Forum Discussion
gateway connection to dynamically take up user credentials
Customer has connected SAP Datasphere to Power BI Service using ODBC connector and On-premises Data Gateway.
Previously, the connection used a shared service account configured on the gateway.
SAP has now requested a move to user-based authentication, where each Power BI user should access SAP Datasphere using their own SAP credentials.
The customer has different SAP access permissions for different users (similar to source-system security/RLS concepts), and they want user-specific access to be enforced based on the logged-in user.
- Customer has many users like 100 users and does not want to create 100 gateway connections to SAP using ODBC connector. They would like to create few connections with gateway that would dynamically take each user's credentials when they would use the connection.
The requirement is not just data filtering; the customer is looking for user-level authentication/pass-through, where the connection dynamically uses the individual user's SAP identity rather than a shared technical account.
Based on Microsoft documentation, standard ODBC gateway connections use credentials stored on the gateway data source. Generic ODBC data sources are not listed among Power BI gateway SSO-supported data sources for user identity passthrough.
Just wanted to check if there is any possibility for such setup where the gateway connection credentials can be changed dynamically as per user credentials.
Hi Poulami
Currently it is not possible for the gateway to dynamically change the user credentials as they come through. The only way to do this is to create a single connector and use single Sign on, which will then pass the user's credentials through to the underlying data source.
2 Replies
- GilbertQSuper User
Hi Poulami
Currently it is not possible for the gateway to dynamically change the user credentials as they come through. The only way to do this is to create a single connector and use single Sign on, which will then pass the user's credentials through to the underlying data source.