Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Level up your Power BI skills this month - build one visual each week and tell better stories with data! Get started

Reply
manoj_0911
Advocate V
Advocate V

Request for Historical Power BI Service Tag IP Ranges (Last 12 Months)

Request for Historical Power BI Service Tag IP Ranges (Last 12 Months)

 

We are troubleshooting connectivity between Power BI Service and Snowflake and need to understand IP range stability.

Request:

  • Historical Service Tag data for “PowerBI” (or AzureCloud) for the past 12 months

  • Specifically for regions:

    • East US 2

    • North Central US

Purpose:

  • To validate whether outbound IP ranges used by Power BI Service have changed over time

  • To assess firewall whitelisting strategy

If historical data is not available, please confirm:

  • Whether Power BI outbound IP ranges are expected to change frequently

  • Recommended best practice for firewall whitelisting (Service Tags vs static IPs vs gateway)

1 ACCEPTED SOLUTION
Shai_Karmani
Resolver IV
Resolver IV

Microsoft does not publish a historical archive of the PowerBI service tag, only the current weekly JSON snapshot is available, so getting 12 months of past data after the fact is not possible. The IPs in that tag are explicitly subject to change and do drift, which is exactly why pinning them in a firewall is discouraged.

For Power BI Service connecting to Snowflake, the better pattern is to control the egress yourself rather than chasing the service IPs. A VNet or on-prem data gateway makes traffic exit from a single fixed IP that you can whitelist cleanly. If your firewall supports Azure Service Tags directly (Azure Firewall, NSG), reference the PowerBI tag rather than extracted IPs so it auto-updates. Snowflake Private Link with a VNet data gateway is the cleanest long term answer because it removes the service tag question entirely.

If this helped, a thumbs up and accepting the solution would be appreciated.

Best,
Shai Karmani

View solution in original post

1 REPLY 1
Shai_Karmani
Resolver IV
Resolver IV

Microsoft does not publish a historical archive of the PowerBI service tag, only the current weekly JSON snapshot is available, so getting 12 months of past data after the fact is not possible. The IPs in that tag are explicitly subject to change and do drift, which is exactly why pinning them in a firewall is discouraged.

For Power BI Service connecting to Snowflake, the better pattern is to control the egress yourself rather than chasing the service IPs. A VNet or on-prem data gateway makes traffic exit from a single fixed IP that you can whitelist cleanly. If your firewall supports Azure Service Tags directly (Azure Firewall, NSG), reference the PowerBI tag rather than extracted IPs so it auto-updates. Snowflake Private Link with a VNet data gateway is the cleanest long term answer because it removes the service tag question entirely.

If this helped, a thumbs up and accepting the solution would be appreciated.

Best,
Shai Karmani

Helpful resources

Announcements
April Power BI Update Carousel

Power BI Monthly Update - April 2026

Check out the April 2026 Power BI update to learn about new features.

Fabric SQL PBI Data Days

Data Days 2026 coming soon!

Sign up to receive a private message when registration opens and key events begin.

New to Fabric survey Carousel

New to Fabric Survey

If you have recently started exploring Fabric, we'd love to hear how it's going. Your feedback can help with product improvements.

Power BI DataViz World Championships carousel

Power BI DataViz World Championships - June 2026

A new Power BI DataViz World Championship is coming this June! Don't miss out on submitting your entry.