Skip to main content
In this section, we provide guides and references to use the PowerBI connector.
Supported Authentication Types:
  • OAuth 2.0 Service Principal — Azure AD application authentication using Client ID, Client Secret, and Tenant ID
Configure and schedule PowerBI metadata and profiler workflows from the OpenMetadata UI:

How to Run the Connector Externally

To run the Ingestion via the UI you’ll need to use the OpenMetadata Ingestion Container, which comes shipped with custom Airflow plugins to handle the workflow deployment. If, instead, you want to manage your workflows externally on your preferred orchestrator, you can check the following docs to run the Ingestion Framework anywhere.

External Schedulers

Get more information about running the Ingestion Framework Externally

Requirements

To access the PowerBI APIs and import dashboards, charts, and datasets from PowerBI into OpenMetadata, a PowerBI Pro license is necessary.
PowerBI dataflows are not yet supported.
OpenMetadata does not support Power BI usage ingestion because the Power BI Usage API does not support Service Principal authentication.
When configuring Azure Authentication, ensure that “Allow public client flows” is enabled. This setting is required to support authentication for public client applications.

PowerBI Admin and Non-Admin APIs:

While configuring the PowerBI ingestion you can choose whether to use the PowerBI Admin APIs to retrieve the metadata or use the PowerBI Non-Admin APIs. Please check below for the the difference in their functionality:
  • Enabled (Use PowerBI Admin APIs) Using the admin APIs will fetch the dashboard and chart metadata from all the workspaces available in the PowerBI instance.
When using the PowerBI Admin APIs, the table and dataset information used to generate lineage is gathered using the PowerBI Scan Result API. This API has no limitations and hence does not restrict getting the necessary data for generating lineage.
  • Disabled (Use Non-Admin PowerBI APIs) Using the non-admin APIs will only fetch the dashboard and chart metadata from the workspaces that have the security group of the service principal assigned to them.
When using the PowerBI Non-Admin APIs, the table and dataset information used to generate lineage is gathered using the PowerBI Get Dataset Tables API. This API only retrieves the table information if the dataset is a Push Dataset. Hence the lineage can only be created for push datasets in this case. For more information please visit the PowerBI official documentation here.

PowerBI Account Setup

Follow the steps below to configure the account setup for PowerBI connector:

Step 1: Enable API permissions from the PowerBI Admin console

We extract the information from PowerBI using APIs, this is a manual step a PowerBI Admin needs to do to ensure we can get the right information. Log in to the Power BI as Admin and enable the tenant settings below from Tenant settings in the Admin portal. Start with Allow service principals to use Power BI APIs, which lets the service principal call the Power BI REST APIs. Of the three settings in the table below, the first authorizes the service principal to call the PowerBI admin APIs. The other two add detail to the GetScanResult response that the connector reads.
Note: The two enhanced metadata settings apply to service principals only when Service principals can access read-only admin APIs is also enabled. Enable all three together, and add the service principal to the security group specified in each setting.
One more admin API setting, Service principals can access admin APIs used for updates, grants write access through the admin APIs. Metadata ingestion is read-only, so this setting is not required.

Step 2: Create the App in Azure AD

Please follow the steps mentioned here for setting up the Azure AD application service principle.

Step 3: Provide necessary API permissions to the Azure AD app

Go to the Azure Ad app registrations page, select your app and add the permissions below to the app for PowerBI service and grant admin consent for the same. All four permissions are required:
  • Dashboard.Read.All: dashboards and the tiles OpenMetadata ingests as charts.
  • Dataset.Read.All: datasets that OpenMetadata ingests as data models, along with their tables and columns. Without it, datamodel and lineage processing is skipped.
  • Report.Read.All: reports, which OpenMetadata also ingests as dashboards.
  • Workspace.Read.All: workspaces, which OpenMetadata stores in the project field of dashboards and data models.
Make sure that in the API permissions section Tenant related permissions are not being given to the app Please refer here for detailed explanation

Step 4: PowerBI Workspaces

The service principal does not take into account the default user workspaces e.g My Workspace. To create a workspace, see Create a workspace in Power BI. For service principal requirements and limitations, see Embed Power BI content with service principal and an application secret.

Python Requirements

Use a Python version supported by the openmetadata-ingestion package that matches your OpenMetadata server. To find the supported range for your release, check the Requires-Python metadata of that release’s ingestion package. To run the PowerBI ingestion, you will need to install:

Metadata Ingestion

All connectors are defined as JSON Schemas. Here you can find the structure to create a connection to PowerBI. In order to create and run a Metadata Ingestion workflow, we will follow the steps to create a YAML configuration able to connect to the source, process the Entities if needed, and reach the OpenMetadata server. The workflow is modeled around the following JSON Schema

1. Define the YAML Config

This is a sample config for PowerBI:

2. Run with the CLI

First, we will need to save the YAML file. Afterward, and with all requirements installed, we can run:
Note that from connector to connector, this recipe will always be the same. By updating the YAML configuration, you will be able to extract metadata from different sources.