Business Intelligence Power BI Embedded Microsoft Fabric

Custom Power BI integration development

Appfront builds custom Power BI integrations for enterprise and mid-market organisations on the Microsoft 365 stack. From embedded dashboards in your SaaS product or customer portal, and multi-tenant Row-Level and Object-Level Security, to dataset refresh orchestration via the REST API, service principal authentication and a full Microsoft Fabric rollout with Direct Lake mode on OneLake.

What is a Power BI integration?

Power BI is Microsoft's business intelligence platform within the broader Microsoft Fabric ecosystem. It combines data modelling, visualisation and distribution on a SaaS platform that integrates seamlessly with Entra ID, Microsoft 365, Teams, SharePoint and Azure data sources. Under the hood: the VertiPaq columnar in-memory engine, DAX as the formula language, Power Query (M) for data transformation and, since 2023, Direct Lake on OneLake.

A Power BI integration means you do not offer reports and dashboards as a standalone tool, but embed them where your users already work: in your own SaaS portal, a customer or partner portal, a SharePoint intranet or a Teams tab. We build the authentication layer, embedding logic, Row-Level Security and refresh orchestration so dashboards are always up to date and set to the correct data scope, without every end user needing their own Power BI licence.

For an in-depth technical guide on embedding architecture and performance, see our Power BI embedding guide. Official documentation: Microsoft Power BI Embedded analytics.

Power BI Embedded for SaaS and portals

App Owns Data architecture with service principal authentication and effective identity per session. Your customers view reports within your application without needing their own Power BI licence. Capacity management keeps performance predictable.

Row-Level & Object-Level Security

RLS roles via DAX and Object-Level Security to hide entire tables or columns. Multi-tenant scenarios built on the tabular engine, not on naive application-layer filtering.

Microsoft Fabric & Direct Lake

Since 2023, Microsoft Fabric has brought Power BI together with OneLake, Lakehouse, Data Warehouse and Real-Time Intelligence. Direct Lake mode lets semantic models read Parquet files straight into memory, without a duplicate import.

How we build your Power BI integration

A Power BI integration touches on authentication, data modelling, embedding, capacity management and operations. Our approach is structured in four phases, each with a clearly documented outcome. You can also read our broader systems integration approach.

1

Architecture & licensing model

We determine the right licensing model (Pro, Premium Per User, Embedded or Fabric F-SKU) for your scenario, and design the workspace structure per environment (dev, test, prod) and per tenant scenario. Decisions on Import, DirectQuery, Direct Lake or composite models are made here, not only during the build.

2

Data model, RLS & OLS

The semantic model is built in Power BI Desktop using a star schema, DAX measures and, where needed, row-level and object-level security roles. Data sources connect via the On-Premises Data Gateway or direct connectors for Azure SQL, Synapse, Snowflake, Databricks and Fabric Lakehouse. We use Tabular Editor for calculation groups and advanced modelling.

3

Embedding implementation

In your web application, we build the embedding layer using the Power BI JavaScript SDK (powerbi-client), server-side token generation via a service principal, and event handlers for filter changes, page navigation, bookmarks, save/print and error states. We apply theming based on your brand colours and build custom visuals where the standard ones fall short.

4

Operations & monitoring

Refresh orchestration via API calls from your ETL stack or Dataflows Gen2, capacity monitoring through the Capacity Metrics App, gateway health checks, and alerts for refresh failures or throttling. Deployment pipelines for dev, test and production, with Git integration on Fabric workspaces.

What can a Power BI integration do for you?

Power BI is much more than dashboards. The REST API, Embedded engine, JavaScript SDK and the broader Fabric ecosystem offer a wide range of integration options for enterprise and SaaS scenarios.

Embedded analytics in your own SaaS

Full reports, individual visuals or complete dashboards embedded in your own UI, with the look and feel of your application. Filtering works both ways: filtering in your UI updates visuals directly via the JavaScript SDK. App Owns Data is the standard route for multi-tenant SaaS.

Corporate dashboards in Teams and SharePoint

Reports as a Teams tab, on a SharePoint Online page, or as an Outlook add-in. Single sign-on via Entra ID, and RLS ensures the right department sees the right figures. Native deep links to the full Power BI Service for power users.

Paginated reports (SSRS replacement)

Pixel-perfect printable output such as invoices, annual reports, audit reports and compliance documents. Exported to PDF, Word or Excel via the Export API within your own automation. Replaces many legacy SQL Server Reporting Services deployments.

DirectQuery on large datasets

For warehouses on Snowflake, Databricks, Azure Synapse, or your own Snowflake integration, where import mode is impractical. Composite models combine DirectQuery with imported aggregations for the right balance of performance and freshness.

