How to Add a Power BI Account to PBRS
Add a Power BI account to PBRS to give PBRS access to the Power BI Service content you want to schedule and distribute. This article explains how to add a Power BI account, configure the appropriate authentication method, and verify that PBRS can connect to Power BI Service.
Applies to
This article applies to:
- Power BI reports and dashboards in Power BI Service
- Power BI paginated reports in Power BI Service
Before you begin
Before adding a Power BI account to PBRS, make sure you have access to the Power BI Service content you want PBRS to schedule and the information required for your organization's authentication method.
Make sure you have:
- Access to the Power BI Service.
- Access to the Power BI workspaces, reports, dashboards, or paginated reports you want PBRS to use.
- The credentials or application information required for the authentication method you will use.
- Any required permissions or administrator approval for PBRS to access your Power BI environment.
Important: An Azure Global Administrator must grant the permissions required for PBRS to access Power BI and any Microsoft 365 services used by your PBRS configuration.
If you are not an Azure Global Administrator, ask your organization's Azure Global Administrator to register the Azure AD application for PBRS, configure the required API permissions, and grant administrator consent. They must then provide you with the Client ID and Azure Tenant ID required to configure the account in PBRS.
For instructions, see Register an Azure AD App to Embed Power BI Content for Use with PBRS.
Open the Power BI integration
Power BI accounts are managed through the PBRS Integrations Library. Open the Power BI integration to view, add, or manage the Power BI accounts available to PBRS.
- From PBRS, open the Integrations Library.
- On the PBRS Integrations screen, select PowerBI.
- The Power BI integration opens, where you can view and manage the Power BI accounts configured in PBRS.


Manage Power BI accounts
The PBRS Integrations - PowerBI Accounts screen displays the Power BI accounts currently configured in PBRS. From this screen, you can add, edit, or remove Power BI accounts.

Add a Power BI account
- Review the existing Power BI accounts to make sure the account you need has not already been configured.
- Select Add to add a new Power BI account.
- Configure the account using the appropriate authentication method
Edit an existing Power BI account
To review or change an existing Power BI account, double-click the required account in the account list. PBRS opens the account configuration so you can review or modify its settings.
Delete a Power BI account
To remove an existing Power BI account, select the account and then select Delete.
Important: Before deleting a Power BI account, make sure it is not being used by existing PBRS schedules.
Choose an authentication type
On the Add a PowerBI Account screen, enter a name for the account and select the authentication method PBRS should use to connect to Power BI Service. The credentials required depend on the authentication method you select.
Choose an authentication type
PBRS supports several authentication methods for connecting to Power BI Service. Use the following table to compare the available options and identify the method that matches your Power BI environment and authentication requirements.

Note: The credentials and permissions required depend on your organization's Microsoft and Power BI configuration. Some authentication methods require an application to be registered and granted access to Power BI before the account can be verified in PBRS.
User-based authentication: Office 365, Azure Active Directory, and MSAL Delegated (User Account) authenticate in the context of a user.
Application-based authentication: Service Principal and MSAL App-Only (Client Credentials) authenticate using an application identity rather than an individual Power BI user.
If you do not yet have the required application credentials, see How to Register an Azure AD App to Embed Power BI Content for Use with PBRS.
→ Configure Office 365
Select Office 365 to configure a Power BI account using Office 365 authentication. Enter the user credentials and application credentials PBRS requires to authenticate the account.

| Setting | Description |
|---|---|
| Account Name | Enter a descriptive name that identifies the Power BI account in PBRS. |
| Username | Enter the username for the Office 365 account PBRS should use to access Power BI Service. |
| Password | Enter the password for the Office 365 account. |
| Client ID | Enter the Client ID for the application PBRS uses to authenticate with Power BI. |
| Client Secret | Enter the Client Secret associated with the application. |
- Under Authentication Type, select Office 365.
- In Username, enter the username for the Office 365 account.
- In Password, enter the password for the account.
- In Client ID, enter the Client ID for the application used by PBRS.
- In Client Secret, enter the corresponding Client Secret.
- Select Verify to verify that PBRS can authenticate the Power BI account.
- After the account is successfully verified, select Save & Close.
To review a value while configuring the account, select Show Password or Show Client Secret as required.
→ Configure Azure Active Directory
→ Use Code Authorization
Select Azure Active Directory to authenticate a Power BI account using Azure Active Directory application credentials. You can also use Code Authorization to complete the user authorization process and generate the required refresh token.

