Key takeaways
- Power BI Embedded shows Power BI reports in your own application or portal, with the interactivity of Power BI.
- When embedding for your organisation, users sign in with their own Microsoft Entra account and need their own permissions and an appropriate licence.
- When embedding for your customers, the application handles access through a service principal; end users do not need a Power BI account.
- To embed for customers in production, you need a Power BI Embedded or Microsoft Fabric capacity.
- Publish to web makes a report public and is never suitable for business data.
Power BI Embedded at a glance
Power BI Embedded is the umbrella term for Microsoft's options for showing Power BI reports, dashboards and individual visuals in your own application. Users then do not work in the Power BI service, but in your portal, intranet or software product. Filtering, drilling through and moving between pages work just as they do in Power BI itself.
Technically, it works like this: your application's server signs in to Microsoft Entra ID and requests an embed token through the Power BI REST API. That token is short-lived and only valid for the reports and semantic models you specify. The browser then loads the report with the Power BI JavaScript library. Secrets, such as the application's password, stay on the server.
Note: Microsoft also uses "Power BI Embedded" as the name of the capacity you buy through Azure. This article is mainly about the technology and the choices you make.
Embedding for your organisation or for your customers
Microsoft distinguishes two scenarios. When embedding for your organisation ("user owns data"), each user signs in with their own Microsoft Entra account, and Power BI itself checks whether that person may see the report. When embedding for your customers ("app owns data"), only the application signs in to Microsoft. Your application then decides who gets to see which report and which data.
The key difference lies in responsibility. In the first scenario, Microsoft handles access; in the second, your application is the gatekeeper, and sign-in, permissions and filtering all have to be right there.
| Embedding for your organisation | Embedding for your customers | |
|---|---|---|
| Also known as | User owns data | App owns data |
| Who signs in to Microsoft | Every user, with their own Microsoft Entra account | Only the application, through a service principal |
| End-user licence | An appropriate Power BI licence, depending on your licensing model | No Power BI licence needed |
| Who controls access | The permissions in the Power BI service | Your application, with roles and RLS in the embed token |
| Typical use | Intranet, SharePoint, internal tools | Customer portal, SaaS product, portal for suppliers or franchisees |
| Capacity needed | Not necessarily | Yes, for production |
The role of the service principal
A service principal is the identity of an application in Microsoft Entra ID. You create an app registration and receive a client ID and a secret or certificate. Your application uses these to sign in, without involving a personal account.
For a service principal to work with Power BI, an administrator must allow service principals to use the Power BI and Fabric APIs in the tenant settings, preferably restricted to a security group. You then add the service principal to the workspaces containing the reports you want to embed. Microsoft recommends a service principal over a master user account with a username and password. When setting it up, pay attention to these points:
- Store the secret only on the server and encrypted, never in the browser or in the source code.
- Give the service principal access only to the workspaces it genuinely needs.
- Let secrets expire and renew them in good time, so that a leaked secret cannot be used indefinitely.
- Use a separate service principal per customer or environment if you want to keep customers strictly separated.
Capacity and licences in broad terms
To embed for your customers in production, the content must be in a workspace assigned to a capacity: reserved computing power in Microsoft's cloud. That can be a Power BI Embedded capacity through Azure or a Microsoft Fabric capacity.
Without capacity, you can develop and test with a Power BI Pro licence, but the number of embed tokens is then limited and not intended for production. Anyone who creates and publishes reports still needs their own licence as well, such as Power BI Pro.
How large the capacity needs to be depends on the number of concurrent users, the size of your semantic models and how often you refresh. Microsoft regularly changes its licences and product names, so always check the current documentation before you make a choice.
When do you need Power BI Embedded?
If you only work with an internal team that already has Power BI licences, sharing through the Power BI service or a Power BI app is usually simpler. Embedding then mainly adds development and maintenance work.
Power BI Embedded becomes worthwhile as soon as you want to show reports outside the Power BI service, or to people outside your organisation. Typical situations:
- You want to share dashboards with customers, suppliers, franchisees or other external parties who do not have an account in your Microsoft environment.
- You want to show reports in your own portal or product, in your own branding and alongside other features.
- You have many readers who only view reports, which makes a licence per person impractical.
- Each external party may only see its own figures, which you handle with row-level security in the embed token.
Alternatives: Publish to web and sharing in the Power BI service
Publish to web creates a public link or embed code. Anyone with that link can see the report without signing in. Links can be forwarded or found, and Microsoft itself warns that this option is not intended for confidential information. So never use it for business data. An administrator can switch the feature off in the tenant settings.
Sharing in the Power BI service, through a sharing link, a workspace or a Power BI app, is the standard for internal reporting. Everyone then needs an account in your Microsoft Entra ID, as an employee or as a guest user, and an appropriate licence.
For an intranet or SharePoint page, you can also use secure embed: viewers then have to sign in and have permission to view the report. That is useful for internal pages, but it is not a solution for external customers.
Build it yourself or use an existing portal
If you build customer embedding yourself, you need more than an embed token: your own sign-in, preferably with two-factor authentication, user management, a link between users and Power BI roles, token renewal, logging and monitoring of refreshes.
ENABLE from Data Analytics B.V. is such an existing portal. Power BI reports are shown in it through Power BI Embedded, with a Microsoft Entra service principal that you configure per customer; the secret is stored encrypted. Access profiles determine who sees which dashboards, row-level security filters the data per user and the activity log also records embed sessions.