Real-time dashboards with streaming datasets

For IoT data, clickstream events or operational KPIs: streaming datasets and the push API, or via Fabric Real-Time Intelligence (Eventstream + KQL Database). Visuals update without a page refresh.

Row- and Object-Level Security

DAX roles for row filtering, plus OLS to hide entire tables or columns. Combinable with dynamic identity mapping in App Owns Data, so tenant isolation is enforced at model level rather than in application code.

Which businesses do we work with on Power BI?

Power BI is the market standard for BI within the Microsoft ecosystem. Our clients share a few recurring patterns, so you may recognise your own situation.

SaaS platforms with customer dashboards

A SaaS application that wants to show each customer their own dashboard without buying a Power BI licence for every customer. App Owns Data with RLS and a service principal is the standard answer here, combined with capacity sizing on an Embedded A-SKU or Fabric F-SKU.

Enterprise warehouse and self-service BI

Organisations with a mature warehouse on Azure Synapse, Databricks, Snowflake or Fabric that want to give their staff self-service reporting. We design the semantic layer, set up RLS roles through Entra ID groups, and automate dataset refresh or switch on Direct Lake.

Portals for external partners and suppliers

Supplier or customer portals where external parties see their own metrics. Power BI Embedded combined with B2B authentication or a custom identity broker delivers a secure, performant experience without partners needing to be present in your own tenant.

Compliance reporting in regulated sectors

Healthcare, finance and government: pixel-perfect reports via paginated reports, gateway connections to on-premises systems, audit logging on every dataset refresh and private link isolation so traffic never touches the public internet.

Power BI vs Tableau, Qlik and Looker

In most BI decisions, four names remain on the shortlist by the end of a vendor selection. Here is the decision model as we apply it in practice for Microsoft 365-oriented organisations.

Power BI

Almost always wins for organisations that already have Entra ID, Teams, SharePoint, Excel, Dataverse, Azure SQL, Synapse, Fabric or Microsoft 365 licences. Per-user costs on Pro are lower than most alternatives, and App Owns Data with a service principal is the most mature embedded path on the market. Direct Lake on OneLake removes the classic import/refresh trade-off for those already on Fabric.

Tableau

Stronger for organisations that place visualisation craftsmanship at the centre, with data analysts who have invested in Tableau skills. Tableau Embedded is mature, but per-user licence costs are typically higher. Tableau Server requires its own infrastructure unless you choose Tableau Cloud.

Qlik Sense

Distinguished by its associative data model (Qlik's Associative Engine), where users can click freely through dimensions without a predefined drill path. Strong in data-discovery use cases. Since the Talend acquisition, Qlik's roadmap has focused heavily on data integration; for pure embedded SaaS, Power BI often wins on cost.

Looker (Google Cloud)

The right choice if you use BigQuery as your main warehouse: LookML makes governance explicit through a central, versionable data model in Git. For Microsoft shops without Google Cloud components, the impedance mismatch is too great to justify.

Decision criteria

Microsoft 365 stack? Power BI. Pure visualisation craft? Tableau. Data discovery with associative filtering? Qlik. BigQuery warehouse and LookML governance? Looker. For enterprise or mid-market organisations on Azure or Microsoft 365, Power BI almost always delivers the highest ROI. Official reference: Microsoft Power BI fundamentals.

Migration patterns

We typically handle migrations from Tableau, Qlik or legacy SSRS to Power BI in phases: parallel run, semantic layer first, then report translation per business unit. For SSRS deployments we typically move to paginated reports within Premium or PPU. Read our guide API vs integration platform for architecture choices around data delivery.

Embedded analytics in your SaaS product

Power BI Embedded is the most mature route for delivering analytics within a SaaS application. Three decisions determine success: the embed model, capacity sizing and theming.

Embed model: App Owns Data vs User Owns Data

User Owns Data: each end user signs in with their own Power BI licence. Suitable for internal staff within your own Entra ID. App Owns Data (Embed for your customers): your application holds service principal credentials or a master user, generates an embed token per session with the correct effective identity, and the end user does not need a Power BI licence of their own. For SaaS and portal scenarios, App Owns Data is always the right choice, and it requires a Premium or Embedded capacity.

Capacity sizing and cost modelling

Embedded and Fabric F-SKUs are billed on compute hours, not on users. We size based on interactive operations per hour, concurrent users, dataset size and refresh frequency. Scaling down or pausing outside office hours via the Azure Resource Manager API often delivers a 30-50% cost reduction with no impact on user experience. The Capacity Metrics App shows, per workload, the CPU ladder, throttling events and the split between background and interactive consumption.

