Skip to content
English
  • There are no suggestions because the search field is empty.

How to Add a Power BI Account to PBRS

Add a Power BI account to PBRS to give PBRS access to the Power BI Service content you want to schedule and distribute. This article explains how to add a Power BI account, configure the appropriate authentication method, and verify that PBRS can connect to Power BI Service.

 Applies to 

This article applies to:

  • Power BI reports and dashboards in Power BI Service
  • Power BI paginated reports in Power BI Service

Before you begin 

Before adding a Power BI account to PBRS, make sure you have access to the Power BI Service content you want PBRS to schedule and the information required for your organization's authentication method. 

Make sure you have:

  • Access to the Power BI Service.
  • Access to the Power BI workspaces, reports, dashboards, or paginated reports you want PBRS to use.
  • The credentials or application information required for the authentication method you will use.
  • Any required permissions or administrator approval for PBRS to access your Power BI environment.

     

 

Important: An Azure Global Administrator must grant the permissions required for PBRS to access Power BI and any Microsoft 365 services used by your PBRS configuration.

If you are not an Azure Global Administrator, ask your organization's Azure Global Administrator to register the Azure AD application for PBRS, configure the required API permissions, and grant administrator consent. They must then provide you with the Client ID and Azure Tenant ID required to configure the account in PBRS.

For instructions, see Register an Azure AD App to Embed Power BI Content for Use with PBRS.

 

Open the Power BI integration 

Power BI accounts are managed through the PBRS Integrations Library. Open the Power BI integration to view, add, or manage the Power BI accounts available to PBRS. 

  1. From PBRS, open the Integrations Library.
  2. On the PBRS Integrations screen, select PowerBI.
  3. The Power BI integration opens, where you can view and manage the Power BI accounts configured in PBRS.

pbrs integrations home
PBRS Integrations Library showing the PowerBI integration

Manage Power BI accounts

The PBRS Integrations - PowerBI Accounts screen displays the Power BI accounts currently configured in PBRS. From this screen, you can add, edit, or remove Power BI accounts. 

PBRS Integrations PowerBI Accounts screen showing configured accounts and Add and Delete options

Add a Power BI account 

  1. Review the existing Power BI accounts to make sure the account you need has not already been configured.
  2. Select Add to add a new Power BI account.
  3. Configure the account using the appropriate authentication method

Edit an existing Power BI account 

To review or change an existing Power BI account, double-click the required account in the account list. PBRS opens the account configuration so you can review or modify its settings. 

Delete a Power BI account 

To remove an existing Power BI account, select the account and then select Delete.

Important: Before deleting a Power BI account, make sure it is not being used by existing PBRS schedules.

Choose an authentication type 

On the Add a PowerBI Account screen, enter a name for the account and select the authentication method PBRS should use to connect to Power BI Service. The credentials required depend on the authentication method you select. 

Add a PowerBI AccountChoose an authentication type 

PBRS supports several authentication methods for connecting to Power BI Service. Use the following table to compare the available options and identify the method that matches your Power BI environment and authentication requirements. 

Authentication Types Avaiable in PBRS

Note: The credentials and permissions required depend on your organization's Microsoft and Power BI configuration. Some authentication methods require an application to be registered and granted access to Power BI before the account can be verified in PBRS. 

User-based authentication: Office 365, Azure Active Directory, and MSAL Delegated (User Account) authenticate in the context of a user.

Application-based authentication: Service Principal and MSAL App-Only (Client Credentials) authenticate using an application identity rather than an individual Power BI user.

 If you do not yet have the required application credentials, see How to Register an Azure AD App to Embed Power BI Content for Use with PBRS

 

Configure Office 365

Select Office 365 to configure a Power BI account using Office 365 authentication. Enter the user credentials and application credentials PBRS requires to authenticate the account. 

