# Reporting Hub Knowledge Center

### Watch our Platform Demo!

{% embed url="<https://youtu.be/Fs7IcrAhqtM>" %}

### Turn-Key Power BI Delivery Platform using *Power BI Embedded*&#x20;

The Reporting Hub is a web-based business intelligence platform that seamlessly integrates with Power BI using Embedded technology. It is a plug 'n' play white label application that deploys to your Azure environment and allows you to instantly deliver Power BI in a more efficient and cost effective manner.

#### See the Reporting Hub featured in Microsoft Documentation:&#x20;

{% embed url="<https://learn.microsoft.com/en-us/power-bi/developer/embedded/embedded-analytics-accelerators>" %}

#### Watch the Microsoft Partner Solution Showcase:

{% embed url="<https://microsoft.github.io/PartnerResources/skilling/microsoft-partner-showcase/reportinghub>" %}

## How Does it Work?

![](/files/kRnub5aFTflpLtMreven)

Reporting Hub integrates with your Power BI Tenant and Microsoft Entra ID (or other supported Auth Scheme) within YOUR Azure environment. The entire solution is contained within your environment and no changes are required to your existing data architecture or Power BI content.

## Understanding Microsoft Licensing Terms

When deploying and operating the Reporting Hub, it's important that you understand and are in compliance with Microsoft's Power BI licensing terms.  It is the customer's responsibility to ensure compliance with Microsoft with respect to your use of Power BI.&#x20;

Please see link below from Microsoft to learn and ensure compliance with special attention paid to the following section:

**"Microsoft Power BI**

**Definitions**

“Customer Application” means an application or any set of applications that adds primary and significant functionality to the Embedded Capabilities and that is not primarily a substitute for any portion of Microsoft Power BI services.

“Embedded Capabilities” means the Power BI APIs and embedded views for use by an application.

**Hosting Exception for Embedded Capabilities**

Customer may create and maintain a Customer Application and, despite anything to the contrary in Customer’s volume licensing agreement, combine Embedded Capabilities with Customer Data owned or licensed by Customer or a third party, to create a Customer Application using the Embedded Capabilities and the Customer Data together. Any Power BI content accessed by the Customer Application or its end users must be stored in Microsoft Power BI Premium capacity. Customer may permit third parties to access and use the Embedded Capabilities in connection with the use of that Customer Application. Customer is responsible for that use and for ensuring that these terms and the terms and conditions of Customer’s volume licensing agreement are met by that use.

**Limitations**

Customer may not

* resell or redistribute the Microsoft Power BI services, or
* allow multiple users to directly or indirectly access any Microsoft Power BI feature that is made available on a per user basis."

{% embed url="<https://www.microsoft.com/licensing/terms/en-US/productoffering/MicrosoftPowerPlatform/EAEAS#ServiceSpecificTerms>" %}

## Getting Started

Follow our handy guides to get started with everything you need.

{% content-ref url="/pages/YU5Ppdk3phslmIwIOwhE" %}
[Required Azure Services](/getting-started/required-azure-services)
{% endcontent-ref %}

{% content-ref url="/pages/mR5xkJjszCkXSyreMmIV" %}
[Deployment Step-by-Step](/getting-started/deployment-step-by-step)
{% endcontent-ref %}


# Required Azure Services

Everything you need to deploy the Reporting Hub

The Reporting Hub is a cloud based web application that is installed and deployed directly to your Azure Environment. In order to deploy the Reporting Hub the following Azure Services are required.  &#x20;

{% hint style="success" %}
**Good to know:** The Reporting Hub Installer will install and properly configure all required Azure resources along with the application itself with your Azure Resource Group.  If preferred, you can also manually install the Azure resources.
{% endhint %}

## Azure Services Required

* [x] [Fabric Capacity or Power BI Embedded Capacity](#power-bi-embedded-capacity)
* [x] [Azure App Service](#azure-app-service)
* [x] [Azure SQL Database](#azure-sql-database)
* [x] [Azure Translator (Free)](#azure-translator)

{% hint style="info" %}
**Please note:** Any and all Azure services are not included within the Reporting Hub subscription. These services are deployed to your organizations' Azure instance and will fall under your Azure subscription. Any and all Azure subscription fees are the responsibility of your organization. &#x20;
{% endhint %}

### Fabric Capacity/Power BI Embedded Capacity

The Reporting Hub is a plug 'n' play, no-code solution for Power BI embedded analytics. The Capacity (Power BI Embedded Capacity or Microsoft Fabric Capacity) allows you to share your Power BI content with users who don't have a Power BI or Microsoft license. Both Fabric and Power BI Embedded Capacities are capacity-based licenses, which means you are paying for a dedicated amount of computing resources vs. a specific number of users. We recommend organizations start with a ***F2 node*** and scale according to need. For more information on pricing and capacity planning, please refer to the Microsoft documentation link below.&#x20;

{% hint style="success" %}
**Good to know:** The Reporting Hub Capacity Manager will allow you to reduce this monthly capacity cost by programmatically activating and pausing your Capacity based on usage. By default, the Reporting Hub will keep your Capacity paused when not in use. When your capacity is paused, you will not incur costs.
{% endhint %}

{% embed url="<https://azure.microsoft.com/en-ca/pricing/details/power-bi-embedded>" %}

{% hint style="info" %}
**NEW Fabric Capacities** are now supported!  With Reporting Hub *version 6.4*, you can now take advantage of Microsoft's new Fabric Capacities with your Reporting Hub.&#x20;
{% endhint %}

{% embed url="<https://azure.microsoft.com/en-ca/pricing/details/microsoft-fabric/>" %}

We recommend using the Microsoft Fabric Capacity Metrics app to monitor your Fabric usage.

{% embed url="<https://learn.microsoft.com/en-us/fabric/enterprise/metrics-app>" %}

Visit our [Embedded Capacity Admin](broken://pages/am2cyvZprcdF7v7BvOuV) page for more details on Power BI Embedded Capacity.

### Azure App Service

An Azure App Service is a fully managed service with built-in infrastructure maintenance, security patching and scaling for web apps within Azure. The Reporting Hub application instance is deployed and hosted to this App Service within your Azure environment. We recommend a ***S1*** ***instance*** for production scenarios. Please refer to the Microsoft documentation link below for more information. &#x20;

{% embed url="<https://azure.microsoft.com/en-ca/pricing/details/app-service/windows>" %}

{% hint style="info" %}
**Please note:** The minimum App Service tier required is a **B1** Basic Service Plan. The Free or Shared plans *WILL NOT* support the application.&#x20;
{% endhint %}

### Azure SQL Database

An Azure SQL Database is required to store the Reporting Hub application configuration, log and audit files. This database is very small and can run on the lowest database tier available in Azure.  If your organization does not have an exiting Azure SQL instance, we recommend a single database **'Basic' Service Tier** and **'DTU' Purchase model.** For more information on region specific pricing please refer to the Microsoft documentation link below.

{% embed url="<https://azure.microsoft.com/en-us/pricing/details/azure-sql-database/single>" %}

### Azure Translator

The Reporting Hub is a multi-language application that can be configured into any language. The Azure Translator service is used to complete language translation. There is **no cost** to this service as the Reporting Hub leverages the free service instance only. This service is required even if you do not plan on using the multi-languages feature.

{% embed url="<https://azure.microsoft.com/en-us/products/cognitive-services/translator/#overview>" %}

## What if I don't have an Azure Instance?

**No Azure? No problem!**&#x20;

All you need to do is follow the link below to set up a Pay As You Go Azure account to get started. Once you have an Azure subscription in place you can proceed with deploying the Reporting Hub.&#x20;

{% embed url="<https://azure.microsoft.com/en-us/pricing/purchase-options/pay-as-you-go>" %}


# Deployment Step-by-Step

Get up and running with the Reporting Hub!

{% hint style="success" %}
**Get Started** with a 30-day Growth tier free trial. No obligation, no credit card required. *Please note:* *Azure services costs may still apply.*
{% endhint %}

Follow our Step-by-Step tutorials to get started with the Reporting Hub.

