Skip to main content

Power BI Embedded lets developers embed interactive reports and dashboards directly inside any web application, customer portal, or ISV product. Two licensing models apply: App Owns Data (no per-user license required — best for external users) and User Owns Data (requires Pro/PPU — best for internal apps). EPC Group recommends App Owns Data for 80% of embedded scenarios.

Key Facts

  • EPC Group recommends App Owns Data for external-facing portals, customer dashboards, and ISV SaaS products.
  • App Owns Data: no per-user license for end users. Capacity serves unlimited external viewers.
  • User Owns Data: requires Power BI Pro ($14/user/month) or PPU ($24/user/month) per viewer.
  • F-SKU capacity pricing: F2 ~$262/mo (dev/test), F8 ~$1,048/mo, F64 ~$4,096/mo (enterprise reserved), F128 ~$8,192/mo.
  • Legacy A-SKU pricing: A1 ~$750/mo through A6 ~$24,000/mo (pause-able — useful for dev/test).
  • Test configurations before coding: Power BI Embedded Playground at playground.powerbi.com.

Last updated by Errin O'Connor, Founder & Chief AI Architect, EPC Group

Enterprise Guide to Power BI Embedded Analytics

Quick Answer: Power BI Embedded lets you add interactive analytics to custom applications. This integration does not require end users to have Power BI licenses.

There are two main patterns:

  • App Owns Data: Uses service principal authentication, requires no user licenses, and is ideal for external portals and ISV products.
  • User Owns Data: Uses user authentication, requires Pro/PPU licenses, and is best for internal applications.

Pricing depends on Fabric capacity SKUs. For instance, F64 costs about $4,096 per month and allows unlimited external users.

EPC Group offers embedded analytics that include:

  • Row-level security
  • Multi-tenancy
  • HIPAA-compliant configurations

Embedded analytics changes Power BI from an internal BI tool to a customer-facing product feature. You can now embed production-grade Power BI visualizations directly in your application. This eliminates the need to export PDFs or create custom charting libraries.

With row-level security, each user will only see their own data.

EPC Group has implemented Power BI Embedded for ISV products, customer portals, healthcare applications, and financial dashboards. This guide covers architecture patterns, pricing optimization, and implementation best practices.

Embedded Analytics Use Cases

Customer-Facing Portal

Embed analytics in a customer portal so clients can view their own data — usage analytics, performance metrics, billing dashboards. Clients do not need Power BI licenses.

Pattern: App Owns Data

Security: Dynamic RLS by customer/tenant ID

Pricing: F-SKU capacity (no per-user cost)

ISV SaaS Product

Embed Power BI analytics as a feature of your SaaS product. Each customer organization sees only their data. White-labeled with your branding.

Pattern: App Owns Data

Security: Multi-tenant RLS with TenantID filter

Pricing: F-SKU capacity, scales with customer count

Internal Business Application

Embed dashboards in internal line-of-business applications (HR portal, sales CRM, operations dashboard). Users authenticate with corporate Entra ID.

Pattern: User Owns Data

Security: Static RLS by user/group identity

Pricing: Power BI Pro or Premium Per User licenses

Healthcare Patient Portal

HIPAA-compliant embedded analytics showing patient health metrics, appointment history, and care plan progress. PHI protection via sensitivity labels and RLS.

Pattern: App Owns Data

Security: Dynamic RLS by patient/provider ID with HIPAA controls

Pricing: F-SKU capacity + compliance configuration

Power BI Embedded Pricing (Fabric SKUs)

SKUCapacity UnitsMonthly Cost (Reserved)Best For
F22 CUs~$262Development and testing
F44 CUs~$524Small-scale dev/test
F88 CUs~$1,048Small production workloads
F1616 CUs~$2,097Medium production
F3232 CUs~$2,048Medium-large production
F6464 CUs~$4,096Enterprise production (recommended)
F128128 CUs~$8,192High-volume enterprise
F256256 CUs~$16,384Large-scale ISV / SaaS

Power BI Embedded Implementation Steps

1

Architecture Design

Choose App Owns Data vs User Owns Data pattern. Design multi-tenant data isolation strategy. Plan capacity SKU based on concurrent user estimates.