PBRS Add a PowerBI Account screen showing Office 365 authentication and credential settings

Setting Description
Account Name Enter a descriptive name that identifies the Power BI account in PBRS.
Username Enter the username for the Office 365 account PBRS should use to access Power BI Service.
Password Enter the password for the Office 365 account.
Client ID Enter the Client ID for the application PBRS uses to authenticate with Power BI.
Client Secret Enter the Client Secret associated with the application.
  1. Under Authentication Type, select Office 365.
  2. In Username, enter the username for the Office 365 account.
  3. In Password, enter the password for the account.
  4. In Client ID, enter the Client ID for the application used by PBRS.
  5. In Client Secret, enter the corresponding Client Secret.
  6. Select Verify to verify that PBRS can authenticate the Power BI account.
  7. After the account is successfully verified, select Save & Close.

 To review a value while configuring the account, select Show Password or Show Client Secret as required. 

Configure Azure Active Directory
 → Use Code Authorization

Select Azure Active Directory to authenticate a Power BI account using Azure Active Directory application credentials. You can also use Code Authorization to complete the user authorization process and generate the required refresh token. 

Add a PowerBI AccountPBRS Power BI Account settings showing Azure Active Directory authentication with Code Authorization

Setting Description
Account Name Enter a descriptive name that identifies the Power BI account in PBRS.
Username Enter the username for the Power BI account, where required by the authentication configuration.
Password Enter the password for the Power BI account, where required.
Client ID Enter the Client ID of the application registered for PBRS to access Power BI.
Client Secret Enter the Client Secret associated with the registered application.
Tenant ID Enter the Azure tenant identifier associated with the Power BI environment.
Refresh Token Displays or stores the refresh token PBRS uses as part of the authentication process.
Use Code Authorization Uses the authorization-code process to authorize the Power BI account.
  1. Under Authentication Type, select Azure Active Directory.
  2. In Client ID, enter the Client ID of the application registered for PBRS.
  3. In Client Secret, enter the corresponding Client Secret.
  4. In Tenant ID, enter the Azure tenant identifier associated with the Power BI environment.
  5. Enter the Username and Password if they are required for your authentication configuration.
  6. Select Verify to verify the account credentials.
  7. After the account has been successfully verified, select Save & Close.

 Use Code Authorization 

Select Use Code Authorization when you want PBRS to use the authorization-code process for the Power BI account. 

  1. Select Azure Active Directory.
  2. Select Use Code Authorization.
  3. Enter the required Client ID, Client Secret, and Tenant ID.
  4. Use Verify to begin the authorization process.
  5. Complete the Microsoft authorization steps when prompted.
  6. After authorization completes, confirm that PBRS has populated or obtained the required Refresh Token.
  7. Select Save & Close.

What's my Azure Tenant ID?

If you do not know your tenant identifier, use the What's my Azure Tenant ID? link in PBRS for guidance.

Configure Service Principal

Select Service Principal to authenticate PBRS to Power BI Service using an application identity instead of an individual user account. This method uses the application's Client ID, Client Secret, and Tenant ID. 

Setting Description
Account Name Enter a descriptive name that identifies the Power BI account in PBRS.
Client ID Enter the Client ID of the application used as the Service Principal.
Client Secret Enter the Client Secret associated with the application.
Tenant ID Enter the tenant identifier for the Microsoft tenant containing the Power BI environment.

PBRS Add a PowerBI Account screen showing MSAL Delegated User Account authentication and credential settings

  1. Under Authentication Type, select Service Principal.
  2. In Client ID, enter the Client ID of the application PBRS should use to authenticate.
  3. In Client Secret, enter the Client Secret associated with the application.
  4. In Tenant ID, enter the tenant identifier associated with the Power BI environment.
  5. Select Verify.
  6. After the account is successfully verified, select Save & Close.

Note: Service Principal accounts can also be used with the Row Level Security settings available for Power BI Single Report Schedules when RLS is configured for the Power BI semantic model.


Configure MSAL Delegated (User Account)

Select MSAL Delegated (User Account) to authenticate PBRS to Power BI Service using Microsoft Authentication Library (MSAL) delegated authentication. The user signs in through the Microsoft authorization process rather than entering a username and password directly in PBRS. 

