway/service-gateway-communication#network-port...
A few telnet port tests confirmed these were open as expected.
However, before we can register a gateway we need to provide an email and login on Azure in the configuration process.
When we provide the details we can pick a user and as soon as we do an additional windows popup dialog appears to login to the STS service.
After filling in our credentials there we get an error that it failed to sign in.
We tried multiple users so we are sure it's not a question of wrong credentials.
The logs show the following:
EnterpriseGatewayConfigurator.exe Error: 0 : Error authenticating user: The browser based authentication dialog failed to complete. Reason: The server or proxy was not found..
EnterpriseGatewayConfigurator.exe Error: 0 : Exception details: MSAL.Desktop.4.18.0.0.MsalClientException:
ErrorCode: authentication_ui_failed
We cannot continue the installation from that point on.
We tried Wireshark but we could not really see which ports were missing for the communication to work.
Anyone any idea why we can't login? Do we need additional firewall openings?
Hi,
The network port tests can only be done AFTER you succesfully log in during the gateway installation, so that is not an option.
All IP adresses were opened.
For other users having issues here: we did need to add seperate IP ranges for our Power BI services region - provided by MS support - as the documentation on the MS site isn't always up to date!
In the end the issue was a policy on our side that required a domain joined machine and a login with a specific type of account with special priviliges.
Once I used that account, all went fine (and the port tests succeeded as well 😉)!
Hi @Anonymous ,
Could you tell me if your problem has been solved? If it is, kindly Accept it as the solution. More people will benefit from it.
Best Regards,
Eyelyn Qin
Hi @Anonymous ,
You could try to do these steps according to the official document :
1. Run the network ports test . If the test succeeded, your gateway successfully connected to all the required ports. If the test failed, your network environment might be blocking these required ports and servers.
2. Unblock the IP addresses.
3. Change the sign-in user to a domain user
Best Regards,
Eyelyn Qin
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.
March 31 - April 2, 2025, in Las Vegas, Nevada. Use code MSCUST for a $150 discount!
Your insights matter. That’s why we created a quick survey to learn about your experience finding answers to technical questions.
Arun Ulag shares exciting details about the Microsoft Fabric Conference 2025, which will be held in Las Vegas, NV.
User | Count |
---|---|
37 | |
22 | |
20 | |
10 | |
9 |
User | Count |
---|---|
59 | |
55 | |
22 | |
14 | |
12 |