⚡
Power Embedded
Voltar para o siteSolicitar suporte
English
English
  • Home
    • What is Power Embedded
    • How much does Power Embedded cost?
    • How to start the 30-day free trial
    • Dedicated capacities
    • System Architecture Document
    • System architecture document
  • Schedule a meeting
    • Presentation
    • Installation
    • Technical support
  • Frequently asked questions
    • General Questions
      • How do the Power Embedded savings work?
      • How many users does Power Embedded benefit my company from?
      • Does Microsoft allow the use of Power Embedded? Is it really allowed?
      • What do I need to use Power Embedded?
      • Is it possible to test or PoC the Power Embedded?
      • Do I need to hire the Power Tuning portal? Can't I use Microsoft's?
      • How long does it take to get Power Embedded in my company?
      • Will my users be able to access the reports using mobile devices?
      • Can I cancel Power Embedded? Is there a fine?
    • Licensing
      • Can I use Power BI Pro or Premium per User to Embed?
      • Do I still need a Power BI Pro license, even with Embedded?
      • Can't I share the reports without paying for a license?
      • Isn't accessing reports without a PRO license only possible from the F64?
    • Dedicated capacities
      • Fabric? Power BI Embedded? What are these capabilities?
      • While capacity is paused, no one can access the reports?
      • What are 24x7, 14x6 and 12x5?
      • My company already has Power BI Premium. Do I need to purchase Embedded?
      • A competitor was able to get a much lower Embedded price
      • I don't have an Azure account to contract the capacity
    • Technical questions
      • How does Power Embedded work internally?
      • Power Embedded's internal security
      • Privacy controls and LGPD
      • Differences between Embedded, “Publish to Web” and “Insert Report”
      • Report publishing process
      • System updates
      • System customizations
  • Power Embedded vs Power BI
  • Main features
    • Generative AI - Power Pilot
    • AI on WhatsApp
    • Synchronize with Entra ID
    • Application
    • Dark Mode
    • Scheduling data updates
    • Updating Data
    • Audits
    • Firewall
    • Report catalog
    • Customization of the portal and login screen
    • Sharing with external users
    • Dynamic Models
    • Capacity control
    • Report subscription
    • Integration with Google Analytics
    • Integrated Microsoft, Google and user/password authentication
    • Show report on your system
  • Calculator
  • Azure Partnership
  • News and updates
  • Privacy Policy
  • Portal de Relatórios
    • Visualization portal
      • Filtering reports using query parameters in the URL
    • Report Catalog
    • Navigating Reports
    • Mobile Application (PWA)
    • Report signature
    • Most common problems
      • This report has Row-Level Security (RLS) enabled, and the user is not associated.
      • Power BI service user password has expired
      • You have reached the usage limit of a shared capacity (Pro or PPU) for embedding reports
      • A capacidade não está ligando quando um usuário acessa um relatório
      • Capacity operation failed with error code CapacityNotActive
      • Embedding a DirectLake report is not supported
      • Não foi possível abrir o relatório pois o Power Embedded não enviou as informações do modelo
      • Relatórios utilizando Live Connection com Analysis Services não carregam
      • Sua capacidade de avaliação gratuita do Fabric expirará em X dias
      • Não é possível carregar o modelo devido ao alcance dos limites de capacidade
        • Como reiniciar e alterar a capacidade pelo Power Embedded
        • Como reiniciar e alterar a capacidade pelo Azure