PBRS Add a PowerBI Account screen showing MSAL Delegated User Account authentication, credentials, Tenant ID, and Refresh Token

Setting Description
Account Name Enter a descriptive name that identifies the Power BI account in PBRS.
Username Not used for MSAL Delegated (User Account) and cannot be edited.
Password Not used for MSAL Delegated (User Account) and cannot be edited.
Client ID Enter the Client ID of the application PBRS uses for authentication.
Client Secret Enter the Client Secret associated with the application, where required.
Tenant ID Enter the tenant identifier associated with the Power BI environment.
Refresh Token Contains the refresh token PBRS uses to maintain delegated access to the Power BI account.
  1. Under Authentication Type, select MSAL Delegated (User Account).
  2. In Client ID, enter the Client ID of the application configured for PBRS.
  3. In Client Secret, enter the corresponding Client Secret where required.
  4. In Tenant ID, enter the tenant identifier associated with the Power BI environment.
  5. Select Verify to begin the authentication and verification process.
  6. Complete the Microsoft sign-in and authorization process when prompted.
  7. After authorization completes, confirm that PBRS has obtained the required Refresh Token.
  8. After the account is successfully verified, select Save & Close.

Note: Username and Password are not used for MSAL Delegated (User Account) authentication and are disabled in PBRS. User authentication takes place through the Microsoft authorization process when the account is verified. 

Configure MSAL App-Only (Client Credentials)

Select MSAL App-Only (Client Credentials) to authenticate PBRS to Power BI Service using Microsoft Authentication Library (MSAL) application credentials. This method authenticates using the registered application's Client ID, Client Secret, and Tenant ID rather than an individual Power BI user account. 

PBRS Add a PowerBI Account screen showing MSAL App-Only Client Credentials authentication settings

Setting Description
Account Name Enter a descriptive name that identifies the Power BI account configuration in PBRS.
Username Not used for MSAL App-Only (Client Credentials) authentication and cannot be edited.
Password Not used for MSAL App-Only (Client Credentials) authentication and cannot be edited.
Client ID Enter the Client ID of the application PBRS should use to authenticate with Power BI Service.
Client Secret Enter the Client Secret associated with the registered application.
Tenant ID Enter the tenant identifier associated with the Power BI environment.
  1. In Account Name, enter a descriptive name for the Power BI account configuration.
  2. Under Authentication Type, select MSAL App-Only (Client Credentials).
  3. In Client ID, enter the Client ID of the application registered for PBRS.
  4. In Client Secret, enter the Client Secret associated with the application.
  5. In Tenant ID, enter the tenant identifier associated with your Power BI environment.
  6. Select Verify to verify that PBRS can authenticate to Power BI Service using the application credentials.
  7. After the account is successfully verified, select Save & Close.

Note: Username and Password are not used for MSAL App-Only (Client Credentials) authentication. PBRS authenticates using the application's Client ID, Client Secret, and Tenant ID instead of an individual user's credentials. 

MSAL App-Only (Client Credentials) uses an application identity rather than acting on behalf of an individual Power BI user. The Power BI content PBRS can access therefore depends on the permissions and Power BI access configured for the application. 

Configure account sharing

Use the Sharing tab to control which PBRS user groups can access and use the Power BI account. Share the account only with the groups that require access to it. 

PBRS Power BI Account Sharing tab showing the groups that can access the account

 

  1. Select the Sharing tab.
  2. Under Share this account with the following groups, select the PBRS groups that should be allowed to use the Power BI account.
  3. To remove access for a group, remove the group from the sharing list.
  4. Review the list and confirm that the account is shared only with the required groups.
  5. Return to the General tab if you need to make additional changes to the account configuration.
  6. After the account has been verified and the sharing settings are correct, select Save & Close.

Note: Power BI account sharing in PBRS does not grant additional permissions in Power BI Service. The Power BI content available through the account is still determined by the permissions associated with the authenticated user or application in Power BI.

