Supported Authentication Types:
- OAuth 2.0 Service Principal — Azure AD application authentication using Client ID, Client Secret, and Tenant ID
How to Run the Connector Externally
To run the Ingestion via the UI you’ll need to use the OpenMetadata Ingestion Container, which comes shipped with custom Airflow plugins to handle the workflow deployment. If, instead, you want to manage your workflows externally on your preferred orchestrator, you can check the following docs to run the Ingestion Framework anywhere.External Schedulers
Get more information about running the Ingestion Framework Externally
Requirements
PowerBI Admin and Non-Admin APIs:
While configuring the PowerBI ingestion you can choose whether to use the PowerBI Admin APIs to retrieve the metadata or use the PowerBI Non-Admin APIs. Please check below for the the difference in their functionality:- Enabled (Use PowerBI Admin APIs) Using the admin APIs will fetch the dashboard and chart metadata from all the workspaces available in the PowerBI instance.
- Disabled (Use Non-Admin PowerBI APIs) Using the non-admin APIs will only fetch the dashboard and chart metadata from the workspaces that have the security group of the service principal assigned to them.
PowerBI Account Setup
Follow the steps below to configure the account setup for PowerBI connector:Step 1: Enable API permissions from the PowerBI Admin console
We extract the information from PowerBI using APIs, this is a manual step a PowerBI Admin needs to do to ensure we can get the right information. Log in to the Power BI as Admin and enable the tenant settings below from Tenant settings in the Admin portal. Start with Allow service principals to use Power BI APIs, which lets the service principal call the Power BI REST APIs. Of the three settings in the table below, the first authorizes the service principal to call the PowerBI admin APIs. The other two add detail to the GetScanResult response that the connector reads.Note: The two enhanced metadata settings apply to service principals only when Service principals can access read-only admin APIs is also enabled. Enable all three together, and add the service principal to the security group specified in each setting.
Step 2: Create the App in Azure AD
Please follow the steps mentioned here for setting up the Azure AD application service principle.Step 3: Provide necessary API permissions to the Azure AD app
Go to theAzure Ad app registrations page, select your app and add the permissions below to the app for PowerBI service and grant admin consent for the same.
All four permissions are required:
Dashboard.Read.All: dashboards and the tiles OpenMetadata ingests as charts.Dataset.Read.All: datasets that OpenMetadata ingests as data models, along with their tables and columns. Without it, datamodel and lineage processing is skipped.Report.Read.All: reports, which OpenMetadata also ingests as dashboards.Workspace.Read.All: workspaces, which OpenMetadata stores in the project field of dashboards and data models.
Step 4: PowerBI Workspaces
The service principal does not take into account the default user workspaces e.gMy Workspace.
To create a workspace, see Create a workspace in Power BI. For service principal requirements and limitations, see Embed Power BI content with service principal and an application secret.
Python Requirements
Use a Python version supported by theopenmetadata-ingestion package that matches your OpenMetadata server. To find the supported range for your release, check the Requires-Python metadata of that release’s ingestion package.
To run the PowerBI ingestion, you will need to install: