Key takeaways
- Publish to web makes a report public to anyone with the link and is never suitable for business data.
- For colleagues, a Power BI app in the Power BI service is usually the clearest way to share.
- For a small number of regular external partners, B2B guest users in Microsoft Entra ID work well.
- For many external users, your own branding and separate figures per customer, a customer portal with Power BI Embedded is the right fit.
- Row-level security only applies to viewers; workspace Members, Contributors and Admins see all data.
Four ways to share a Power BI dashboard
If you want to share a Power BI dashboard, you have roughly four options. They differ in who can view it, whether viewers have to sign in, which licence the viewer needs and who manages access. The table gives an overview; the sections that follow explain what to look out for with each option.
| Option | Who can view | Sign-in | Viewer licence | Suitable for |
|---|---|---|---|---|
| Publish to web | Anyone with the link | No | None | Only public, non-sensitive data |
| Sharing or an app in the Power BI service | Colleagues in your own tenant | Yes, with a Microsoft account | Pro or Premium Per User, or content in a suitable capacity | Internal reporting |
| B2B guest users | External users you invite as guests | Yes, with their own account as a guest | Pro or Premium Per User, or content in a suitable capacity | A few regular external partners |
| Embedded portal (Power BI Embedded) | Users the portal admits | Yes, in the portal | None; the organisation buys capacity | Customers, suppliers, franchisees |
Publish to web: public, so not for business data
Publish to web produces a link and an embed code that let anyone view the report without signing in. There is no control over who views it, links can be forwarded and embedded pages can be found by search engines. You cannot even publish reports with row-level security this way.
Only use this option for data you would also put on your website, such as public statistics. As an administrator, you can switch the feature off in the tenant settings or restrict it to a small group. In the Power BI admin portal, under Embed codes, you can see which reports have already been published publicly. Check that list regularly.
Sharing within your organisation through the Power BI service
For colleagues, you share in the Power BI service. You can share a report directly through a link, give someone a role in a workspace, or publish a Power BI app with one or more audiences. For wide distribution, an app is the clearest option: creators work in the workspace, readers only get the app.
Viewers need a Power BI Pro or Premium Per User licence, unless the content is in a sufficiently large Premium or Fabric capacity. Do not give readers the Member, Contributor or Admin role in the workspace: row-level security only applies to the Viewer role. Be sparing with sharing links for "People in your organization" too; they often reach further than intended.
Sharing Power BI with external users through B2B guest users
With Microsoft Entra B2B, you invite an external user as a guest in your own tenant. The guest signs in with their own work account or with a one-time passcode sent by email, and then sees the apps and reports you share with them. An administrator does have to allow external sharing in the Microsoft Entra ID and Power BI settings.
Guests also need an appropriate licence: their own Pro licence from their organisation, a licence you assign, or content in a suitable capacity. B2B works well for a limited number of regular partners. With dozens or hundreds of customers, management becomes heavy: guest accounts pile up, access remains when a partnership ends and users see Microsoft's environment instead of your branding.
A Power BI customer portal with Power BI Embedded
A Power BI customer portal is your own web environment in which external users sign in and see their dashboards. The portal uses Power BI Embedded in the "embed for your customers" scenario: it requests an embed token on the user's behalf, containing the identity and role for row-level security. End users do not need a Power BI licence; the organisation does buy capacity.
The advantage is scale and control. You can admit many users, filter the data per customer and show the portal in your own branding. The downside is that security depends entirely on the portal: sign-in, permissions, RLS mappings and logging all have to be properly handled there.
ENABLE is an example of such a portal. Users are invited by email and sign in with two-factor authentication, access profiles determine which dashboards someone sees and row-level security links users to Power BI roles. Client administrators can see in the activity log who did what.
Risks of sharing Power BI dashboards
The biggest risks usually lie not in Power BI itself, but in the way you share. Pay particular attention to these points:
- Public links through Publish to web that expose business data.
- Sharing links for the whole organisation, so that reports reach further than intended.
- Exports to Excel, PDF or PowerPoint that live on outside Power BI; administrators can restrict export options.
- Readers with the Member, Contributor or Admin role in the workspace, for whom row-level security does not apply.
- Guest accounts that remain after a partnership has ended.
- A custom portal that falls back to an unfiltered report when a user has no role.
- One shared account for several people: you no longer know who has seen what, and it does not fit Microsoft's licensing model, which works per user.
How to choose the right way to share
Whichever option you choose, test what a user actually sees before going live, check the export settings and schedule a regular review of who still has access. As a rule of thumb:
- Colleagues only: publish a Power BI app and use row-level security if not everyone may see everything.
- A few regular external partners who use Microsoft 365 themselves: invite them as B2B guest users.
- Many external users, your own branding and separate figures per customer: choose a customer portal with Power BI Embedded, built in-house or as an existing platform.
- Truly public figures: Publish to web is an option, used deliberately and with the administrator's approval.