Theming, custom visuals and interaction bindings

JSON theme files bring your Power BI reports into line with your brand colours, fonts and spacing. The JavaScript SDK exposes a rich event API: filter changes, page navigation, bookmarks, error states, save/print and data-selected events. Custom visuals (built with the PowerBI visuals SDK in TypeScript) are the way out when a standard visual falls short, for example for sector-specific chart types or branded interaction patterns.

Our technical approach

A Power BI integration touches Entra ID, capacity management, data modelling, frontend integration, gateway routing and monitoring. We build all of these layers to production grade, not as a demo.

For authentication, we register a service principal in your Entra ID tenant with the minimum required Power BI API permissions (workspace access, dataset read, embed token). Server-side, we exchange client credentials for an access token, which we use to generate an embed token per session with the effective identity required for RLS. Tokens have a short lifetime (typically one hour), with cache warming and transparent rotation so that long sessions do not break. We store secrets in Azure Key Vault with automatic rotation policies.

We automate capacity orchestration through the Power BI REST API and Azure Resource Manager: pausing outside office hours, scaling up during refresh peaks, and raising alerts on CPU throttling. We link dataset refresh to your ETL pipeline via REST POST /datasets/{id}/refreshes, with retry logic and alerting through Application Insights or Microsoft Sentinel. For on-premises sources, we route traffic through a clustered On-Premises Data Gateway with failover and monitoring.

For Fabric deployments, we configure OneLake shortcuts to existing Azure Data Lake Storage Gen2 accounts or S3 buckets, so data does not need to be duplicated. Direct Lake models read Delta-Parquet directly from OneLake; we monitor framing operations and fallback-to-DirectQuery scenarios. Dataflows Gen2 replace classic ETL steps where transformation needs to sit closer to the data.

Tech stack

Power BI REST API Power BI Embedded Power BI JavaScript SDK Microsoft Fabric OneLake Direct Lake mode Microsoft Entra ID Service Principals DAX / Power Query (M) Tabular Editor Azure SQL / Synapse Snowflake / Databricks On-Premises Data Gateway Dataflows Gen2 Capacity Metrics App Application Insights Azure Key Vault

Why choose Appfront for your Power BI integration?

Power BI integrations look simple until tokens expire, a capacity gets throttled, an RLS role shows slightly too much, or a Direct Lake model unexpectedly falls back to DirectQuery. We build for those edge cases from day one, rather than working around them.

Our experience extends to similar integrations with Google Analytics, Matomo, Piwik PRO and data platforms such as Snowflake and Databricks. For custom dashboards beyond Power BI, see custom KPI dashboard development and real-time analytics platform development.

  • Experience with Power BI Embedded, Premium Per User and Fabric F-SKUs
  • Service principal setup in Entra ID tenants with scoped permissions
  • RLS and OLS design for multi-tenant SaaS scenarios
  • Dataset refresh orchestration via REST API and Dataflows Gen2
  • Direct Lake mode on OneLake and composite models in Fabric
  • Gateway clustering and failover for on-premises data sources
  • Deployment pipelines with Git integration on Fabric workspaces
  • Capacity tuning and cost optimisation via the Capacity Metrics App
  • Migration projects from Tableau, Qlik or SSRS

Security and compliance

Power BI often handles business-critical data: revenue, staff, customer behaviour, clinical metrics. Our integrations meet the requirements of regulated sectors and Microsoft's own Well-Architected best practices.

Your data stays within your own Azure tenant, with the option of private endpoints so that Power BI traffic never touches the public internet. Customer-Managed Keys for encryption at rest give you control over key rotation and revocation. We store service principal credentials in Azure Key Vault with automatic rotation. Audit logging runs through the Power BI Activity Log and Microsoft Purview for compliance reporting; sensitivity labels propagate automatically from data source to report and export.

For multi-tenant SaaS, we ensure tenant isolation is enforced at model level through RLS and OLS, not just in application code. For every integration we provide a technical description for your record of processing activities, support DPIA processes, and can make clear how data flows against GDPR obligations, NIS2 and sector-specific frameworks (BIO, NEN 7510, ISO 27001).

