You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

本地Power BI Server外网Web应用免登需求:通用AD凭据程序化配置问询

Solution for Embedding On-Prem Power BI Dashboard Without Secondary Login (Forms Auth Web App)

Got it, let's tackle this since you're dealing with an on-premises Power BI Report Server and a Forms Auth web app—no Azure AD needed here. The key to eliminating that annoying secondary login prompt is using Trusted Ticket Authentication with a dedicated AD service account. Here's how to make it work, step by step:

Prerequisites

  • A dedicated AD user account (service account) that has been granted view access to the target dashboard/report on your Power BI Server.
  • Ensure your Power BI Report Server allows trusted ticket generation (enabled by default, but we'll verify configuration later).
  • Your web app must be able to make HTTP requests to the Power BI Server's internal endpoints.

Step 1: Configure Power BI Server for Trusted Tickets

First, make sure your web app's server is allowed to request trusted tickets. Edit the RSReportServer.config file on your Power BI Server and add your web app's domain/IP to the trusted hosts list:

<TrustedHosts>
  <Host>your-web-app-server-domain-or-ip</Host>
</TrustedHosts>

Restart the Power BI Report Server service after saving this change.

Step 2: Programmatically Generate a Trusted Ticket

When a logged-in user in your web app wants to view the dashboard, your app will generate a short-lived trusted ticket using the dedicated AD service account. This ticket acts as a one-time authentication token for the Power BI dashboard.

Here's a C# example of how to fetch the ticket:

using System.Net;
using System.Collections.Specialized;

public string GetPowerBITrustedTicket(string powerBiServerUrl, string serviceAccountUsername, string serviceAccountPassword, string domain, string dashboardPath)
{
    var ticketEndpoint = $"{powerBiServerUrl}/ReportServer/rswebservice.asmx/GetTrustedTicket";
    
    using (var client = new WebClient())
    {
        // Authenticate the service account against the Power BI Server
        client.Credentials = new NetworkCredential(serviceAccountUsername, serviceAccountPassword, domain);
        
        var formData = new NameValueCollection
        {
            {"userName", serviceAccountUsername},
            {"password", serviceAccountPassword},
            {"authority", domain},
            {"reportPath", dashboardPath} // Example: "/Dashboards/MonthlySalesDashboard"
        };
        
        var responseBytes = client.UploadValues(ticketEndpoint, "POST", formData);
        return System.Text.Encoding.UTF8.GetString(responseBytes);
    }
}

Step 3: Embed the Dashboard with the Ticket

Once you have the trusted ticket, embed the dashboard in your web app's iframe by appending the ticket as a query parameter. This skips the login prompt entirely:

<iframe 
  src="https://your-powerbi-server/ReportServer/Pages/ReportViewer.aspx?/Dashboards/MonthlySalesDashboard&rs:Command=Render&trustedticket=INSERT_YOUR_TICKET_HERE"
  width="100%" 
  height="800px" 
  frameborder="0"
></iframe>

If you're using a redirect instead of an iframe, send the user to the same URL with the trustedticket parameter attached.

Step 4: Programmatically Update Credentials

To modify the AD service account credentials later, store them in a secure, encrypted configuration store (like your app's encrypted appsettings.json, or a dedicated secrets manager). Then, build an admin interface in your web app to update these values securely.

For example, in a .NET app, retrieve credentials from config like this:

var serviceAccountUsername = _configuration["PowerBiSettings:ServiceAccount:Username"];
var serviceAccountPassword = _configuration["PowerBiSettings:ServiceAccount:Password"];
var domain = _configuration["PowerBiSettings:ServiceAccount:Domain"];

When you need to change the credentials, update the stored values—your app will pick up the new details the next time it generates a trusted ticket.

Key Security Notes

  • Keep the dedicated AD account to minimum permissions only (just view access to the required dashboards—never use a high-privilege account).
  • Trusted tickets expire after 10 minutes by default, so generate a new ticket every time a user accesses the dashboard.
  • Add an extra layer of authorization in your Forms Auth app: check if the logged-in user has permission to view the dashboard before generating the ticket.

内容的提问来源于stack exchange,提问作者SlickVik

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:41:03