EnableYourData.nl

Resources · Power BI

What is Power BI Embedded?

Power BI Embedded is the way to show Power BI reports and dashboards in your own application, website or portal, instead of in Microsoft's Power BI service. There are two variants: embedding for your organisation, where users sign in with their own Microsoft account, and embedding for your customers, where the application handles access through a service principal and end users do not need a Power BI licence. For that second variant, you need capacity in production.

Key takeaways

  • Power BI Embedded shows Power BI reports in your own application or portal, with the interactivity of Power BI.
  • When embedding for your organisation, users sign in with their own Microsoft Entra account and need their own permissions and an appropriate licence.
  • When embedding for your customers, the application handles access through a service principal; end users do not need a Power BI account.
  • To embed for customers in production, you need a Power BI Embedded or Microsoft Fabric capacity.
  • Publish to web makes a report public and is never suitable for business data.

Power BI Embedded at a glance

Power BI Embedded is the umbrella term for Microsoft's options for showing Power BI reports, dashboards and individual visuals in your own application. Users then do not work in the Power BI service, but in your portal, intranet or software product. Filtering, drilling through and moving between pages work just as they do in Power BI itself.

Technically, it works like this: your application's server signs in to Microsoft Entra ID and requests an embed token through the Power BI REST API. That token is short-lived and only valid for the reports and semantic models you specify. The browser then loads the report with the Power BI JavaScript library. Secrets, such as the application's password, stay on the server.

Note: Microsoft also uses "Power BI Embedded" as the name of the capacity you buy through Azure. This article is mainly about the technology and the choices you make.

Embedding for your organisation or for your customers

Microsoft distinguishes two scenarios. When embedding for your organisation ("user owns data"), each user signs in with their own Microsoft Entra account, and Power BI itself checks whether that person may see the report. When embedding for your customers ("app owns data"), only the application signs in to Microsoft. Your application then decides who gets to see which report and which data.

The key difference lies in responsibility. In the first scenario, Microsoft handles access; in the second, your application is the gatekeeper, and sign-in, permissions and filtering all have to be right there.

Embedding for your organisationEmbedding for your customers
Also known asUser owns dataApp owns data
Who signs in to MicrosoftEvery user, with their own Microsoft Entra accountOnly the application, through a service principal
End-user licenceAn appropriate Power BI licence, depending on your licensing modelNo Power BI licence needed
Who controls accessThe permissions in the Power BI serviceYour application, with roles and RLS in the embed token
Typical useIntranet, SharePoint, internal toolsCustomer portal, SaaS product, portal for suppliers or franchisees
Capacity neededNot necessarilyYes, for production

The role of the service principal

A service principal is the identity of an application in Microsoft Entra ID. You create an app registration and receive a client ID and a secret or certificate. Your application uses these to sign in, without involving a personal account.

For a service principal to work with Power BI, an administrator must allow service principals to use the Power BI and Fabric APIs in the tenant settings, preferably restricted to a security group. You then add the service principal to the workspaces containing the reports you want to embed. Microsoft recommends a service principal over a master user account with a username and password. When setting it up, pay attention to these points:

  • Store the secret only on the server and encrypted, never in the browser or in the source code.
  • Give the service principal access only to the workspaces it genuinely needs.
  • Let secrets expire and renew them in good time, so that a leaked secret cannot be used indefinitely.
  • Use a separate service principal per customer or environment if you want to keep customers strictly separated.

Capacity and licences in broad terms

To embed for your customers in production, the content must be in a workspace assigned to a capacity: reserved computing power in Microsoft's cloud. That can be a Power BI Embedded capacity through Azure or a Microsoft Fabric capacity.

Without capacity, you can develop and test with a Power BI Pro licence, but the number of embed tokens is then limited and not intended for production. Anyone who creates and publishes reports still needs their own licence as well, such as Power BI Pro.

How large the capacity needs to be depends on the number of concurrent users, the size of your semantic models and how often you refresh. Microsoft regularly changes its licences and product names, so always check the current documentation before you make a choice.

When do you need Power BI Embedded?

If you only work with an internal team that already has Power BI licences, sharing through the Power BI service or a Power BI app is usually simpler. Embedding then mainly adds development and maintenance work.

Power BI Embedded becomes worthwhile as soon as you want to show reports outside the Power BI service, or to people outside your organisation. Typical situations:

  • You want to share dashboards with customers, suppliers, franchisees or other external parties who do not have an account in your Microsoft environment.
  • You want to show reports in your own portal or product, in your own branding and alongside other features.
  • You have many readers who only view reports, which makes a licence per person impractical.
  • Each external party may only see its own figures, which you handle with row-level security in the embed token.

Alternatives: Publish to web and sharing in the Power BI service

Publish to web creates a public link or embed code. Anyone with that link can see the report without signing in. Links can be forwarded or found, and Microsoft itself warns that this option is not intended for confidential information. So never use it for business data. An administrator can switch the feature off in the tenant settings.

Sharing in the Power BI service, through a sharing link, a workspace or a Power BI app, is the standard for internal reporting. Everyone then needs an account in your Microsoft Entra ID, as an employee or as a guest user, and an appropriate licence.

For an intranet or SharePoint page, you can also use secure embed: viewers then have to sign in and have permission to view the report. That is useful for internal pages, but it is not a solution for external customers.

Build it yourself or use an existing portal

If you build customer embedding yourself, you need more than an embed token: your own sign-in, preferably with two-factor authentication, user management, a link between users and Power BI roles, token renewal, logging and monitoring of refreshes.

ENABLE from Data Analytics B.V. is such an existing portal. Power BI reports are shown in it through Power BI Embedded, with a Microsoft Entra service principal that you configure per customer; the secret is stored encrypted. Access profiles determine who sees which dashboards, row-level security filters the data per user and the activity log also records embed sessions.

FAQ

Frequently asked questions

What is Power BI Embedded?

Power BI Embedded is the way to show Power BI reports and dashboards in your own application, website or portal. Your application requests a short-lived embed token through the Power BI REST API and uses it to load the report in the browser.

Do users need a Power BI licence with Power BI Embedded?

That depends on the scenario. When embedding for your customers (app owns data), end users do not need a Power BI licence, because the application signs in and the organisation buys capacity. When embedding for your organisation, users sign in themselves and need an appropriate licence.

What is the difference between Power BI Embedded and Publish to web?

Publish to web makes a report public: anyone with the link can view it without signing in. With Power BI Embedded, your application decides who gets access and everything works with short-lived tokens, optionally with row-level security per user. Only the latter is suitable for business data.

What is a service principal in Power BI?

A service principal is the identity of an application in Microsoft Entra ID. An application uses it to sign in to Power BI without a personal account, for example to request embed tokens. An administrator must allow service principals to use the Power BI APIs, and the service principal must have access to the workspace.

Does row-level security work with Power BI Embedded?

Yes. When embedding for your customers, the application passes an effective identity in the embed token: a username, one or more roles and, optionally, an extra value for CUSTOMDATA(). Power BI applies the RLS rules of the semantic model for that identity.

Do I need capacity for Power BI Embedded?

For embedding for your customers in production, yes: the content must be in a workspace on a Power BI Embedded or Fabric capacity. For development and testing, you can use a limited number of embed tokens with a Pro licence.

Share securely, live fast, no headache

In an online demo we show you the portal: dashboards per role, row-level security, plain-language questions and how we set it up and manage it for you.