| Setting | Description |
|---|---|
| Account Name | Enter a descriptive name that identifies the Power BI account in PBRS. |
| Username | Enter the username for the Power BI account, where required by the authentication configuration. |
| Password | Enter the password for the Power BI account, where required. |
| Client ID | Enter the Client ID of the application registered for PBRS to access Power BI. |
| Client Secret | Enter the Client Secret associated with the registered application. |
| Tenant ID | Enter the Azure tenant identifier associated with the Power BI environment. |
| Refresh Token | Displays or stores the refresh token PBRS uses as part of the authentication process. |
| Use Code Authorization | Uses the authorization-code process to authorize the Power BI account. |
- Under Authentication Type, select Azure Active Directory.
- In Client ID, enter the Client ID of the application registered for PBRS.
- In Client Secret, enter the corresponding Client Secret.
- In Tenant ID, enter the Azure tenant identifier associated with the Power BI environment.
- Enter the Username and Password if they are required for your authentication configuration.
- Select Verify to verify the account credentials.
- After the account has been successfully verified, select Save & Close.
Use Code Authorization
Select Use Code Authorization when you want PBRS to use the authorization-code process for the Power BI account.
- Select Azure Active Directory.
- Select Use Code Authorization.
- Enter the required Client ID, Client Secret, and Tenant ID.
- Use Verify to begin the authorization process.
- Complete the Microsoft authorization steps when prompted.
- After authorization completes, confirm that PBRS has populated or obtained the required Refresh Token.
- Select Save & Close.
What's my Azure Tenant ID?
If you do not know your tenant identifier, use the What's my Azure Tenant ID? link in PBRS for guidance.
→ Configure Service Principal
Select Service Principal to authenticate PBRS to Power BI Service using an application identity instead of an individual user account. This method uses the application's Client ID, Client Secret, and Tenant ID.
| Setting | Description |
|---|---|
| Account Name | Enter a descriptive name that identifies the Power BI account in PBRS. |
| Client ID | Enter the Client ID of the application used as the Service Principal. |
| Client Secret | Enter the Client Secret associated with the application. |
| Tenant ID | Enter the tenant identifier for the Microsoft tenant containing the Power BI environment. |

- Under Authentication Type, select Service Principal.
- In Client ID, enter the Client ID of the application PBRS should use to authenticate.
- In Client Secret, enter the Client Secret associated with the application.
- In Tenant ID, enter the tenant identifier associated with the Power BI environment.
- Select Verify.
- After the account is successfully verified, select Save & Close.
Note: Service Principal accounts can also be used with the Row Level Security settings available for Power BI Single Report Schedules when RLS is configured for the Power BI semantic model.
→ Configure MSAL Delegated (User Account)
Select MSAL Delegated (User Account) to authenticate PBRS to Power BI Service using Microsoft Authentication Library (MSAL) delegated authentication. The user signs in through the Microsoft authorization process rather than entering a username and password directly in PBRS.

| Setting | Description |
|---|---|
| Account Name | Enter a descriptive name that identifies the Power BI account in PBRS. |
| Username | Not used for MSAL Delegated (User Account) and cannot be edited. |
| Password | Not used for MSAL Delegated (User Account) and cannot be edited. |
| Client ID | Enter the Client ID of the application PBRS uses for authentication. |
| Client Secret | Enter the Client Secret associated with the application, where required. |
| Tenant ID | Enter the tenant identifier associated with the Power BI environment. |
| Refresh Token | Contains the refresh token PBRS uses to maintain delegated access to the Power BI account. |
- Under Authentication Type, select MSAL Delegated (User Account).
- In Client ID, enter the Client ID of the application configured for PBRS.
- In Client Secret, enter the corresponding Client Secret where required.
- In Tenant ID, enter the tenant identifier associated with the Power BI environment.
- Select Verify to begin the authentication and verification process.
- Complete the Microsoft sign-in and authorization process when prompted.
- After authorization completes, confirm that PBRS has obtained the required Refresh Token.
- After the account is successfully verified, select Save & Close.
Note: Username and Password are not used for MSAL Delegated (User Account) authentication and are disabled in PBRS. User authentication takes place through the Microsoft authorization process when the account is verified.
→ Configure MSAL App-Only (Client Credentials)
Select MSAL App-Only (Client Credentials) to authenticate PBRS to Power BI Service using Microsoft Authentication Library (MSAL) application credentials. This method authenticates using the registered application's Client ID, Client Secret, and Tenant ID rather than an individual Power BI user account.