Recommended: Share Power BI accounts only with the PBRS groups that require them.

Verify the Power BI account

 Before saving a Power BI account, verify that PBRS can authenticate to Power BI Service using the configured account and authentication settings. The verification options available may depend on the authentication method you selected. 

Verify Power BI Account

 

Option Description
Verify Verifies the Power BI account using the authentication settings configured in PBRS.
With Browser Uses a browser-based Microsoft authentication process to verify and authorize the account.
  1. Complete the required authentication settings on the General tab.
  2. Review the Account Name, authentication type, and required credentials or application information.
  3. Select Verify to verify the Power BI account.
  4. Complete any authentication or authorization prompts that appear.
  5. Confirm that PBRS successfully verifies the account.
  6. Review the Sharing settings and confirm that the account is available to the required PBRS groups.
  7. Select Save & Close to save the verified account.

Verify with a browser 

For authentication methods that require interactive Microsoft authorization, use With Browser to complete the authentication process in a web browser. 

  1. Select the dropdown arrow next to Verify.
  2. Select With Browser.
  3. Complete the Microsoft sign-in and authorization process.
  4. Return to PBRS and confirm that the account has been successfully verified.

When using Azure Active Directory with Use Code Authorization, the browser verification option can be used to complete the interactive Microsoft authorization process. 

After successful delegated or code-based authorization, PBRS may obtain a Refresh Token that it uses to maintain authorized access to Power BI Service. 

 Successful verification confirms that PBRS can authenticate using the account. Access to individual Power BI workspaces and content is still determined by the permissions assigned in Power BI. 

 If verification fails 

Review the authentication method and required credentials, including the Client ID, Client Secret, Tenant ID, and user authorization where applicable. Also confirm that the registered application and authenticated identity have the required Microsoft and Power BI permissions.

After correcting the configuration, select Verify again.

 Azure administrator permissions 

Important: An Azure Global Administrator must grant the permissions required for PBRS to access Power BI and any Microsoft 365 services used by your PBRS configuration.

If you are not an Azure Global Administrator, ask your organization's Azure Global Administrator to register the Azure AD application for PBRS, configure the required API permissions, and grant administrator consent. They must then provide you with the Client ID and Azure Tenant ID required to configure the account in PBRS.

For instructions, see Register an Azure AD App to Embed Power BI Content for Use with PBRS.

Required Power BI API permissions 

Under Power BI Service, configure the following Delegated permissions and grant Admin Consent

Permission Type Admin consent
Dashboard.ReadWrite.All Delegated Required
Dataset.ReadWrite.All Delegated Required
Report.ReadWrite.All Delegated Required
Workspace.Read.All Delegated Required

Required Microsoft Graph permissions 

If PBRS will access SharePoint, OneDrive, or email functionality, configure the applicable Microsoft Graph Delegated permissions and grant Admin Consent

Permission Purpose
Sites.ReadWrite.All Read and write SharePoint site content.
Sites.FullControl.All Full control of SharePoint sites. Required when PBRS needs to edit SharePoint metadata.
Sites.Manage.All Manage SharePoint sites.
Sites.Read.All Read SharePoint site content.
Mail.Read Read mail.
Mail.ReadBasic Read basic mail properties.
Mail.ReadWrite Read and modify mail.
Mail.Send Send mail.
Files.Read Read files the signed-in user can access.
Files.Read.All Read files the signed-in user can access across supported locations.
Files.ReadWrite Read and write files available to the signed-in user.
Files.ReadWrite.All Read and write files across supported locations available to the signed-in user.

Note: Sites.ReadWrite.All appears only once in the final permission list even though it may be required by more than one PBRS SharePoint/OneDrive workflow. 

After configuring the permissions:

  1. Grant Admin Consent for the required API permissions.
  2. Confirm that the permissions show as successfully granted in the Azure application registration.
  3. Provide the PBRS administrator with the application's Client ID and Azure Tenant ID.
  4. Return to the Power BI account configuration in PBRS.
  5. Select Verify or With Browser, as required by the authentication method.
  6. Confirm that PBRS successfully authenticates before selecting Save & Close.

Troubleshooting 

If PBRS cannot verify the Power BI account or the expected Power BI content is unavailable after the account is added, check the following common issues. 

The Power BI account does not verify

Confirm that you selected the correct Authentication Type and entered the required credentials for that method.

Check the Client ID, Client Secret, and Tenant ID, where applicable. Make sure the values belong to the same registered Azure application and Microsoft tenant.

If the authentication method requires interactive authorization, use Verify → With Browser and complete the Microsoft sign-in and authorization process.

Microsoft authorization or consent fails

Confirm that the Azure application has been registered correctly and that the required API permissions have been configured.

An Azure Global Administrator must grant Admin Consent for the required permissions. If you do not have the necessary Azure permissions, ask your Azure Global Administrator to complete the application registration and consent process.

See Azure administrator permissions above for the required Power BI Service and Microsoft Graph permissions.

The Client ID or Tenant ID is rejected

Confirm that the Client ID belongs to the application registered for PBRS and that the Tenant ID identifies the Microsoft tenant containing the Power BI environment.

If you do not know your tenant identifier, select What's my Azure Tenant ID? in PBRS for guidance.

The Client Secret does not work

Confirm that the Client Secret is correct and has not expired. If necessary, create a new Client Secret for the registered application and update the Client Secret in PBRS.

Make sure you are using the Client Secret value required by the application configuration rather than another identifier associated with the secret.

Browser verification does not complete

If you are using an authentication method that requires interactive authorization, select the dropdown next to Verify, and then select With Browser.

Complete the Microsoft sign-in and consent process using an account authorized for the Power BI environment. If consent is blocked, contact your Azure Global Administrator to confirm that the application has the required permissions and Admin Consent.

A Refresh Token is not generated

For authentication methods that use delegated or code-based authorization, confirm that the Microsoft authorization process completed successfully.

Select Verify → With Browser where applicable and complete the sign-in and authorization process again.

Do not manually modify the Refresh Token unless your PBRS configuration specifically requires it.

The account verifies, but Power BI workspaces or reports are missing

Successful verification confirms that PBRS can authenticate to Power BI Service. It does not grant the authenticated user or application access to all Power BI content.

Confirm that the user, Service Principal, or application identity has access to the required Power BI workspace and content.

Authentication succeeded does not necessarily mean authorization to the content succeeded.

A Service Principal or MSAL App-Only account cannot access Power BI content

Confirm that the application identity has been granted the required access to the Power BI environment and the workspaces PBRS needs to use.

Also confirm that the application's Client ID, Client Secret, and Tenant ID are correct and that the Client Secret has not expired.

MSAL Delegated authentication does not work

Confirm that MSAL Delegated (User Account) is selected and that the Client ID, Client Secret where required, and Tenant ID are correct.

Username and Password are disabled for this authentication method. Complete user authentication through the Microsoft authorization process instead.

Use Verify → With Browser where required to complete interactive authorization.

MSAL App-Only authentication does not work

Confirm that MSAL App-Only (Client Credentials) is selected and that the Client ID, Client Secret, and Tenant ID are correct.

Username and Password are not used for this authentication method. Confirm that the application identity itself has the required permissions and access to Power BI.

Other PBRS users cannot use the Power BI account

Open the Power BI account and select the Sharing tab. Confirm that the appropriate PBRS groups are listed under Share this account with the following groups.

Remember that PBRS account sharing does not grant additional Power BI permissions. The authenticated user or application must still have access to the required Power BI content.

If the problem continues

Recheck the authentication method, application credentials, Azure permissions, Admin Consent, and Power BI workspace access. After making any changes, select Verify again to test the account.

If you need further assistance, submit a support request and our Support team will help you troubleshoot the issue. 

When troubleshooting authentication, do not send or publish passwords, Client Secrets, or Refresh Tokens. Keep sensitive credential values masked in screenshots and support communications.

Related Articles

 Integrations Library