2

Development

Implement embed token generation on your server. Integrate Power BI JavaScript SDK into your frontend. Configure row-level security for data isolation per tenant.

3

Security & Testing

Validate RLS with test accounts across multiple tenants. Load test concurrent embedded views. Verify token refresh and error handling.

4

Deploy & Monitor

Deploy to production with Azure Monitor integration. Set up capacity usage alerting. Monitor embed token generation performance and error rates.

App Owns Data vs User Owns Data

FactorApp Owns DataUser Owns Data
AuthenticationService principal — users don't need Power BI accountsEach user authenticates with Entra ID
User LicensingNo per-user Power BI license neededEach user needs Power BI Pro or PPU license
Best ForExternal-facing: customer portals, ISV products, public dashboardsInternal: employee-facing apps where users already have M365
Data SecurityDynamic RLS via embed token with effective identityStandard RLS based on user's Entra ID identity
ScalabilityScales to millions of external users on capacityLimited by Power BI license count
Cost ModelFabric capacity (F-SKU) — fixed monthly cost regardless of user countPer-user licensing — cost scales linearly with users
EPC Recommendation80% of embedded scenarios — default choiceOnly when users already have M365 E3/E5 licenses

Frequently Asked Questions

What is Power BI Embedded?

Power BI Embedded is a Microsoft service that allows developers to embed interactive Power BI reports, dashboards, and visuals directly into custom web applications, portals, and SaaS products. Unlike standard Power BI Service (where users navigate to powerbi.com), embedded analytics brings Power BI content into your own application UI — users interact with analytics without leaving your application and without needing individual Power BI licenses.

What is the difference between App Owns Data and User Owns Data?

App Owns Data (service principal authentication): your application authenticates with a service principal — end users do NOT need Power BI licenses. Best for external-facing applications, ISV products, and customer portals. User Owns Data (interactive authentication): each user authenticates with their own Entra ID credentials and needs a Power BI Pro or Premium license. Best for internal applications where users already have M365 licenses. EPC Group recommends App Owns Data for 80% of embedded analytics scenarios.

How much does Power BI Embedded cost?

Power BI Embedded pricing uses capacity-based SKUs: F2 (2 CUs): ~$262/month — development/testing. F8 (8 CUs): ~$1,048/month — small production workloads. F64 (64 CUs): ~$4,096/month (reserved) — enterprise production. F128 (128 CUs): ~$8,192/month — high-volume production. Legacy A-SKU (Azure-based): A1 ~$750/month to A6 ~$24,000/month. F-SKUs (Fabric) are recommended for new deployments. No per-user licensing for App Owns Data — the capacity serves unlimited external users.

How do you handle row-level security in embedded analytics?

Row-level security (RLS) in embedded analytics ensures each user only sees their data. Implementation: 1) Define RLS roles and DAX filters in the Power BI data model, 2) When generating embed tokens via the API, pass the effective identity (username + roles), 3) Power BI applies the DAX filter at query time, 4) Each user sees only their authorized data. For multi-tenant ISV applications, use dynamic RLS with a TenantID filter — each customer sees only their organization data. EPC Group implements RLS patterns that scale to millions of users across thousands of tenants.

Can I embed Power BI in a React or Angular application?

Yes. Microsoft provides the Power BI JavaScript SDK and React wrapper (powerbi-client-react) for embedding. The React component handles token management, configuration, and event handling. Angular, Vue, and vanilla JavaScript applications use the core powerbi-client SDK. EPC Group has embedded Power BI in React/Next.js, Angular, ASP.NET, and custom SaaS platforms. The embedding process involves: generating embed tokens via the REST API (server-side), passing tokens to the client-side SDK, and configuring the embedded report with filters, page navigation, and event handlers.

What is the Power BI Embedded playground?

The Power BI Embedded playground (playground.powerbi.com) is an interactive tool for testing embedded configurations before implementing in your application. You can experiment with: report embedding with different filter configurations, dashboard and tile embedding, Q&A embedding for natural language queries, paginated report embedding, and custom visual interactions. EPC Group uses the playground during design sessions with clients to prototype embedded experiences before development begins.

Embed Analytics in Your Application

Schedule a free embedded analytics consultation. We will evaluate your application architecture and design an embedded Power BI solution with proper security, multi-tenancy, and performance optimization.

Power BI Embedded Analytics: Application Integration Guide

Power BI Embedded allows developers to integrate interactive reports and dashboards into any web application, customer portal, or ISV product.

There are two licensing models:

  • App Owns Data: No per-user license needed; ideal for external users.
  • User Owns Data: Requires Pro/PPU; best for internal applications.

EPC Group recommends using App Owns Data for 80% of embedded scenarios.

Key facts

  • EPC Group recommends App Owns Data for external-facing portals, customer dashboards, and ISV SaaS products.
  • App Owns Data: no per-user license for end users. Capacity serves unlimited external viewers.
  • User Owns Data: requires Power BI Pro ($14/user/month) or PPU ($24/user/month) per viewer.
  • F-SKU capacity pricing: F2 ~$262/mo (dev/test), F8 ~$1,048/mo, F64 ~$4,096/mo (enterprise reserved), F128 ~$8,192/mo.
  • Legacy A-SKU pricing: A1 ~$750/mo through A6 ~$24,000/mo (pause-able — useful for dev/test).
  • Test configurations before coding: Power BI Embedded Playground at playground.powerbi.com.

App Owns Data vs User Owns Data

Factor App Owns Data User Owns Data
Authentication Service principal (Entra ID app registration) Entra ID — individual user login
End-user license required No — capacity covers all viewers Yes — Pro or PPU per user
Best for External customers, ISV SaaS, customer portals Internal apps, employee-facing dashboards
Row-level security Effective identity passed in embed token User's own Entra ID identity
Multi-tenant support Yes — TenantID filter in RLS No — single tenant only
EPC Group recommendation ✓ Recommended for 80% of scenarios Internal apps only

Capacity pricing options

Embedded analytics runs on capacity licensing, not per-user licensing (for App Owns Data). Choose the SKU that matches your concurrent user load and refresh frequency needs.

Microsoft Fabric F-SKUs (recommended for new deployments)

  • F2 — ~$262/month. Development and testing. Not suitable for production workloads.
  • F8 — ~$1,048/month. Small production apps with light concurrent load.
  • F64 — ~$4,096/month (reserved). Enterprise production — the most common choice for customer-facing portals.
  • F128 — ~$8,192/month. High-concurrency ISV platforms serving thousands of simultaneous users.

Legacy A-SKUs (pause-able — useful for dev/test cost control)

  • A1 — ~$750/month. Smallest production-capable A-SKU.
  • A4 — ~$6,000/month. Mid-range ISV workloads.
  • A6 — ~$24,000/month. Large enterprise or multi-tenant ISV.

Implementing row-level security (RLS)

RLS restricts what data each embedded user sees. The implementation follows three steps regardless of report complexity.

  1. Define DAX filters in the data model — create RLS roles in Power BI Desktop. Each role uses a DAX expression to filter rows (e.g., [Region] = USERNAME()).
  2. Pass effective identity in the embed token — when your application generates the embed token via the Power BI REST API, include the effectiveIdentity parameter with the current user's identifier.
  3. Power BI applies filters at query time — every data query from the embedded report runs through the RLS filter before returning data to the browser. Users never see other users' data.

Multi-tenant RLS

For ISV products that serve multiple customer organizations, adding a TenantID column to your data model is essential. This TenantID must be part of the effective identity. Each customer's embedded session will only access their specific rows. All customers will share one capacity and one dataset.

Developer tools and SDKs

Power BI Embedded uses the JavaScript SDK and a set of framework-specific wrappers. All are open-source and maintained by Microsoft.

  • JavaScript SDK — vanilla JS library for embedding reports, dashboards, tiles, and Q&A. Works in any web framework.
  • powerbi-client-react — React wrapper for the JS SDK. Provides React components and hooks for embedding Power BI content.
  • Angular support — community-maintained Angular wrapper available on npm. EPC Group has production Angular deployments using this wrapper.
  • Power BI Embedded Playground — interactive demo environment at playground.powerbi.com. Test embed configurations, generate code snippets, and validate authentication before writing application code.
  • Power BI REST API — programmatic control of workspaces, reports, datasets, and embed tokens. Required for dynamic token generation in App Owns Data scenarios.

Common use cases

  • Customer-facing portal (App Owns Data) — embed a sales performance or account health dashboard in your customer portal. Each customer sees only their data. No Power BI license required for customers.
  • ISV SaaS product (App Owns Data + multi-tenant RLS) — embed analytics as a paid feature inside your software product. One capacity and one dataset serve all tenants.
  • Internal employee app (User Owns Data) — embed dashboards in an internal SharePoint or Teams application. Users authenticate with their existing Microsoft 365 credentials.
  • Healthcare patient portal (App Owns Data + HIPAA controls) — embed patient-specific health metrics with sensitivity labels and service-principal RLS. SOC 2 Type II audit requirement met by design.

HIPAA and compliance considerations

Healthcare and financial services applications embedding Power BI need additional controls beyond standard RLS.

  • Sensitivity labels — apply Microsoft Purview sensitivity labels to datasets containing PHI or PII. Labels persist when data is exported or downloaded.
  • Service-principal RLS — App Owns Data with service-principal authentication meets SOC 2 Type II audit requirements for external-facing portals handling regulated data.
  • Audit logging — Power BI activity logs capture every embed token request, report view, and data export. Enable in Microsoft 365 compliance center.
  • Data residency — configure Power BI Premium capacity to a specific Azure region to meet data sovereignty requirements.

Frequently asked questions

Do my customers need a Power BI license to view embedded reports?

If you use the App Owns Data model, your application generates an embed token with a service principal. This allows end users to access the embedded report through your application.

They can do this without needing a Power BI license.

You will pay for capacity, which starts at approximately $262 per month. This capacity allows unlimited external viewers.

What is the difference between F-SKUs and A-SKUs?

F-SKUs are the newer Microsoft Fabric capacity model. They are always-on and include Fabric features (Lakehouse, Data Factory, Real-Time Analytics) in addition to Power BI Embedded.

A-SKUs are the legacy Power BI Embedded model. They can be paused when not in use, which makes them cost-effective for development and testing.

EPC Group recommends using F-SKUs for new production deployments.

How do I implement row-level security for multiple customers?

Add a TenantID column to your data model. Create a DAX RLS role that filters rows where TenantID equals the value passed in the effective identity.

When your application creates an embed token for a customer session, include the customer's TenantID in the effectiveIdentity parameter. This ensures that Power BI applies the filter at query time.

As a result, each customer will only see their own data rows.

What is the Power BI Embedded Playground?

The Playground at playground.powerbi.com is a free, interactive test environment for Power BI Embedded.

You can test report embedding and configure authentication. You can also generate code snippets for JavaScript, React, and Angular. Additionally, validate your token generation logic before writing application code. EPC Group uses this as the starting point for every embedded analytics project.

Is Power BI Embedded HIPAA compliant?

Yes, this is possible when set up correctly. Follow these steps:

  • Use App Owns Data with service-principal authentication.
  • Apply Microsoft Purview sensitivity labels to PHI datasets.
  • Enable audit logging in the Microsoft 365 compliance center.
  • Configure data residency to a specific Azure region.

EPC Group designs HIPAA-compliant embedded analytics architectures for healthcare clients.

Build your embedded analytics solution

EPC Group has successfully completed over 1,500 Power BI deployments. These include:

  • Customer portals
  • ISV integrations
  • HIPAA-compliant embedded analytics applications

For more information, call (888) 381-9725, email contact@epcgroup.net, or schedule a Power BI Embedded architecture call.

Related reading

Related EPC Group Services

AI assistant — not human