Skip to content

Access to the Resource is forbidden when using Power BI & the Governance.storage report#1268

Description

馃悰 Problem

When using the Governance.storage PowerBI Report, there are a few tables, 'AdvisorRecommendations, AdvisorReservationRecommendations, Disks, ManagementGroups' that run Azure Resource Graph Queries to populate the report.聽

I am able to get this report to work if I setup PowerBI to use a Global Admin Account to connect to Azure Resource Graph. Which seems overkill, and from documentation I've seen, only Reader should be required.聽

If I try to run the same Azure Resource Graph queries that are being used in PowerBI with az-cli/powershell and Reader Access, I can execute the queries just fine and don't have any access issues. But when running the PowerBI report, if it's done with anything less than Global Admin, the report fails with forbidden errors.

The Azure Resource Graph queries in PowerBI run at a tenant level, and I suspect this is why these fail with just Reader access.聽

馃懀 Repro steps

  1. Run the Governance.storage.pbit Power BI Report.聽

  2. Connect to Azure Resource Graph using an account with Reader Access only.聽

馃 Expected

It would be good to get clarity on what the minimum access requirements are in order to run the Governance.storage PowerBI Report. Or is Global Admin really the minimum required for this report?

馃摲 Screenshots

Image

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Needs: Attention 馃憢Issue or PR needs to be reviewed by the author or it will be closed due to no activityOKR: 1.2 ReliabilityIssues that improve reliability and resiliencyResolution: ExternalIssue is external to the FinOps toolkitTool: Power BIPower BI reportsTool: Resource GraphExternal issues related to Azure Resource Graph

Type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions