Power BI
Power BI Service (cloud)
Access mode: Read-only
Required information
| Field | Details |
|---|---|
| Azure AD tenant ID | M365 tenant. |
| Workspace ID(s) | Power BI workspace GUIDs. |
| App registration | Azure AD app with Power BI API permissions. |
| API permissions | Read-only: Dashboard.Read.All, Dataset.Read.All, Report.Read.All, Workspace.Read.All. |
Network considerations
Fully managed SaaS. HTTPS to api.powerbi.com. No VPN needed.
Tenant isolation: If the org uses Power BI tenant isolation or conditional access, the service principal must be allowed.
Admin API: For tenant-wide scanning (datasets, lineage), the service principal needs admin consent for Tenant.Read.All.
Credential and auth management
Preferred: Service principal (Azure AD app). Enable “Allow service principals to use Power BI APIs” in Power BI admin portal. Grant workspace access to the service principal.
Alternative: Master user account. A dedicated Power BI Pro/Premium user. Less secure, requires password management.
Token: Standard Azure AD OAuth2. Flume handles refresh.
Admin API access: Requires Power BI admin to enable “Service principals can access read-only admin APIs” in tenant settings.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Authentication | GET https://api.powerbi.com/v1.0/myorg/groups | Returns workspace list |
| Dataset listing | GET /v1.0/myorg/groups/<wsId>/datasets | Lists datasets |
| Report listing | GET /v1.0/myorg/groups/<wsId>/reports | Lists reports |
| Lineage scan | POST /v1.0/myorg/admin/workspaces/getInfo with lineageEnabled=true | Returns dataset lineage |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.