Security
The Embedsy Portal runs inside your own Azure environment, next to your Power BI data. Embedsy does not host, store or process your business data on its own infrastructure, so there is no vendor platform in the middle to trust with it.
The short version
Runs in your Azure subscription
The portal is deployed into your own Azure environment, in the region you choose.
Your data stays with you
Reports, business data and user accounts live in your environment and aren't sent to Embedsy.
Least-privilege access
A dedicated service principal sees only the Power BI workspaces you add it to.
You decide who sees what
Roles control which reports each user sees, and row-level security controls which data.
Deployed into your Azure environment
Installing the Embedsy Portal creates its resources in a resource group in your own Azure subscription, in the Azure region you choose during installation. Your Power BI reports stay in your Power BI or Fabric tenant. The portal adds the sign-in, access control and branding layer on top, without moving your data.
- Azure App Service runs the portal itself.
- Azure SQL Database holds the portal's technical data.
- Azure Storage holds files such as logos, icons and theme files.
Because these resources are yours, they fall under your Azure subscription's own access controls, policies and monitoring. See the Azure resources in detail.
What Embedsy receives, and what it doesn't
Everything the portal works with lives in your Azure subscription: report content and the underlying business data, end-user accounts and access configuration, Embedsy Studio apps and the data they read or write, and the portal's configuration, branding and logs. None of it is sent to Embedsy.
For billing and technical purposes, your deployment reports usage information to us: the number of users and which features are used. It consists of counts only, with no names, email addresses or other details about your users, and no report content or business data. Beyond that, we hold the account and billing details you give us when you subscribe.
The full detail, including your rights, is in our Product Privacy Statement.
When we access your environment
We access your environment only when you ask for support that needs it. Our staff may then see data inside your portal, including personal data, and use it only to resolve your request. You remain the data controller for everything in your portal.
Least-privilege access to Power BI
The portal reads your reports through a dedicated service principal, an app registration in your own Microsoft Entra tenant. You decide exactly what it can reach.
- It sees only the Power BI workspaces you add it to as a member. Every other workspace stays invisible to the portal.
- It sits in its own Entra security group, and we recommend enabling the required Fabric tenant settings for that group only, not for your whole organisation.
- On a paid Fabric or Power BI Embedded capacity it gets the Contributor role, so the portal can pause the capacity when nobody is using it and start it again on the next sign-in.
- Its client secret is entered by a super admin in the portal settings, together with its expiry date. You rotate it in Entra on your own schedule.
- Its Microsoft Graph and Power BI API permissions are granted by an admin in your tenant, with admin consent, during installation.
The exact permissions, and the step-by-step setup with screenshots, are in the installation guide: setting up the service principal.
Who signs in, and what they can see
- Sign-in methods you choose. Microsoft Entra ID, Google, or email and password managed by the portal, alone or side by side.
- No open sign-up unless you want it. Turn off self-registration and only admins can add users.
- Roles decide which pages a user sees. Every page is assigned to one or more roles.
- Row-level security decides which data. Power BI RLS filters each report to the rows a user is allowed to see.
- Entra groups as roles. Portal roles can follow your Entra groups, so removing someone from a group removes the matching portal role too.
- Check before you share. Admins can use View As to see the portal exactly as a given role sees it.
More in roles, pages and users and Entra groups as roles.
Public sharing stays under your control
The optional Public Embed feature publishes reports or visuals without a login. Anyone with the link can see that data, so it comes with its own guard rails.
- A super admin has to switch the feature on, and only roles with embed rights can create public embeds.
- It uses its own service principal, separate from the portal's main one. We recommend dedicated workspaces for public content, so nothing outside them can ever be exposed.
- Deleting an embed revokes its link immediately. Switching the feature off stops every public link at once.
Backups and deletion
Installation sets up a backup policy for the portal's Azure SQL database, which allows point-in-time restore within the retention period. You can adjust that policy in Azure like any other database of yours.
Because every portal resource lives in your subscription, removing them removes your data: deleting the portal's resources deletes everything in them.
Questions from your security team?
Send us their questions, or set up a call with your IT team. To report a security issue, email info@embedsy.io.
Prefer a live walkthrough? Book a free demo