| Setting | Description |
|---|---|
| Account Name | Enter a descriptive name that identifies the Power BI account configuration in PBRS. |
| Username | Not used for MSAL App-Only (Client Credentials) authentication and cannot be edited. |
| Password | Not used for MSAL App-Only (Client Credentials) authentication and cannot be edited. |
| Client ID | Enter the Client ID of the application PBRS should use to authenticate with Power BI Service. |
| Client Secret | Enter the Client Secret associated with the registered application. |
| Tenant ID | Enter the tenant identifier associated with the Power BI environment. |
- In Account Name, enter a descriptive name for the Power BI account configuration.
- Under Authentication Type, select MSAL App-Only (Client Credentials).
- In Client ID, enter the Client ID of the application registered for PBRS.
- In Client Secret, enter the Client Secret associated with the application.
- In Tenant ID, enter the tenant identifier associated with your Power BI environment.
- Select Verify to verify that PBRS can authenticate to Power BI Service using the application credentials.
- After the account is successfully verified, select Save & Close.
Note: Username and Password are not used for MSAL App-Only (Client Credentials) authentication. PBRS authenticates using the application's Client ID, Client Secret, and Tenant ID instead of an individual user's credentials.
MSAL App-Only (Client Credentials) uses an application identity rather than acting on behalf of an individual Power BI user. The Power BI content PBRS can access therefore depends on the permissions and Power BI access configured for the application.
Configure account sharing
Use the Sharing tab to control which PBRS user groups can access and use the Power BI account. Share the account only with the groups that require access to it.

- Select the Sharing tab.
- Under Share this account with the following groups, select the PBRS groups that should be allowed to use the Power BI account.
- To remove access for a group, remove the group from the sharing list.
- Review the list and confirm that the account is shared only with the required groups.
- Return to the General tab if you need to make additional changes to the account configuration.
- After the account has been verified and the sharing settings are correct, select Save & Close.
Note: Power BI account sharing in PBRS does not grant additional permissions in Power BI Service. The Power BI content available through the account is still determined by the permissions associated with the authenticated user or application in Power BI.
Recommended: Share Power BI accounts only with the PBRS groups that require them.
→ Verify the Power BI account
Before saving a Power BI account, verify that PBRS can authenticate to Power BI Service using the configured account and authentication settings. The verification options available may depend on the authentication method you selected.

| Option | Description |
|---|---|
| Verify | Verifies the Power BI account using the authentication settings configured in PBRS. |
| With Browser | Uses a browser-based Microsoft authentication process to verify and authorize the account. |
- Complete the required authentication settings on the General tab.
- Review the Account Name, authentication type, and required credentials or application information.
- Select Verify to verify the Power BI account.
- Complete any authentication or authorization prompts that appear.
- Confirm that PBRS successfully verifies the account.
- Review the Sharing settings and confirm that the account is available to the required PBRS groups.
- Select Save & Close to save the verified account.
Verify with a browser
For authentication methods that require interactive Microsoft authorization, use With Browser to complete the authentication process in a web browser.
- Select the dropdown arrow next to Verify.
- Select With Browser.
- Complete the Microsoft sign-in and authorization process.
- Return to PBRS and confirm that the account has been successfully verified.
When using Azure Active Directory with Use Code Authorization, the browser verification option can be used to complete the interactive Microsoft authorization process.
After successful delegated or code-based authorization, PBRS may obtain a Refresh Token that it uses to maintain authorized access to Power BI Service.
Successful verification confirms that PBRS can authenticate using the account. Access to individual Power BI workspaces and content is still determined by the permissions assigned in Power BI.
If verification fails
Review the authentication method and required credentials, including the Client ID, Client Secret, Tenant ID, and user authorization where applicable. Also confirm that the registered application and authenticated identity have the required Microsoft and Power BI permissions.
After correcting the configuration, select Verify again.
Azure administrator permissions
Important: An Azure Global Administrator must grant the permissions required for PBRS to access Power BI and any Microsoft 365 services used by your PBRS configuration.
If you are not an Azure Global Administrator, ask your organization's Azure Global Administrator to register the Azure AD application for PBRS, configure the required API permissions, and grant administrator consent. They must then provide you with the Client ID and Azure Tenant ID required to configure the account in PBRS.
For instructions, see Register an Azure AD App to Embed Power BI Content for Use with PBRS.
Required Power BI API permissions
Under Power BI Service, configure the following Delegated permissions and grant Admin Consent:
| Permission | Type | Admin consent |
|---|---|---|
Dashboard.ReadWrite.All |
Delegated | Required |
Dataset.ReadWrite.All |
Delegated | Required |
Report.ReadWrite.All |
Delegated | Required |
Workspace.Read.All |
Delegated | Required |
Required Microsoft Graph permissions
If PBRS will access SharePoint, OneDrive, or email functionality, configure the applicable Microsoft Graph Delegated permissions and grant Admin Consent.
| Permission | Purpose |
|---|---|
Sites.ReadWrite.All |
Read and write SharePoint site content. |
Sites.FullControl.All |
Full control of SharePoint sites. Required when PBRS needs to edit SharePoint metadata. |
Sites.Manage.All |
Manage SharePoint sites. |
Sites.Read.All |
Read SharePoint site content. |
Mail.Read |
Read mail. |
Mail.ReadBasic |
Read basic mail properties. |
Mail.ReadWrite |
Read and modify mail. |
Mail.Send |
Send mail. |
Files.Read |
Read files the signed-in user can access. |
Files.Read.All |
Read files the signed-in user can access across supported locations. |
Files.ReadWrite |
Read and write files available to the signed-in user. |
Files.ReadWrite.All |
Read and write files across supported locations available to the signed-in user. |
Note: Sites.ReadWrite.All appears only once in the final permission list even though it may be required by more than one PBRS SharePoint/OneDrive workflow.
After configuring the permissions:
- Grant Admin Consent for the required API permissions.
- Confirm that the permissions show as successfully granted in the Azure application registration.
- Provide the PBRS administrator with the application's Client ID and Azure Tenant ID.
- Return to the Power BI account configuration in PBRS.
- Select Verify or With Browser, as required by the authentication method.
- Confirm that PBRS successfully authenticates before selecting Save & Close.
Troubleshooting
If PBRS cannot verify the Power BI account or the expected Power BI content is unavailable after the account is added, check the following common issues.
The Power BI account does not verify
Confirm that you selected the correct Authentication Type and entered the required credentials for that method.
Check the Client ID, Client Secret, and Tenant ID, where applicable. Make sure the values belong to the same registered Azure application and Microsoft tenant.
If the authentication method requires interactive authorization, use Verify → With Browser and complete the Microsoft sign-in and authorization process.
Microsoft authorization or consent fails
Confirm that the Azure application has been registered correctly and that the required API permissions have been configured.
An Azure Global Administrator must grant Admin Consent for the required permissions. If you do not have the necessary Azure permissions, ask your Azure Global Administrator to complete the application registration and consent process.
See Azure administrator permissions above for the required Power BI Service and Microsoft Graph permissions.
The Client ID or Tenant ID is rejected
Confirm that the Client ID belongs to the application registered for PBRS and that the Tenant ID identifies the Microsoft tenant containing the Power BI environment.
If you do not know your tenant identifier, select What's my Azure Tenant ID? in PBRS for guidance.
The Client Secret does not work
Confirm that the Client Secret is correct and has not expired. If necessary, create a new Client Secret for the registered application and update the Client Secret in PBRS.
Make sure you are using the Client Secret value required by the application configuration rather than another identifier associated with the secret.
Browser verification does not complete
If you are using an authentication method that requires interactive authorization, select the dropdown next to Verify, and then select With Browser.
Complete the Microsoft sign-in and consent process using an account authorized for the Power BI environment. If consent is blocked, contact your Azure Global Administrator to confirm that the application has the required permissions and Admin Consent.
A Refresh Token is not generated
For authentication methods that use delegated or code-based authorization, confirm that the Microsoft authorization process completed successfully.
Select Verify → With Browser where applicable and complete the sign-in and authorization process again.
Do not manually modify the Refresh Token unless your PBRS configuration specifically requires it.
The account verifies, but Power BI workspaces or reports are missing
Successful verification confirms that PBRS can authenticate to Power BI Service. It does not grant the authenticated user or application access to all Power BI content.
Confirm that the user, Service Principal, or application identity has access to the required Power BI workspace and content.
Authentication succeeded does not necessarily mean authorization to the content succeeded.
A Service Principal or MSAL App-Only account cannot access Power BI content
Confirm that the application identity has been granted the required access to the Power BI environment and the workspaces PBRS needs to use.
Also confirm that the application's Client ID, Client Secret, and Tenant ID are correct and that the Client Secret has not expired.
MSAL Delegated authentication does not work
Confirm that MSAL Delegated (User Account) is selected and that the Client ID, Client Secret where required, and Tenant ID are correct.
Username and Password are disabled for this authentication method. Complete user authentication through the Microsoft authorization process instead.
Use Verify → With Browser where required to complete interactive authorization.
MSAL App-Only authentication does not work
Confirm that MSAL App-Only (Client Credentials) is selected and that the Client ID, Client Secret, and Tenant ID are correct.
Username and Password are not used for this authentication method. Confirm that the application identity itself has the required permissions and access to Power BI.
Other PBRS users cannot use the Power BI account
Open the Power BI account and select the Sharing tab. Confirm that the appropriate PBRS groups are listed under Share this account with the following groups.
Remember that PBRS account sharing does not grant additional Power BI permissions. The authenticated user or application must still have access to the required Power BI content.
If the problem continues
Recheck the authentication method, application credentials, Azure permissions, Admin Consent, and Power BI workspace access. After making any changes, select Verify again to test the account.
If you need further assistance, submit a support request and our Support team will help you troubleshoot the issue.
When troubleshooting authentication, do not send or publish passwords, Client Secrets, or Refresh Tokens. Keep sensitive credential values masked in screenshots and support communications.