      • Não foi possível carregar os dados para este visual: ClientError_TokenExpired
      • Erro ao exportar relatório - Error Code 400
      • Os visuais não certificados do AppSource ou aqueles adicionados a partir de um arquivo não estão dis
  • Portal de Administração
    • Overview
    • Portal navigation
    • First Access
    • DNS configuration
      • Cloudflare
    • Artefatos
      • Data set
        • Filtragem dinâmica
      • Capacidades
        • Permissões no Azure
        • Configurar a capacidade no Power Embedded
        • Atribuir um workspace à uma capacidade
        • Otimização de custos
        • Redimensionamento automático
        • Auditoria de capacidade
      • Workspaces
      • Gateways
      • Fontes de dados
    • Application
    • Reports
      • Como configurar o workspace
      • Importar relatório
        • Com importar relatório externo
      • Editar relatório
      • Como excluir um relatório
      • Segurança (RLS)
      • Publicar relatório no Power BI
      • Dynamic models
      • Assinatura de relatórios
      • Importação automática de relatórios criados pelo portal de visualização
    • Users
      • Create/edit user
      • Tipos de funções de usuário
      • Métodos de autenticação
      • Autenticação de 2 fatores
      • Importar arquivo CSV
      • Importar do Entra ID
      • Importar com API
      • Bloqueios e senhas
      • Convidar usuário externo para acessar o portal de administração
      • Usuário do Windows AD (Analysis Services)
      • Personalização do método de autenticação por usuário ou grupo
    • Grupos
      • Criar/editar grupo
      • Métodos de autenticação
      • Importar arquivo CSV
      • Importar do Entra ID
      • Synchronize with Entra ID
      • Importar com API
    • Folders
    • Audits
      • Reports
      • Usage Metrics
      • Report Catalog
      • Sent Emails
      • Entities (Changes)
      • Access Logs
      • Capacity
      • Permissions
      • Firewall
      • Audit Tab in Power Pilot
    • Billing
      • Configuring Invoicing
      • Payment Link and Invoice
    • Power Pilot (IA)
      • Prerequisites
      • Hiring an AI
        • Azure OpenAI
        • OpenAI
      • AI Models
      • AI Assistants
      • RLS on PowerPilot
      • Audits
      • AI on WhatsApp
      • Power Pilot Questions
    • Firewall
      • Blocked Login Attempts
      • Ignoring Firewall Rules
      • Firewall Audit page
    • Companies
      • Multiple companies or organizations
    • Warnings
    • Settings
      • Organization
        • Changing the Application Password
        • Atualização de token
        • Google Analytics
        • Configuração do sub-domínio
      • Visualization portal
        • Customizing Colors
        • Personalizar imagens
      • Login screen
        • Customize colors
        • Customize images
        • Authentication methods
      • Parameters
        • General customizations
        • Edit and Creation Mode
      • Emails
    • Migration
    • Systems of support
  • Links úteis
    • Power Embedded sites
    • Price Calculator
    • News
    • Meeting Support
    • Meet Power Tuning
    • Azure Partnership
    • Videos and tutorials
  • Documentação Técnica
    • Installation
      • Fabric Trial
      • Power BI Embedded
    • Commercial Presentation Document
    • Documento de arquitetura do sistema
    • API
      • Automações com APIs
      • Show report on your system
      • Filtragem dinâmica
      • Documentação técnica
Fornecido por GitBook
Nesta página
  • How to set up automatic synchronization with Entra ID
  • How to synchronize groups with Entra ID
  • Automatic Synchronization Operating Rules
  • Permissions for importing Entra ID data
  1. Portal de Administração
  2. Grupos

Synchronize with Entra ID

AnteriorImportar do Entra IDPróximoImportar com API

Atualizado há 2 meses

Entra ID's automatic group synchronization improves user governance by automatically synchronizing Power Embedded's local groups with the groups in Entra ID.

This functionality allows the security, service desk or infrastructure team to manage user and group associations directly from Entra ID, without the need to have permission in Power Embedded, and these changes will be reflected in the system automatically.

In Power Embedded, it was already possible to create groups and also import them from CSV files or from Entra ID or programmatically via the API, greatly speeding up the process of importing users and groups.

However, these options require some manual action by the user or that you create an integration using programming (in the case of the API).

Synchronization is a feature that allows you to synchronize Entra ID data simply and automatically, making it easier to manage security, RLS and permissions.

How to set up automatic synchronization with Entra ID

In order for group synchronization with Entra ID to work correctly, you need to define how the system will behave when synchronizing.

To configure the synchronization behaviour, go to the “Settings” menu > “Integrations” tab > Group synchronization with Entra ID.

Below, we'll explain in detail what each permission means and how it affects the synchronization process:

Create user in system when added to synchronized groups: This permission is responsible for automatically registering in Power Embedded and associating with the respective groups in the system, users who are added to synchronized groups in Entra ID. If this permission is disabled, new users created in Entra ID will not be added to the system automatically.

What to do when a user is removed from a synchronized group in Entra ID?

There are four options for defining what the system will do when a user is removed from a group that is synchronized with Entra ID, and understanding each of them is crucial to making effective use of the functionality:

  1. Disabled: This is the system's default option, and if it is checked, removing the user from the synchronized group in Entra ID will have no effect in Power Embedded.

  2. Exclude the user from the system: When a user is removed from an Entra ID group, they will automatically be removed from that same group in Power Embedded. If the user is still part of any other synchronized group, the system will only remove them from the Power Embedded groups that the user is no longer part of in Entra ID. If the user is no longer part of any synchronized group, they will be permanently removed from the system, including their settings and permissions.

  3. Block the user from the system: When a user is removed from an Entra ID group, they will automatically be removed from that same group in Power Embedded. If the user is still part of any other synchronized group, the system will only remove them from the Power Embedded groups that the user is no longer part of in Entra ID. If the user is no longer part of any synchronized group, they will be blocked in the system, preventing them from accessing it, but still retaining their permissions and settings. This is a more conservative option than deletion, guaranteeing easy recovery (just unblock the user) in the event of an error when removing the user from the Entra ID group.

  4. Remove the user from the group in the system: When a user is removed from an Entra ID group, they remain registered in the portal, but are only removed from the specific group from which they were removed in Entra ID. Unlike the other options, the user remains active in the portal, but without association with the group from which they were removed.

Synchronization on the portal is done automatically once a day. However, if you need to force this synchronization, you can do it in two ways:

  1. Clicking on the “Synchronize Now” button to synchronize all groups.

  2. Choose a specific group, click the “Actions” button and then the “Synchronize” button to synchronize only the selected group.

How to synchronize groups with Entra ID

For synchronization to actually take place, you need to select which groups you want to synchronize.

Step 1: Go to the “Groups” screen Step 2: Click on the “Synchronize” button Step 3: On the “Groups synchronized with Entra ID” screen, click on the “Add Groups” button. Step 4: All Entra ID groups will be listed. Select one or more of the groups you want to synchronize and save.

Automatic Synchronization Operating Rules

  1. Synchronization will only be carried out if you have enabled the automatic creation of users OR have configured an action to be carried out when the user is removed from Entra ID, other than the “Disabled” option.

  2. If the group selected for synchronization does not exist in Power Embedded, it will be created automatically in the system.

  3. If a group already exists in the system with the same name that was selected for synchronization with Entra ID, that group will be included in the synchronization. If any user is part of this group in Power Embedded and is not part of this group in Entra ID, they will be removed from the group in Power Embedded, and may even be blocked or removed from the system, depending on the synchronization settings.

  4. Automatic synchronization runs daily at 10pm.

Permissions for importing Entra ID data

To be able to import user and group data from Entra ID, you need to assign some permissions to the Service Principal, created in the Azure Portal, used by Power Embedded to communicate with your environment.

On the application screen, click API permissions in the side menu and then Add a Permission.

On the next screen, select the Microsoft Graph option.

Then select the Application permissions option.

In the next tab, search for Directory and select the first option Directory.Read.All and click Add permissions.

Finally, grant the administrator's consent by clicking on Grant admin consent for.

Now you can import users and groups from Azure AD (Entra ID) into Power Embedded.

If you don't want to synchronize groups, but just want to perform a one-off import of groups and their users, read the article .

If you want to import a few users at a time, instead of importing or synchronizing a group, read the article .

On the , search for the name of the application you created (The default name is PowerEmbedded-App).

Importing Groups from Entra ID
Importing Users from Entra ID
Application Registration screen