  • Your data stays within your Azure tenant
  • Private endpoints for the Power BI Service and gateways
  • Customer-Managed Keys for encryption at rest
  • Service principal credentials in Key Vault with rotation
  • Audit log via Activity Log and Microsoft Purview
  • Sensitivity labels from data source to export
  • Tenant isolation via RLS/OLS, not the application layer
  • Set up to be compliant with GDPR, NIS2, BIO and NEN 7510

Frequently asked questions about Power BI integrations

Power BI Pro is the basic per-user licence for internal staff. Premium Per User (PPU) adds premium features (paginated reports, AI, larger models, Direct Lake) on a per-user basis for smaller teams. Premium Capacity (the F-SKUs within Microsoft Fabric) is a dedicated compute pool where consumers do not need their own licence provided the content comes from Premium workspaces; this is the basis for Power BI Embedded and enterprise rollouts.

Microsoft Fabric is the overarching SaaS data platform that has been generally available since 2023. It brings together Power BI with Data Factory, Synapse Data Engineering, Data Warehouse, Real-Time Intelligence and Data Activator on shared OneLake storage. Within Fabric, Power BI is the presentation layer; semantic models can query Parquet/Delta files in OneLake directly via Direct Lake mode without data import. Existing Power BI Premium capacities have become Fabric capacities (F-SKUs).

User Owns Data is designed for scenarios where every end user has their own Power BI licence and signs in interactively, which suits internal staff within your own Entra ID tenant. App Owns Data (Embed for your customers) is built for SaaS and portal scenarios: your application holds the service principal credentials, generates an embed token per session, and the end user does not need a Power BI licence of their own. App Owns Data requires Premium or Embedded capacity and is the standard route for multi-tenant SaaS.

Import loads data into the VertiPaq in-memory engine: the fastest query times, but the data is a snapshot until the next refresh. DirectQuery passes queries straight through to the source in real time (Snowflake, Azure SQL, Synapse), which suits very large datasets or strict real-time requirements. Direct Lake is the Fabric variant: the semantic model reads Delta-Parquet files in OneLake directly into memory when they are needed, without a duplicate import. Composite models combine modes within a table or across a model.

Row-Level Security (RLS) filters rows through DAX roles, for example [Region] = USERNAME() or a lookup against a user table. When embedding, we pass an effective identity via the REST API so that customer A only sees customer A's rows. Object-Level Security (OLS) goes a step further: entire tables or columns are hidden from specific roles, including their metadata. We configure OLS using Tabular Editor; it is useful when even the existence of a PII column must remain hidden.

Power BI almost always wins for organisations already deeply invested in the Microsoft 365 stack: integration with Teams, SharePoint, Excel, Dataverse, Entra ID and Fabric is native. Per-user licensing costs at the Pro tier are lower than most alternatives. Tableau is stronger on visualisation craft, Qlik on associative models and data discovery, and Looker (within Google Cloud) on governance through LookML and BigQuery integration. For Microsoft shops with Azure as their data landscape, Power BI is nearly always the highest ROI.

The Power BI REST API gives programmatic control over workspaces, datasets, reports, dashboards, gateways, dataflows and embed tokens. All endpoints authenticate through Microsoft Entra ID using OAuth 2.0. For server-to-server access we use service principals (client credentials flow). The Embedded JavaScript SDK (powerbi-client) handles iframe communication in the browser: filter events, page navigation, and save, print and export handlers, as well as bookmarks. Embed tokens are generated server-side with an effective identity for RLS.

The Power BI Data Gateway is a Windows service you install on your own network so that the Power BI Service can securely access on-premises sources such as SQL Server, Oracle, SAP HANA, file shares or an ERP behind the firewall. The gateway itself initiates an outbound connection to the Service via Azure Service Bus, so no inbound port needs to be opened. For purely cloud sources, a gateway is usually not needed, except in private endpoint-only setups.

Embedded and Fabric F-SKU capacities are billed on compute hours, not on users. We monitor through the Capacity Metrics App and the Fabric capacity monitor: CPU percentage per workload, throttling events, refresh overlap, and interactive versus background time. We automate capacity scaling through the Azure Resource Manager API: scaling up during peaks, down or pausing outside office hours. Data model tuning (star schema, aggregations, incremental refresh, composite models) often reduces costs more than adding capacity does.

A single embedded dashboard in an existing web app, with service principal authentication and a working data model, can be live within one to two weeks. A full SaaS scenario with multi-tenant RLS, App Owns Data, dataset refresh orchestration via an ETL pipeline and custom interaction bindings takes three to eight weeks, depending on the number of reports and the complexity of the data model. A Microsoft Fabric rollout with OneLake and Direct Lake alongside an existing warehouse usually takes six to twelve weeks to reach the first production capacity.

Ready to integrate Power BI into your application?

Book a no-obligation advisory session. We will review your tenant set-up, data sources, licence mix and embedding goals, and within a week provide a concrete approach and indicative price for your Power BI integration. You can also explore our wider smart API integrations and other integration pages.

Edit content