1. **Install and deploy the Reporting Hub web application and required Azure services**

{% content-ref url="/pages/1H8wP6dzjP8qdChwnaMg" %}
[Self-Serve Guided Install](/getting-started/deployment-step-by-step/self-serve-guided-install)
{% endcontent-ref %}

&#x20; 2\.   **Configure your Power BI Admin Settings**

{% content-ref url="/pages/ZTurS8WKwsHYDkpOORRM" %}
[Enable Power BI Service Settings](/getting-started/deployment-step-by-step/enable-power-bi-service-settings)
{% endcontent-ref %}

3. **Configure your Reporting Hub App Settings**

{% content-ref url="/pages/D6QLOw6IhUgl69x7qJL6" %}
[Configure Reporting Hub App Settings](/getting-started/deployment-step-by-step/configure-reporting-hub-app-settings)
{% endcontent-ref %}

4. **Set Your Landing Page**

{% content-ref url="/pages/fmYjHXgF7pL3ZhniLF1B" %}
[Set Your Home Page](/getting-started/deployment-step-by-step/set-your-home-page)
{% endcontent-ref %}


# Self-Serve Guided Install

Install and deploy the Reporting Hub with our guided install service

{% hint style="success" %}
**Get started** with a 30-day Growth-tier free trial. No obligation, no credit card required. *Please note:* *Azure services costs may still apply.*
{% endhint %}

## Getting Started

Installing Reporting Hub is simple, easy, and takes approximately 20 minutes. The Reporting Hub web application and required [Azure services](/getting-started/required-azure-services) can all be fully deployed by following our guided installation service.&#x20;

**Please review the checklist below before getting started:**

* [x] You have an active Azure Pay-as-you-go subscription.
* [x] You have [Global Admin](https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#global-administrator) and [Subscription Owner](https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal-subscription-admin) roles within your Azure subscription to complete the installation.
* [x] You have a Power BI online account.
* [x] You are agreeing to install the required [Azure services](/getting-started/required-azure-services).
* [x] You agree to the following Azure services setup conditions:

{% hint style="warning" %}
**Azure Services Setup Conditions**: *Any and all Azure services are not included within your Reporting Hub subscription. These services are deployed to your organizations' Azure instance and reside within your Azure subscription. Any and all Azure subscription fees are the responsibility of your organization. Once deployed any changes or ongoing administration of these services are the responsibility of your organization.*
{% endhint %}

#### Ready to Get Started?  Click the link below and follow along!

<table data-card-size="large" data-view="cards" data-full-width="false"><thead><tr><th align="center"></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><a href="https://thereportinghub.com/install-today">Click Here to Begin Installation</a></td><td><a href="/files/Jgc1vDcVzPceztNqWgCT">/files/Jgc1vDcVzPceztNqWgCT</a></td><td><a href="https://thereportinghub.com/install-today">https://thereportinghub.com/install-today</a></td></tr></tbody></table>

The tutorial below outlines the step-by-step process to install and deploy the Reporting Hub and associated Azure services within your Azure environment. For each Azure resource, you will have the option to select an existing resource or create a new resource.&#x20;

{% hint style="success" %}
If you’re selecting existing resources, **use the** [**Azure Service Setting**](#azure-services-configuration-settings) **requirements documentation to verify** that each resource is configured correctly. **Correct any mismatched settings before continuing**otherwise, the installation will fail.
{% endhint %}

{% embed url="<https://youtu.be/54tjH4FiKTw>" %}

## Installation Steps

The following is a step by step of each page in the installation wizard to guide you through what is happening on each page.

1. Grant **Application Admin Consent**: \
   After signing in, you will be prompted to grant application admin consent to the Reporting Hub Installer application. This consent will allow the Installer application to deploy the applicable Azure services and Reporting Hub web application within your Azure environment. You must grant consent to proceed and complete the installation.

<div align="center"><figure><img src="/files/qz2wvodrPUB2tFFHz6Bi" alt=""><figcaption><p>Admin Consent Form</p></figcaption></figure></div>

{% hint style="info" %}
Reporting Hub Installer is a Microsoft **'*****verified***' application, and Shift Analytics Inc. is a Microsoft ISV Partner as identified on the Admin Consent page. This [admin consent](https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/manage-application-permissions?pivots=portal) can be revoked at anytime following deployment via your Azure Portal.
{% endhint %}

2. Start by selecting your **Azure Subscription** and **Azure Subscription** from the dropdown list and click **Next**.

{% hint style="warning" %}
If the **Select Subscription used for the Reporting Hub** dropdown is empty, you may not have **Subscription Owner** permission for any Azure Subscriptions.
{% endhint %}

<div align="left"><figure><img src="/files/nXEHpEi2NC5x1IUsSDkI" alt=""><figcaption></figcaption></figure></div>

3. Next, select your **Azure Resource Group**. You will be presented with the option to either select an existing Resource Group ***or*** add a new Resource Group.

* If using an existing Resource Group, select it from the dropdown list and click **Next**. If you are using existing Azure resources instead of creating new ones, select the Resource Group that those resources belong to.
* If adding a new Resource Group, select **Add New** from the dropdown list and fill in the required fields; then click **Next**.&#x20;

{% hint style="success" %}
It is recommended to create a new Resource Group. If you are in the East US region, we recommend choosing East US 2 to ensure a successful deployment.
{% endhint %}

<div align="center"><figure><img src="/files/jvryuS8bHqMVMACznUU1" alt="" width="563"><figcaption><p>Example of creating a new Resource Group</p></figcaption></figure></div>

4. Select your **Azure App Service**. You will be presented the option to either use an existing App Service ***or*** add a new App Service.
   1. If using an existing App Service,
      1. Select the App Service.&#x20;
      2. Then, select an existing App Service slot ***or*** select **Add New** from the dropdown list.&#x20;
      3. Then, click **Next**.
   2. If adding a new App Service,
      1. Select **Add New** and fill in the required fields.&#x20;
      2. Then, click **Next**.&#x20;

{% hint style="success" %}
Good to Know: Your app service name determines the default domain for your website: `<AppServiceName>.azurewebsites.net`.
{% endhint %}

<div align="center"><figure><img src="/files/cuebshu7XGPH3RIxlxUS" alt="" width="563"><figcaption><p>Example of adding a new App Service.</p></figcaption></figure></div>

{% hint style="info" %}
The minimum [App Service Plan](https://learn.microsoft.com/en-us/azure/app-service/overview-hosting-plans) required is a **B1** Basic Service Plan. B1 is only for development or testing purposes if selected periods of poor performance in the application are expected. \
An **S1** (Standard) is recommended for production.
{% endhint %}

5. Select your **Azure SQL Server** & **Azure SQL Database.** You will be presented with the option to either select an existing SQL Server ***or*** add a new SQL Server.
   1. If selecting an existing Azure SQL server:
      1. Select it from the dropdown menu
      2. Select an existing database ***or*** create a new database. You will be asked to enter your SQL Server credentials if you're accessing an existing database. **Note that any data will be overwritten in an existing database.**
   2. If adding a new SQL Server:
      1. Select **Add New** from the dropdown list
      2. Name your SQL Server and Database
      3. Click **Next**.

<div align="center"><figure><img src="/files/oUw0XEdMpqH5uLsmFVFW" alt="" width="563"><figcaption><p>Example of creating a new SQL Server and database</p></figcaption></figure></div>

6. Select your **Embedded Capacity**. You will be presented with the option to either select an existing Capacity ***or*** add a new Capacity.
   1. If selecting an existing Capacity, select it from the dropdown list and click **Next.**
   2. If adding a new Capacity
      1. Select **Add New**
      2. If you wish to deploy an F2 **Fabric Capacity,** check the box. Leave it unchecked if you want to create an A1 Embedded Capacity.
      3. Name your capacity and select **Next**.

{% hint style="success" %}
**Good to Know:** Reporting Hub will, by default, manage (pause/resume) the capacity selected or created at this stage based on in-app activity. This may affect existing workloads in Power BI/Fabric if you select an existing capacity.
{% endhint %}

<div align="center"><figure><img src="/files/VaPMDqAzmdMSiPFbTkCi" alt="" width="563"><figcaption><p>Example of creating a new F2 Fabric Capacity</p></figcaption></figure></div>

7. Register your **Azure AD Application** and **Service Principal** and select your default **Authentication Scheme**.
   1. Name your application and service principal. Consider incorporating "App" and "SP" into your naming conventions to clearly define them.

<div align="center"><figure><img src="/files/SNEii9fmAPBMS8bBmQz3" alt="" width="563"><figcaption><p>Name your App Registration</p></figcaption></figure></div>

{% hint style="success" %}
**IMPORTANT:** Ensure you take note of your **Application name** and **Service Principal** name, as you will need this later when granting access within the Power BI Service.
{% endhint %}

8. Select your **Azure Translator**. You will be presented with the option to either select an existing Translator ***or*** add a new Translator.
   1. If selecting an existing Translator, select from the dropdown menu and click **Next**.
   2. If adding a new Translator:
      1. Select **Add New**
      2. Name your Translator
      3. Click **Next**.

<div align="center"><figure><img src="/files/fjXEiqSEOGlOpSjrMbFm" alt="" width="563"><figcaption><p>Ecample of creating a new translator</p></figcaption></figure></div>

The installer will now run a series of checks and deploy your new services and/or connect with your existing services. Each service will return a result of "Done" if successful, or "Failed" if unsuccessful.&#x20;

9. Following successful completion of the Azure services, click **Next**.

{% hint style="warning" %}
**Deployment Failures:** First, review the [**Installation Failures**](/getting-started/deployment-step-by-step/self-serve-guided-install/installation-failures) page and follow the steps for the error you’re seeing. If the error is related to location/region, refer to the [**Location (Region) Errors**](/getting-started/deployment-step-by-step/self-serve-guided-install/installation-failures#deployment-failure-location-not-available) section.
{% endhint %}

<div align="center"><figure><img src="/files/BwSAmR0LSeR1o7KwPuFU" alt="" width="563"><figcaption><p>A successful verification.</p></figcaption></figure></div>

10. You will be prompted to grant application admin consent for your new Reporting Hub Azure Entra ID Application. This consent allows your Reporting Hub application to access your Microsoft tenant and Power BI.

{% hint style="info" %}
This subsequent admin consent is to grant permission for ***your*** deployed application instance of Reporting Hub to access ***your*** Microsoft tenant details, including Power BI. It will show as "unverified".

This is the expected result, given you have yet to verify your application. Please reference Microsoft's documentation for more information on how to verify your application if desired: [Mark App As Publisher Verified](https://learn.microsoft.com/en-us/azure/active-directory/develop/mark-app-as-publisher-verified).
{% endhint %}

11. After providing consent, the Reporting Hub application installation will be initiated. This step may take several minutes, depending on your Azure Region.
12. The installer will then run a series of checks and start your new Reporting Hub application.&#x20;
    1. If successful, you will receive a success message with the URL link to your application. Click the link to access your application.
    2. If unsuccessful, you will receive a failure message; review the [Installation Failures](/getting-started/deployment-step-by-step/self-serve-guided-install/installation-failures) page.

       <div align="center"><figure><img src="/files/ssReEQsjhq3dxhLH4TMy" alt=""><figcaption></figcaption></figure> <figure><img src="/files/QTKyq61r9tRHMBR3tTaC" alt=""><figcaption><p>Click the link to access your application.</p></figcaption></figure></div>

## After Installation: Power BI Configuration

{% hint style="warning" %}
You **must complete** the Power BI Service Settings and Reporting Hub App Settings configurations before you can embed content in your application.
{% endhint %}

After you have completed the installation of the Reporting Hub application and Azure services, you will need to ensure Power BI is configured correctly to allow permission to the Reporting Hub.

Please follow the two guided tutorials to finish your deployment of the application

{% content-ref url="/pages/ZTurS8WKwsHYDkpOORRM" %}
[Enable Power BI Service Settings](/getting-started/deployment-step-by-step/enable-power-bi-service-settings)
{% endcontent-ref %}

{% content-ref url="/pages/D6QLOw6IhUgl69x7qJL6" %}
[Configure Reporting Hub App Settings](/getting-started/deployment-step-by-step/configure-reporting-hub-app-settings)
{% endcontent-ref %}

***

## Azure Services Configuration Settings

{% hint style="info" %}
**Please note**: this section only applies if you're using pre-existing Azure services. If you are creating new services as part of the guided installation process, you can omit this section as the installer will ensure these services are configured correctly.
{% endhint %}

The following content is provided here as a reference **if needed** during the installation. If you have successfully deployed your application, move on to the Power BI Service Settings link above.

If you would prefer to create the Azure services manually before executing the installer, below are the minimum Azure service requirements and configuration details required. Ensure that all of your Azure Services settings match the below configuration, and then run the installer and select the created resources. All Azure services can be additionally scaled as required based on your needs.

All of the Azure services need to be in the same Azure subscription. All of the Azure services except for the Translator need to be in the same resource group, which you will be prompted to select during installation. They do not need to be in the same region.

<details>

<summary>Azure SQL Server</summary>

If a setting is not specified here, use the default value in the Azure portal.

**When creating the Server, ensure:**

* Set the Azure **Subscription** and **Resource group** to the same as your other Reporting Hub services are in.
* Set **Authentication method** to **use both SQL and Microsoft Entra authentication**.
* Set the **Microsoft Entra admin**. We recommend setting it to the user that will perform the Reporting Hub installation.
* Set the **Server Admin login** and **password**, or, if using an existing server, ensure you have the credentials. You can validate that your credentials are correct by logging in through the Query Editor on the Azure portal.
* Under **Networking**, enable **Allow Azure services and resources to access this server**.

Once the server has been created, under **Security** > **Networking**,&#x20;

* Ensure **Public network access** is set to **Selected networks**.

</details>

<details>

<summary>Azure SQL Database</summary>

If a setting is not specified here, use the default value in the Azure portal.

**When creating the database, ensure:**

* Set the Azure **Subscription** and **Resource group** to the same as your other Reporting Hub services are in.
* If you are creating a new database for your Reporting Hub, we recommend the following settings:
  * Set **Want to use SQL elastic pool?** to **No**.
  * Set **Workload environment** to **Production**.
  * Set **Compute + storage** **service tier** to **Basic (DTU-based purchasing model) 5 DTUs**.
  * Set **Backup storage redundancy** to **Geo-redundant backup storage**.
* The database must be empty.

</details>

<details>

<summary>Azure App Service</summary>

If a setting is not specified here, use the default value in the Azure portal.

**When creating the App Service, ensure:**

* **App Type** should be **Web App**.
* Set **Subscription** and **Resource group** to the resource group that your other Reporting Hub services are in.
* Uncheck "**Secure unique default hostname on**".
* Set **Publishing model** to **Code**.
* Set **Runtime stack** to **.NET 8 (LTS)**.
* Set **Operating system** to **Windows**.
* Set **Pricing plan** to **Basic B1** or **Standard S1**.
* We recommend setting **Enable Application Insights** to **No**.

Once the App Service has been created, under **Settings** > **Configuration**:&#x20;

* Set **Platform** to **64 Bit**.
* Set **SCM Basic Auth Publishing** to **On**.
* Set **FTP Basic Auth Publishing** to **On.**
* Set **FTP state** to **All allowed**.

</details>

<details>

<summary>Azure Translator</summary>

* Set **Pricing tier** to **Free F0**.

</details>


# Request a Quota Increase in Azure

How to request an Azure quota increase when the installer flags that a required resource isn't available in your selected region.

When you select your **resource group region** in the Reporting Hub installer, the installer checks your Azure subscription's quota for each required resource — **App Service**, **SQL Database**, and **Fabric Capacity** — in that region. Any resource without quota in the selected region is marked with a red icon, and you can't continue until you either:

* Confirm that you will create that resource in a different region (by selecting **Will select region on creation**), **or**
* Request a quota increase for the resource in your preferred region and then retry the installation.

The path you take depends on the resource:

* **App Service** quota requests are submitted through the **My Quotas** blade.
* **SQL Database** and **Fabric Capacity** quota requests are submitted through a Microsoft support ticket.

Microsoft typically processes support tickets within a few business days. {% endhint %}

#### When to Request a Quota Increase

Request a quota increase if:

* You need all Reporting Hub resources to live in a specific region for compliance, latency, or data residency reasons.
* The flagged resource is the only one without quota in your preferred region and you don't want to split deployment across regions.

If you are flexible on region for the flagged resource, the simpler path is to select **Will select region on creation** in the installer and choose a different region for that resource when prompted. See Installation Failures for details on multi-region deployments.

#### Minimum Quota Required

When you submit the quota request, ask for the minimum required for Reporting Hub:

| Resource            | Deployment SKU    | Quota to Request              |
| ------------------- | ----------------- | ----------------------------- |
| **App Service**     | **S1** (Standard) | `1` unit of S1                |
| **SQL Database**    | **Basic**         | `1` vCore (via Region access) |
| **Fabric Capacity** | **F2**            | `2` Capacity Units (CU)       |

You can request a higher value if you plan to scale, but these minimums are enough to complete the installation.

### Request a Quota Increase for App Service

Use the **My Quotas** blade for App Service requests.

1. Go to the **My Quotas** blade in the Azure portal: <https://portal.azure.com/#view/Microsoft_Azure_Capacity/QuotaMenuBlade/~/myQuotas>.
2. At the top of the page, set the filters:
   1. For **Provider**, select **App Service**.
   2. For **Region**, select the region you want to deploy into.
   3. Leave **Subscription** set to the subscription you're installing Reporting Hub into.
3. In the results list, find the **S1** quota and select the pencil **Edit** icon on the right of the row.
4. In the **New quota request** field, enter `1` and select **Submit**.
5. If the request can't be approved automatically, the same form will open a Microsoft support ticket. Complete and submit it.

### Request a Quota Increase for SQL Database or Fabric Capacity

Use the **Help + support** blade for SQL Database and Fabric Capacity requests. These always go through a Microsoft support ticket.

1. Go to the **Help + support** blade in the Azure portal: <https://portal.azure.com/#view/Microsoft_Azure_Support/HelpAndSupportBlade>.

<figure><img src="/files/Hy4anc4RgEMiPZRdCAi0" alt="" width="313"><figcaption></figcaption></figure>

2. In the **Tell us about the issue** field, enter `quota` and select **Go**.
3. For **Which service are you having an issue with?**, select **Service and subscription limits (quotas)**.
4. For **Which subscription are you having an issue with?**, select the subscription you're installing Reporting Hub into.
5. For **What issue are you having?**, set **Problem type** to the service the installer flagged:
   * **SQL database** for SQL Database quota.
   * **Microsoft Fabric** for Fabric Capacity quota.
6. Select **Next**.
7. On the **Service and Subscription Limits (Quotas)** card, select **Create a support request**.

<figure><img src="/files/KzpaNn6d8UVcydHBwHOZ" alt="" width="317"><figcaption></figcaption></figure>

8. On the **Problem description** tab, set **What is your issue related to?** to **Azure services**. The **Issue type**, **Subscription**, and **Quota type** fields are pre-filled from your previous selections — confirm they're correct, then select **Next**.
9. On the **Additional details** tab, under **Request details**, select **Enter details** to open the **Quota details** panel.
10. Fill in the panel based on the resource:
    * **For SQL Database:**
      1. Set **SQL database quota type** to **Region access**.
      2. Set **Location** to the region you want to deploy into.
      3. Set **Expected Consumption** to `1` (one vCore is enough for the Basic tier — Reporting Hub uses approximately 100–125 DTU).
      4. Optionally add context in **Description** (for example, *Deploying Reporting Hub, requires SQL Database access in this region*).
      5. Select **Save and continue**.
    * **For Fabric Capacity:**
      1. Set **Location** to the region you want to deploy into.
      2. Set **QuotaBucket** to **CapacityQuota**.
      3. Set **New limit (CU)** to `2` (the F2 SKU is 2 Capacity Units, which is enough to deploy Reporting Hub). Request a higher value if you plan to scale.
      4. Select **Save and continue**.
11. Complete the remaining fields on the **Additional details** tab (advanced diagnostic information, support method, contact info), then select **Next**.
12. On the **Review + create** tab, review your request and select **Create** to submit.

{% hint style="warning" %}
Microsoft typically processes quota support tickets within a few business days. This processing time is **outside of Reporting Hub's control**. If your installation timeline is tight, consider deploying the flagged resource in an alternate region while you wait for approval.
{% endhint %}

### Return to the Installer

Once Microsoft has approved your quota request:

1. Return to the [Reporting Hub installer](https://license.thereportinghub.com/install).
2. Re-run the installation, selecting the same region you requested quota for.
3. The quota check on the **Resource Group** page should now show a green check for the resource that was previously flagged.
4. Continue through the remaining installation steps as described in [Self-Serve Guided Install](/getting-started/deployment-step-by-step/self-serve-guided-install).


# Installation Failures

Common errors you may encounter during installation

**Pre-Install Quota Check.** When you select your resource group region, the installer now checks your Azure subscription's quota for **App Service**, **SQL Database**, and **Fabric Capacity** in that region. A green check means quota is available. A red icon means there is no quota in the selected region — you can't continue until you either:

* Select **Will select region on creation** for the flagged resource (you'll be prompted to choose a different region for that resource later), or
* Request a quota increase for that resource in your preferred region, then retry. {% endhint %}

#### Troubleshooting Deployment Failures

If you reach the deployment check page and the deployment fails, complete the cleanup steps below before trying again.

In most failed deployments, **many resources are still created successfully**. In the Azure portal, you’ll typically see **all Reporting Hub resources except the one that failed**. When you rerun the installer, you can select those existing resources instead of recreating them. In the example below, everything was deployed except for the Azure SQL Server/Database

<figure><img src="/files/Na7MZzWIgNXxn7jB76S8" alt=""><figcaption></figcaption></figure>

## Clean Up Reporting Hub Entra ID Objects

A failed installation will still create Entra ID objects (an app registration and a security group). Delete those before retrying. You named these objects in step 7 of the Self-Serve Guided Install.

#### Delete the App Registration

1. In the Azure portal, go to **Microsoft Entra ID**.
2. Under **Manage**, select **App registrations**.
3. Select **All applications**.
4. Find your **Reporting Hub** app registration.
5. Select it, then select **Delete**.

#### Delete the Security Group

1. In the Azure portal, go to **Microsoft Entra ID**.
2. Under **Manage**, select **Groups**.
3. Select **All groups**.
4. Search for the security group **created during installation**.
5. Select it, then select **Delete**.

## Resource Not Available in Your Region (Quota Restriction)

The installer checks your subscription's quota for **App Service**, **SQL Database**, and **Fabric Capacity** when you select a resource group region. If a resource has no quota in that region, the installer marks it with a red icon and blocks you from continuing.

You have two options:

1. **Deploy the flagged resource in a different region.** Select the **Will select region on creation** checkbox next to the flagged resource and continue. You'll be prompted to choose a region for that resource when it's created.
2. **Request a quota increase for your preferred region.** Use this if you need all resources in the same region for compliance, latency, or data residency reasons.

{% content-ref url="/pages/RP5Mb9RFz5iB9wIimXXU" %}
[Request a Quota Increase in Azure](/getting-started/deployment-step-by-step/self-serve-guided-install/quota)
{% endcontent-ref %}

## Other Common Issues

#### Installer does not proceed after selecting a resource group

This usually means your account does not have the **Subscription Owner** role.

* If you are a Contributor, you can often proceed by selecting an existing resource group (instead of creating a new one).
* Otherwise, either:
  * activate/get the **Azure Subscription Owner** role for your account, or
  * ask an Azure admin in your organization to complete the installation.

#### Blank screen with “Microsoft login failed.”

This is typically caused by the account signing in **not having a Power BI Service account yet** (common in brand-new Azure tenants). You can double-check this by viewing the error in the URL bar. To fix this:

1. Go to [`https://app.powerbi.com`](https://app.powerbi.com/)`.`
2. Sign in with the same email used for the installer.
3. Confirm the account is successfully created/accessible, then retry the installation.

#### SQL Credentials Failing

If you are selecting an existing SQL server, the installer will prompt you to enter your SQL admin credentials. Your Entra ID credentials will not work here, you must use [SQL Authentication.](https://learn.microsoft.com/en-us/azure/azure-sql/database/logins-create-manage?view=azuresql#authentication-and-authorization)

#### The progress bar says 100%, but has not moved past that.

If this happens, then likely the installation was successful, but the installer timed out. To verify if the installation completed, navigate to the Azure App Service via the Azure Portal. On the overview page, select the default domain, and the application should start.

<figure><img src="/files/xPXqYy92DJugCatXzx2s" alt=""><figcaption></figcaption></figure>

#### Azure Kudo Services has been blocked

<figure><img src="/files/rrzWglbh5AYHXJenFCPV" alt="" width="563"><figcaption></figcaption></figure>

This typically means that the settings configuration on the Azure App Service is incorrect. If you created the resource manually, ensure that the [App Service Configuration](https://docs.thereportinghub.com/getting-started/deployment-step-by-step/self-serve-guided-install#azure-services-configuration-settings) Settings are correct.&#x20;

#### Reinstall&#x20;

Run the [Reporting Hub installer](https://license.thereportinghub.com/install) again and create all resources in the new region you selected.

## Contact Support

If none of the above cover the issue you are encountering, you can [reach out to our support team](https://support.thereportinghub.com/) to create a ticket. You’ll need to create a support account first—use the **Sign Up** link in the top right corner of the Support page.\
\
Where it says Application URL, input **Installation Error**.


# Enable Power BI Service Settings

Give the Reporting Hub permission to access Power BI

For Reporting Hub (an Entra ID app) to access Power BI content and APIs, a Fabric or Power BI Admin needs to enable the following settings:

* [x] Enable XMLA endpoint&#x20;
* [x] Embed content in apps
* [x] Allow Service principals can create workspaces, connections, and deployment pipelines&#x20;
* [x] Allow Service principals can call Fabric public APIs
* [x] Allow service principals to create and use profiles
* [x] Enable Enhance admin APIs responses with detailed metadata
* [x] Grant Permission to workspaces

## Enable Power BI Tenant Admin Settings

### 1. Integration Settings

#### **1.A. Enable XMLA endpoint**

Go to **Tenant settings** in the Power BI [**Admin portal**](https://app.powerbi.com/admin-portal/tenantSettings), and scroll down to **Integration settings**.

Enable the **Allow XMLA endpoints and Analyze in Excel with on-premises datasets** toggle either for the entire organization or for the specific security group you created in Azure Entra ID.

<https://learn.microsoft.com/en-us/power-bi/enterprise/service-premium-connect-tools#security>

<div align="left"><figure><img src="/files/9Aw19ymt9Q2AFkhQz92E" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
**Note:** If you choose 'specific security group', you must add the Reporting Hub Service Principal security group you created in step 7 of the installation process.
{% endhint %}

### 2. Developer Settings

#### 2.A. Embed Content in Apps

Enable the **Embed content in apps** toggle either for the entire organization or for a specific security group you created in Azure Entra ID.

{% hint style="info" %}
**Note:** If you choose 'specific security group', you must add the Reporting Hub Service Principal security group you created in step 7 of the installation process.
{% endhint %}

<figure><img src="/files/nnAaqIs2lOmKA9qIHJL2" alt=""><figcaption></figcaption></figure>

#### **2.B.** Service principals can create workspaces, connections, and deployment pipelines

Enable the **Service principals can create workspaces, connections, and deployment pipelines** toggle either for the entire organization or for the specific security group you created in Azure Entra ID.

{% hint style="info" %}
**Note:** If you choose 'specific security group', you must add the Reporting Hub Service Principal security group you created in step 7 of the installation process.
{% endhint %}

<figure><img src="/files/2GgjbY0KpTpkbHo8vKhk" alt=""><figcaption></figcaption></figure>

#### **2.C. Allow** Service principals can call Fabric public APIs&#x20;

Enable the **Service principals can call Fabric public APIs** toggle either for the entire organization or for the specific security group you created in Azure Entra ID.

{% hint style="info" %}
**Note:** If you choose 'specific security group', you must add the Reporting Hub Service Principal security group you created in step 7 of the installation process.
{% endhint %}

<figure><img src="/files/JM9oZgdIkWsJzK34TrAu" alt=""><figcaption></figcaption></figure>

#### **2.D.** Allow service principals to create and use profiles&#x20;

Enable the **Allow service principals to create and use profiles** toggle either for the entire organization or for the specific security group you created in Azure Entra ID.

{% hint style="info" %}
**Note:** If you choose 'specific security group', you must add the Reporting Hub Service Principal security group you created in step 7 of the installation process.
{% endhint %}

<figure><img src="/files/cCGVh8Sweg7z9OyOa0kn" alt=""><figcaption></figcaption></figure>

### **3. Admin API Settings**

#### **3.A. Enable Enhance admin APIs responses with detailed metadata**&#x20;

Enable the **Enhance admin APIs responses with detailed metadata** toggle either for the entire organization or for the specific security group you created in Azure Entra ID. To learn more about the Admin API Settings, visit the Microsoft link below the screenshot.

{% hint style="info" %}
**Note:** If you choose 'specific security group', you must add the Reporting Hub Service Principal security group you created in step 7 of the installation process.
{% endhint %}

<div align="left"><figure><img src="/files/FOPkpLnJM39mxLmXBJeb" alt=""><figcaption></figcaption></figure></div>

{% embed url="<https://learn.microsoft.com/en-us/fabric/admin/service-admin-portal-admin-api-settings#enhance-admin-apis-responses-with-detailed-metadata>" %}

## Power BI Workspace Configuration

There are three steps you need to perform in order to make your Power BI workspaces available in Reporting Hub.

* [x] [Assign your workspace to your embedded capacity](#assign-your-workspace-to-your-embedded-capacity)
* [x] [Add the Reporting Hub application to your workspace](#add-the-reporting-hub-application-to-your-workspace)
* [x] [Add the workspace to your Reporting Hub Global Tenant](#add-the-workspace-to-a-reporting-hub-tenant)

{% hint style="info" %}
**Please note:** your personal '*My Workspace*' can not be added to the Reporting Hub.
{% endhint %}

### 1. Assign your workspace to your Embedded or Fabric Capacity

To add a Power BI workspace to a capacity, you'll need to:

1. Log in to: <https://app.powerbi.com>
2. Navigate to the workspace you integrate with Reporting Hub. If this is your first time using Reporting Hub, it is recommended to integrate a **non-production** workspace.
3. Click on the three-dot menu, and choose **Workspace Settings**.

   ![](/files/2eKKymTv7scXZYx6vQSM)
4. On the License Info tab, the license mode to **Embedded** *or* **Fabric**. If you have more than one embedded capacity, select the one that is being managed by Reporting Hub and click **Apply**.

{% hint style="warning" %}
**If capacity is greyed out:** The capacity selection will only be visible to you if you are a [**Capacity administrator**](https://learn.microsoft.com/en-us/fabric/admin/capacity-settings?tabs=fabric-capacity#add-and-remove-admins) and the [**capacity is currently active**](https://learn.microsoft.com/en-us/fabric/enterprise/pause-resume#resume-your-capacity). If the capacity is paused, you can start it by either going to the Azure portal and starting the capacity or by signing into Reporting Hub, and the application will start the capacity automatically.
{% endhint %}

<img src="/files/3SBEMxzjBsCU7ilFC9Nz" alt="Note that it will say License Info instead of Premium" width="563">

### 2. Add the Reporting Hub Application to your Workspace

After assigning the capacity as the workspace license, you need to give your Reporting Hub application access to the workspace.

1. In your Reporting Hub application, navigate to **App Settings** > **App Information.**&#x20;
2. Copy the **Name** of your service principal and note the **Client ID.**

<figure><img src="/files/tg3f79sNOVjiUNEFsNn2" alt=""><figcaption></figcaption></figure>

3. Navigate back to the workspace in the [Power BI Service](https://app.powerbi.com). Ensure this is the same one from first step.
4. Click on the three-dot menu, and choose **Manage Access** > **+ Add people or groups**.

![](/files/NQ4ngBIlzDWo5a6NW0m4)

{% hint style="info" %}
**Note:** A diamond icon next to a Workspace means that the license mode is a capacity.
{% endhint %}

5. In the 'Enter name or email' field, paste the **Name** that you copied from your application and select the one that shows an **AppID** under the name. If you see multiple apps with the same name, select the one with the **AppID** that matches the **Client ID** in your app.

You must set the permission to **Admin.** Click **Add.**

<img src="/files/IKlXmOeDrgZxbBejqExj" alt="" width="375">

{% hint style="info" %}
By using the application, workspaces are typically available in the Reporting Hub within minutes. If you choose the security group instead of the application, workspaces will take longer (hours or even next day) to become available in the Reporting Hub application.
{% endhint %}

{% hint style="info" %}
**Service principal not showing up?** Ensure you have enabled your [Power BI Tenant settings](#enable-power-bi-tenant-admin-settings) and that your [Service principals can call Fabric public APIs](#id-2.c.-allow-service-principals-can-call-fabric-public-apis) setting is either enabled for the entire organization or that the application service principal you want to add is a member of one of the specified groups.

Sometimes copying and pasting adds an invisible character and the name may not appear. Try to type the name in and you should see it in the list.
{% endhint %}

### 3. Add the Workspace to your Reporting Hub Global Tenant

Now that your workspace is added to your capacity and you have granted your Reporting Hub application permission, you will need to assign the workspace to your Reporting Hub Global Tenant.&#x20;

We will go through this in the next step, in [Configure Reporting Hub App Settings](/getting-started/deployment-step-by-step/configure-reporting-hub-app-settings).&#x20;


# Configure Reporting Hub App Settings

## 1.  Add Your Authentication Scheme (Optional Step)

By default, the Reporting Hub is installed with Microsoft Entra ID authentication (previously known as Azure Active Directory). If you wish to change how your users authenticate, you need to add your authentication scheme before you can assign permissions.&#x20;

For more information, please visit our in-app dedicated Authentication Admin documentation. Note that you can make changes to your authentication schemes at any time.

## 2.  Sync Your Groups

{% hint style="success" %}
Security groups are utilized to assign permissions to tenants and content within Reporting Hub.
{% endhint %}

Following installation, your Reporting Hub application will be integrated with Entra ID (by default) or whatever authentication scheme if you completed the optional step 1. Although the integration will be established, Reporting Hub will not automatically sync your users and security groups. You must sync groups to make security groups available to the Reporting Hub.&#x20;

1. From your user profile, click **App Settings** > **Manage Groups** to access the page.&#x20;
2. Select **Sync Groups**.&#x20;

**This will pull all your security groups into Reporting Hub** so they can be granted permissions accordingly throughout the app. For more information, visit our dedicated Manage Groups documentation page from the in-app documentation.&#x20;

<figure><img src="/files/b7fTvkcctIMybBgnvg9H" alt=""><figcaption></figcaption></figure>

## 3. Configure Your Global Tenant Settings

Following installation, your Reporting Hub Tenant will not have any user permissions in place nor have access to any of your Power BI workspaces. You will need to establish these from within your Global Tenant settings.&#x20;

1. Open your Reporting Hub and select your user profile. Click **App Settings** > **Tenant Admin** to access the page.
2. Select **Refresh Workspaces and Capacities**. This provides your Reporting Hub with an up-to-date list of which Power BI Workspaces and Capacities it has access to, so you may add them to your Global Tenant.&#x20;

<figure><img src="/files/Pje49wMeb0Hj5X0hPrPs" alt=""><figcaption></figcaption></figure>

3. Click the **ellipses** and **Edit** button of your Global Tenant.&#x20;

   <figure><img src="/files/oERdjFmph8uOhWvH9t5H" alt=""><figcaption></figcaption></figure>

4. Your Global Tenant settings will look similar to the screenshot below after installation:&#x20;

   <figure><img src="/files/YTCJj1FkZEYcO7Zgcq4B" alt=""><figcaption><p>Tenant Settings Form</p></figcaption></figure>

### 3.1 - Select the Tenant Administrator

After installation, the user who completed the setup is automatically assigned as a **Platform Admin** with **Global Permissions**. To designate them as a **Tenant Administrator**, select their name from the dropdown list.

If additional admins are required, they can be added from the **Manage Seats** page in **App Settings.**

{% content-ref url="/pages/JrbubgZm0AneMZz1lATw" %}
[Broken mention](broken://pages/JrbubgZm0AneMZz1lATw)
{% endcontent-ref %}

### 3.2 - Apply Your Power BI Workspaces

A Power BI workspace must be added to the tenant for your Reporting Hub application to access it.

1. Ensure you have properly [configured your Workspace in Power BI](/getting-started/deployment-step-by-step/enable-power-bi-service-settings#power-bi-workspace-configuration).
2. Select the workspace(s) from the **Power BI Workspaces** dropdown you wish to integrate with Reporting Hub.&#x20;
3. Click **Save**.

{% hint style="info" %}
**Don't see your workspace?** If your Power BI workspace isn’t showing up in the app, it may be due to configuration or permission issues. Head over to our Troubleshooting Guide in-app to find out how to resolve it.
{% endhint %}

### 3.3 - Apply a Parent Group (Optional)

The "Parent Group" is the top-level security group that controls access to a Reporting Hub tenant. If set, users and security groups must be part of this Parent Group to access the tenant.

This field is ***optional*** for your Global Tenant. Enter a Parent Group only to limit access to the Reporting Hub global tenant to certain security groups in your organization. Leave this field blank to allow access for your entire organization.

{% hint style="danger" %}
**Caution:** Ensure your user is a member of a security group that belongs to the Parent Group you set. **You will lock yourself out of the application** if your user is not associated with this Parent Group. We also recommend NOT using the Service Principal security group that was created as part of the installation process. The Service Principal security group is meant for enabling connectivity with the Power BI Service.
{% endhint %}

## Set your Home Page

You are now ready to manage content for your Reporting Hub application. To find out how to set the home page, click the next button below.


# Set Your Home Page

Configure your home page for Reporting Hub

Reporting Hub home page is a basic content page where all users will land after signing in. **This page is globally accessible by all users with access to your Reporting Hub tenant.** Individual or security group permissions can not be applied to this page.&#x20;

## Editing the Home Page Following Deployment

Following the installation of Reporting Hub, the home page is pre-configured to display documentation to aid in completing your deployment setup. Once you have completed the steps outlined, you can update your home page.

{% hint style="info" %}
The home page can not be removed. It must be edited and updated with your custom content. Alternatively, Growth and Enterprise+ users can designate any navigation item as their home page.
{% endhint %}

The home page can be an embedded URL page or Power BI content, like a report or a dashboard.

## Set the Home Page to Power BI Content

1. Access your **Admin Settings** menu by clicking on your profile picture.&#x20;
2. Select **Manage Content**.

   <figure><img src="/files/NQeHcui4iHCRaVghYeu6" alt=""><figcaption><p>Select 'Manage Content' from the 'Admin Settings' menu</p></figcaption></figure>
3. Select the top item in the menu structure to edit the home page. It is called **Getting Started** by default, but you can change the name.

   <div align="center"><figure><img src="/files/IFajfNRMUr02zSDRJUTB" alt="" width="563"><figcaption><p>Select the top item in the menu</p></figcaption></figure></div>
4. If you'd like your home page to be a Power BI report, a paginated report, or a dashboard, set **What type of Navigation Option are you creating?** to **Report**. Fill out the fields and select **Save**. <br>

   <figure><img src="/files/MqUCWOatZ1LbxKMasFBe" alt=""><figcaption><p>Set Home Page navigation option type to Report</p></figcaption></figure>

## Using an Embedded Page Link for your Home Page

{% hint style="success" %}
Good to know: The Reporting Hub Free Trial is the same as the Growth subscription experience.
{% endhint %}

If you have a Growth or Enterprise+ subscription, you can make the home page an embedded URL.

1. Access your **Admin Settings** menu by clicking on your profile picture.&#x20;
2. Select **Manage Content**.
3. Select the top item in the menu structure to edit the home page. It is called **Getting Started** by default, but you can change the name.
4. Under **What type of Navigation Option are you creating?** select **Page Link**.

   <div align="left"><figure><img src="/files/RQkqaa3ppK8Q8d64rKpY" alt="" width="563"><figcaption></figcaption></figure></div>
5. Change the **Name** if you'd like.&#x20;
6. Select an **Icon** (optional).
7. Enter a **Description** (optional).
8. Enter a **Page Link**, including the protocol (`http://` or `https://`).
9. Enable the **Show Title and Description** check box if you want a header with the title and description (entered in step 5) to show above the embedded page.
10. To grant access, type user email or group names into the **Permission (Users/Groups from AD)** box and select the ones you wish to add. (Learn more about [managing users and groups in AD](broken://pages/lRRmoOd2ijOM00EJjn4L)). The content page will only be visible to those with permission.&#x20;
11. Choose a **Sort Order**: where you want your Page Link to appear in sequence on your Navigation Pane. If you're not sure what the number should be, you can reorder the menu items later.&#x20;
12. Click **Save.**

## Set Any Navigation Item as Your Home Page

Instead of having to edit the home page navigation item, Growth or Enterprise+ subscribers can set any existing navigation it (embedded URL page or Power BI content) as their home page. If you are creating a new navigation item to use as your home page, you must save it before the 'Set as Home Page' option will appear.

To set a navigation item as your home page:

1. Access your **Admin Settings** menu by clicking on your profile picture.&#x20;
2. Select **Manage Content**.
3. [Add a new navigation item](broken://pages/sUMfjuN6QVNlUgSbOuJr) or select an existing navigation item.
4. Unlike other content pages, the home page does not have to have groups/users assigned to it unless it is a row-level security report. If you are using a report with row-level security for your home page, you must select at least one group and assign roles as usual. See [Row-Level Security on Your Home Page](#row-level-security-on-your-home-page) for more information.
5. Select the **dropdown arrow in the Save** icon and select **Set as "Home Page"**.

   <figure><img src="/files/6JOBD0YEfYudkMd6CqcM" alt=""><figcaption><p>Set as Home Page button in Create/Edit Navigation Item Menu</p></figcaption></figure>

## Row-Level Security on Your Home Page

If your home page report uses row-level security, you should add every possible group/viewer to the report. If a user logs in and does not belong to any of the report's groups, they will see an error page saying that the home report is not set up.


# Azure Marketplace Install

Install the Reporting Hub through the Azure Marketplace

You can install the Reporting Hub using [our installer](https://license.thereportinghub.com/install/installer), or through the Azure marketplace. This guide will explain the differences between the two installation methods and describe the requirements and steps for installing through Azure Marketplace.

## Comparison with Installer Methods

Regardless of which installation method you choose, the latest version of the Reporting Hub will be installed in your environment.

The biggest differences when you install via the Azure Marketplace versus using our installer are:

* There is no free trial period when you install through the Azure Marketplace.&#x20;
* Can only deploy a Power BI Embedded capacity (instead of a Fabric capacity). We will update our offering to include the Fabric capacity option soon.
* Translator service isn't deployed automatically through Azure Marketplace and requires manual configuration.

## Installing through the Azure Marketplace

### Create a Managed Identity

Before you install through the Azure Marketplace, you must create a Managed Identity. You must also assign the necessary permissions to the Managed Identity. The Managed Identity requires contributor access on the Azure subscription where the app will be installed, as well as Application Administrator and Groups Administrator permissions in the directory.

#### Create a User Assigned Managed Identity

1. In the Azure portal, select **Managed Identities**.
2. Select **Create**.
3. Select the appropriate **Subscription** in which you'd like to deploy all of the Reporting Hub app resources.
4. Select the **Resource Group** you'd like to use, or create a new one.
5. Select a **Region** you'd like to deploy your Azure resources in.&#x20;
6. **Name** your managed identity.
7. Select **Review + Create** to review your settings and select **Create**.&#x20;

#### Give Managed Identity the Necessary Entra ID Permissions

This allows the managed identity to create the app registration required for your Reporting Hub application.

1. In the Azure portal, select **Microsoft Entra ID**.&#x20;
2. Under **Manage**, select **Roles and administrators**.&#x20;
3. From the list of roles, select:&#x20;
   1. **Application Administrator**
   2. **Groups Administrator**
4. Select **Add assignments**.&#x20;
5. Search for the name of the managed identity and select it. Select **Add**.

#### Give Managed Identity the Necessary Permissions on Azure Subscription

This allows the managed identity to create the necessary resources on the Azure subscription.

1. In the Azure portal, select **Subscriptions**.
2. Select the relevant subscription.
3. Select **Access control (IAM)** on the left menu.
4. On the top menu select **Add** and then **Add role assignment**.
5. Select the **Privileged administrator roles** tab and then select **Contributor**. Select **Next**.
6. Leave the **Assign access to** field set to **User, group, or service principal**. Click **Select members**.
7. Search for the Managed Identity you created, select it, and hit the **Select** button below.
8. Select **Review + assign** at the bottom of the screen.

### Deploy through the Azure Marketplace

{% embed url="<https://azuremarketplace.microsoft.com/marketplace/apps/shiftanalyticsinc1663186612563.reportinghub_prod_003?tab=overview>" %}

1. Open the link above in a new tab to view our Azure Marketplace offering and select **Get It Now**.
2. Sign in to the Microsoft Azure Marketplace.
3. Choose a [Plan](https://thereportinghub.com/pricing) and select **Create**.&#x20;

   1. You must select a paid plan; there is no free trial period when you install through the Azure Marketplace. If you'd like to install with a free trial period, [use our installer](/getting-started/deployment-step-by-step/self-serve-guided-install) instead.&#x20;

   <figure><img src="/files/I8osnd8mabcrhu9d0PbV" alt=""><figcaption></figcaption></figure>
4. Select your Azure **Subscription** and the **Resource group** that your Managed Identity is in.
5. Select the **Region** that you'd like to deploy all of the Reporting Hub resources in.
6. Enter a name for the **Managed Application** and the **Managed Resource Group**. Select **Next**.

   <figure><img src="/files/og8o6YKPmeIqiFybiK8a" alt=""><figcaption></figcaption></figure>
7. On the App Service Setup page, you will be presented the option to either use an existing App Service or add a new App Service.&#x20;

   * To use an existing App Service, check the **Use existing App Service** box and select an App Service and deployment slot. Select **Next**.
   * To create a new App Service, enter an **App Service Name**. Select a **Tier**; you can scale up your App Services plan later. Select **Next**.&#x20;

   <figure><img src="/files/lmHNWIjOatYsABEJZDXp" alt=""><figcaption></figcaption></figure>
8. On the Database Setup page, you can either use an existing Azure SQL Server or create a new one.&#x20;

   * To use an existing server, select the **Use existing Azure SQL Server** box and select it from the list.
   * To create a new server, enter a **SQL Server Name**.

   Enter a **Database Name**. Select **Next**.

   <figure><img src="/files/hRX8YT1NGbvRslVSEm8Z" alt=""><figcaption></figcaption></figure>
9. On the Database Credentials page, enter a **SQL Server Username**, **Password**, and enter the **Password** again to confirm. If you are creating a new SQL server, the server admin credentials will be what you enter here. If you are using an existing server, please ensure that you are entering the correct server admin credentials here — the installer is unable to validate them here. Select **Next**.

   <figure><img src="/files/4XV6K1naQ9iBZDyGuF8z" alt=""><figcaption></figcaption></figure>
10. On the Embedded Capacity Setup page, you have the option of creating a new Embedded Capacity or using an existing one.

    * To use an existing capacity, check the **Use existing capacity** box and select a capacity from the list. Only capacities in the resource group you have selected will be available to select. Select **Next**.
    * To create a new capacity, enter a **Capacity Name** and an **Administrator Email** for the user you'd like to set as the capacity's administrator. You can add additional capacity administrators later on. Select **Next**.

    <figure><img src="/files/lxf3bPRGQu0D667yRMN5" alt=""><figcaption></figcaption></figure>
11. On the Identity page, select **Add** and then select the user assigned managed identity you created earlier. Select **Next**.

    <figure><img src="/files/K6vK2pOCovSoyjIKK9z9" alt=""><figcaption></figcaption></figure>
12. Review your terms. You can read The Reporting Hub's Terms of Use and Privacy Policy, as well as the Azure Marketplace Terms, and select **I agree to the terms and conditions above**. Select **Create**.&#x20;

    <figure><img src="/files/8vVUDR4jxIEESmwJItux" alt=""><figcaption></figcaption></figure>
13. The wizard will deploy your Reporting Hub app in your Azure environment. After deployment, navigate to your App Service and select the domain from the Overview page to launch your Reporting Hub.

After deployment, enable Power BI Settings and configure your Reporting Hub app settings. Additionally, if you want to translate your Reporting Hub into a language other than English, [link a Translator service to your Reporting Hub app](#add-a-translator-optional). &#x20;

### Enable Power BI Service Settings

Follow the instructions linked below.

{% content-ref url="/pages/ZTurS8WKwsHYDkpOORRM" %}
[Enable Power BI Service Settings](/getting-started/deployment-step-by-step/enable-power-bi-service-settings)
{% endcontent-ref %}

### Configure Reporting Hub App Settings

Follow the instructions linked below.

{% content-ref url="/pages/D6QLOw6IhUgl69x7qJL6" %}
[Configure Reporting Hub App Settings](/getting-started/deployment-step-by-step/configure-reporting-hub-app-settings)
{% endcontent-ref %}

### Add a Translator (Optional)

#### Create a Translator service in Azure&#x20;

1. In the Azure portal, search for **Translators** in the top search bar and select **Translators**.&#x20;
2. Select **Create**.&#x20;
3. Choose a **Subscription** and **Resource group**; it doesn't have to be in the same subscription or resource group that your Web App is in.&#x20;
4. Choose a **Region** that is the same as or close to the region your Web App is in.&#x20;
5. Enter a **Name** for your Translator.&#x20;
6. Set the **Pricing tier** as **Free**.&#x20;

   <figure><img src="/files/AJff06ABqtD1CMJ07MU4" alt=""><figcaption></figcaption></figure>
7. On the **Network** tab, select **All networks, including the internet, can access this resource**.&#x20;

   <figure><img src="/files/ukmlhDbdbqN2zVKdVFDI" alt=""><figcaption></figcaption></figure>
8. Select **Review + Create** and then **Create** to create the resource.&#x20;

#### Add Translator Keys to Reporting Hub App

After the Translator has been created, you need to add its keys to your Reporting Hub app's settings.

1. Select the Translator in your Azure portal.
2. Under **Resource Management**, select **Keys and Endpoint**.&#x20;

   <figure><img src="/files/Q0pGTTnwgJanmz0iK4NG" alt=""><figcaption></figcaption></figure>
3. Select **Show Keys** and copy KEY 1, KEY 2 and Location/Region to a notes app, like notepad.&#x20;

   <figure><img src="/files/pT3sxzySKYVak7h3Gcps" alt=""><figcaption></figcaption></figure>
4. Navigate to your **App Services** list; you can use the search bar at the top of the page. &#x20;

   <figure><img src="/files/CA7c0qAjd6c11X8Ob1mG" alt=""><figcaption></figcaption></figure>
5. From the list of App Services, select your Reporting Hub app service.&#x20;
   1. If you deployed your Reporting Hub app to a specific slot on your app service, then expand the **Deployment** menu in the left menu pane; select **Deployment slots**; and select the desired slot.&#x20;
6. On the left menu, expand the **Development Tools** menu and select **Advanced Tools**.&#x20;

   <figure><img src="/files/EIA6Y7aORy1OxpLqDZRP" alt=""><figcaption></figcaption></figure>
7. Select **Go ->** and Kudu tools will open in a new tab.&#x20;

   <figure><img src="/files/Mwt2s4WvxyN76x1uj4cG" alt=""><figcaption></figcaption></figure>
8. On the Kudu page, in the top menu, select **Tools** and **Zip Push Deploy**.&#x20;

   <figure><img src="/files/n4wO44w29KRSoMu9z0RN" alt=""><figcaption></figcaption></figure>
9. Scroll down in the file list and find `appsettings.json`. Select the **pencil icon** next to it.&#x20;

   <figure><img src="/files/EAg2PuL9raxRqipoPno3" alt=""><figcaption></figcaption></figure>
10. In the text editor on the page, find **"key1"** and replace the text beside it with the KEY1 value from step 3. Ensure the key value is inside quotation marks.&#x20;

    <figure><img src="/files/uEk3L9G4r0h2HP0kWgvV" alt=""><figcaption></figcaption></figure>
11. Find **"key2"** and replace the text beside it with the KEY2 value from step 3.&#x20;
12. Find **"location"** and replace the text beside it with the translator region you copied in step 3.&#x20;
13. Select **Save**.


# Reporting Hub Architecture

The Reporting Hub is an Azure-based application that is installed and deployed within your Azure environment. It integrates with your existing Microsoft tenant and communicates with Power BI Embedded via Microsoft APIs. The following Azure services are required to run the Reporting Hub:

1. Power BI Embedded or Fabric Capacity
2. Azure App Service
3. Azure SQL Database

Below is a diagram highlighting the high level architecture.

![](/files/eJ82Ocd1ceEEGnuDhy9a)

## How it works with Power BI

The Reporting Hub communicates with Power BI Embedded via Microsoft APIs. The below list includes the key communication areas:

* Connects to authorized Power BI Workspaces, Reports and Dashboards
* Applies Row-level-security (RLS) based on authenticated user
* Built-in capacity optimizer manages Power BI Embedded Capacity availability based on usage
* Connections to data sources are established through Power BI&#x20;
* Works with all Power BI Embedded, Fabric and Power BI Premium Microsoft licenses

{% hint style="success" %}
**Important:** Your data is **NEVER** accessed by, made available to, or, stored within the Reporting Hub web application. &#x20;
{% endhint %}

## Component Functions

### Microsoft Entra ID (B2B)

Microsoft Entra ID (formerly called Azure Active Directory or AAD) is the default authentication method for the Reporting Hub. Entra ID B2B allows you to add guest users (outside of your tenant). Users and Groups are managed in Entra ID and are used to provide access to navigation options, reports and row-level security.&#x20;

{% hint style="info" %}
**Note:** The Reporting Hub also supports Okta, OpenID Connect & Auth0 authentication schemes. See App Settings > Authentication Admin in your [in-app help](/tutorials-and-references/in-app-help) for more information.
{% endhint %}

### Power BI Embedded

Power BI Embedded is the Microsoft license required to share Power BI content with un-licensed users. Your embedded capacity is applied to the Power BI workspaces you wish to make available to the Reporting Hub.&#x20;

### Azure App Service

The Reporting Hub is a stand-alone application instance installed directly within your Azure environment. An Azure App Service is required to 'host' the application.&#x20;

### Azure SQL Database

All the Reporting Hub application configuration data (logos, themes, navigation, report security, and audit logs) are stored in this Azure SQL Database.&#x20;

### Reporting Hub License Manager

The Reporting Hub license manager is a separate application that runs within the Reporting Hub Azure environment. Your locally deployed Reporting Hub application instance periodically communicates with the license manager to validate subscription.

{% hint style="info" %}
**Important:** Communication between your application and the Reporting Hub license manager is a simple ping via strongly encrypted keys. No data of any kind is stored with the license manager.  The Reporting Hub license manager can request and read the locally deployed Reporting Hub instance application log files by default.  Read access to the application log files can be disabled and blocked by the customer if desired.&#x20;
{% endhint %}

<details>

<summary>Log files made available to Reporting Hub license manager </summary>

The Reporting Hub application log has 2 types of entries:

**Information:**

* Entries to show if the app can access the database --> checkdatabase information Returned: found org
* Entries to show CapacityManager function
* Entries to show number of active tenants
* CapacityManagement function when started

&#x20;                                       when CapacityManagement/CapacityResume&#x20;

&#x20;                                       when CapacityManagement/Pause

&#x20;                                       when CapacityManagment/Refresh Schedule

* Entries for Cache Management

&#x20;                            When it skipped and when it cleared Memory

* Entries for Checking Ad App Secret

&#x20;                            when was the app secrete checked /updated

**Exceptions:**

* It records all the Exceptions and the functions involved along with debug information the application gets from Microsoft or the Reporting Hub App itself

&#x20;

</details>

#### Related Article

For more information on the Azure services required please reference:

{% content-ref url="/pages/YU5Ppdk3phslmIwIOwhE" %}
[Required Azure Services](/getting-started/required-azure-services)
{% endcontent-ref %}


# AaaS end-to-end Architecture

How to deliver Analytics-as-a-Service with the Reporting Hub & Microsoft Fabric

## What is Analytics-as-a-Service (AaaS)?&#x20;

The concept of Analytics-as-a-Service (AaaS) is similar to a Software-as-a-Service (SaaS) business model, however the main 'service' that you're providing is analytics-based content, typically in the form of pre-configured data visualization, models and insights.  Effectively, an AaaS business solution is still delivered as SaaS, so the two concepts are linked.

## How to Accelerate Delivery of your AaaS Solution

Historically, delivering an AaaS solution was a significant technical undertaking involving complex processes and disparate tools and workloads.  With the introduction and release of Microsoft Fabric much of the data framework can now be streamlined and delivered more efficiently and cost effectively.  The Reporting Hub then provides a no-code turn-key delivery platform for Power BI analytics content, with the complete solution contained within a Customer's Azure environment.

Microsoft Fabric together with the Reporting Hub provides a complete end-to-end framework to accelerate the delivery of an AaaS solution. &#x20;

## AaaS Solution Framework&#x20;

The Reporting Hub together with Microsoft Fabric presents a seamless solution framework to deliver AaaS.  The AaaS solution accelerator framework as shown below highlights how the Reporting Hub can be viewed as an extension of your data workloads for the purposes of delivering analytics content at scale to end-users via a plug'n'play front-end application.  &#x20;

<figure><img src="/files/mrYb2sTiAc8MuU5ctQGS" alt=""><figcaption></figcaption></figure>

## AaaS Solution Architecture Example

The below solution architecture diagram is a basic example that is meant to highlight the overall workflow, tools and workloads to deliver an AaaS solution.  The specific attributes of the architecture could vary in many different ways, but the overall process is generally consistent. &#x20;

<figure><img src="/files/NuJtmTAzOfmGZ5Qp979s" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**Please Note:**  Although the above solution architecture depicts Microsoft Fabric as the underlying recommended data framework, other data frameworks and tools can also be used.  The Reporting Hub is designed for seamless integration with Power BI using Power BI Embedded APIs, however the underlying data infrastructure can vary.
{% endhint %}

## Related Microsoft Content

{% embed url="<https://learn.microsoft.com/en-us/fabric/get-started/microsoft-fabric-overview>" %}

{% embed url="<https://learn.microsoft.com/en-us/fabric/onelake/onelake-overview>" %}

{% embed url="<https://learn.microsoft.com/en-us/power-bi/developer/embedded/embedded-analytics-power-bi>" %}


# Security & Trust Center

Your resource center for all security, privacy and compliance information related to a Reporting Hub deployment

The Reporting Hub takes security, privacy and compliance seriously and our goal is to ensure you have all the information you need to ensure your success.&#x20;

## Reporting Hub Architecture

The Reporting Hub is a fully deployed web-app that is installed within the customers Azure environment.  Our [Reporting Hub Architecture](/concepts/reporting-hub-architecture) documentation provides all the relevant information you will need to understand how the application works within Azure.   &#x20;

The Reporting Hub's policies can be found on our website here:

{% embed url="<https://thereportinghub.com/policies>" %}

## Security & Compliance Considerations for Reporting Hub’s Solution Deployment

At Reporting Hub, we understand the importance of security and compliance in enterprise environments. However, one of the challenges we consistently face is that many security questionnaires and audits operate under the assumption that we function as a traditional SaaS provider. Our solution is fundamentally different in its deployment model, which directly impacts how various security standards apply to us.

#### **Fully Deployed in Customer Environments – No Data Access**

Unlike most SaaS offerings that host customer data on their own infrastructure, Reporting Hub’s solution is fully deployed within the customer’s environment. This means:

* We **do not store, process, or transmit customer data** on our infrastructure.
* Customers maintain **full control over their data security and compliance** within their own Azure cloud.&#x20;
* Reporting Hub has **no access to customer data**, ensuring data sovereignty and eliminating risks associated with third-party data storage.

#### **Why Traditional Security Audits & Certifications May Not Apply**

Many security frameworks such as **SOC 2 and ISO 27001** are designed to assess a company’s ability to protect customer data **within its own infrastructure**. Since Reporting Hub does not store or have access to customer data, many of the security controls and requirements outlined in these frameworks do not apply to our solution.

For example:

* **SOC 2** focuses on the security, availability, and confidentiality of customer data stored within a vendor's systems. Since we do not handle customer data, these controls are not relevant.
* **ISO 27001** pertains to information security management systems (ISMS) for data stored within an organization’s environment. However, since our software runs **entirely within the customer’s environment**, their own security policies govern data protection, not ours.

#### **How We Address Security Concerns**

Although traditional SaaS compliance frameworks do not apply, we take security seriously and provide the following assurances:

1. **Secure Code Development** – We follow industry best practices for secure software development, including regular code reviews, static/dynamic security testing, and adherence to OWASP standards.
2. **Minimal Attack Surface** – Since our solution does not rely on an external multi-tenant infrastructure, the attack surface is limited to what is already protected within the customer’s own security framework.
3. **Customer-Managed Access Control** – Since the solution is deployed within the customer’s environment, they retain full control over **identity and access management (IAM), authentication, and authorization policies**.
4. **No Data Retention Risks** – Unlike SaaS providers that must implement data protection mechanisms, Reporting Hub does not retain any customer data, eliminating concerns around data leaks or breaches.
5. **Compliance Alignment** – While traditional SaaS security frameworks do not apply, we align with **customer security policies** and ensure our software integrates seamlessly into existing security models.

#### **Custom Security Assessments**

Since security audits are often based on predefined templates for SaaS solutions, we recommend that customers work with us to tailor security assessments that are **relevant to our specific deployment model**. Instead of evaluating Reporting Hub as a data processor or cloud service provider, security reviews should focus on:

* **Software security practices** (e.g., secure development lifecycle, vulnerability management).
* **Integration security** (e.g., how the solution interacts with customer data sources securely).
* **Deployment security** (e.g., customer-configurable security controls within their environment).

While SOC 2, ISO 27001, and similar frameworks are important for traditional SaaS vendors, they are **not applicable to Reporting Hub** due to our deployment model. Instead, our security posture is built around **secure software development, integration security, and customer-controlled deployment**.

We are happy to work with customers to address any security concerns within the **context of their specific environment** and ensure that Reporting Hub meets their security and compliance requirements without unnecessary overhead from frameworks that do not apply.

## Reporting  Hub Security & Compliance Overview Document

{% file src="/files/LWV9m5IZxnkSuwZgqeFD" %}

## Reporting Hub Application Security Controls

<details>

<summary>Reporting Hub Compliance - Audit Logging</summary>

The Reporting Hub includes built-in logging functionality with both application and audit logs. The logs are captured and stored in the Azure App Service within the client's environment. Below is a list of the information captured in the logs.

**Application Logging**

* Any exceptions/errors encountered by the application
* Information messages for Power BI embedded capacity operations and scheduled tasks in the Reporting Hub

**Audit Logging**

* Content page security changes - which security groups and/or individuals are assigned to a content page. This includes if a group/individual's RLS role changes.
* AD group - when sync groups is initiated, groups that were added/removed are tracked
* Application roles - when a user or user group's application role changes (user, content admin, application admin)
* Changes to Tenant admin - any changes made to on a tenant admin page (parent group, assigned workspaces, authentication scheme, billing, etc.)
* Power BI settings - any changes made to the capacity, time out settings, Power BI gateway\*, scheduled refresh
* Scheduled tasks - add, modify, delete scheduled tasks
* Subscription changes\* - when customer upgrades/downgrades their license

</details>

## Microsoft Security, Privacy & Compliance Documentation

The Reporting Hub is an Azure web application, built within the Azure framework using Microsoft APIs. The benefit of using the Reporting Hub is that you are taking advantage of all the built-in Microsoft security. The below list has been compiled to simplify the sourcing of this relevant information:

Microsoft Trust Center:

{% embed url="<https://www.microsoft.com/en-us/trust-center/product-overview>" %}

Microsoft Data Protection & Privacy:

{% embed url="<https://www.microsoft.com/en-ca/trust-center/privacy>" fullWidth="false" %}

Azure App Service Security:

{% embed url="<https://learn.microsoft.com/en-us/azure/app-service/overview-security>" %}

Power BI Security

{% embed url="<https://learn.microsoft.com/en-ca/power-bi/enterprise/service-admin-power-bi-security>" %}

{% embed url="<https://learn.microsoft.com/en-us/power-bi/guidance/whitepaper-powerbi-security>" %}

Data Protection in Power BI

{% embed url="<https://learn.microsoft.com/en-ca/power-bi/enterprise/service-security-data-protection-overview>" %}

Power Platform Compliance and Data Privacy

{% embed url="<https://learn.microsoft.com/en-us/power-platform/admin/wp-compliance-data-privacy>" %}

Power BI Governance & Compliance - Metadata Scanning

{% embed url="<https://learn.microsoft.com/en-ca/power-bi/enterprise/service-admin-metadata-scanning>" %}

Power BI Embedded Security:

{% embed url="<https://learn.microsoft.com/en-us/power-bi/developer/embedded/embedded-row-level-security>" %}

Embedded Analytics Access Tokens:

{% embed url="<https://learn.microsoft.com/en-ca/power-bi/developer/embedded/embed-tokens?tabs=embed-for-customers>" %}

Service Principal Profiles Security:

{% embed url="<https://learn.microsoft.com/en-ca/power-bi/developer/embedded/embed-multi-tenancy>" %}

Microsoft Compliance Offerings:

{% embed url="<https://learn.microsoft.com/en-us/compliance/regulatory/offering-home>" %}


# In-App Help

Our full library of step-by-step tutorials, troubleshooting guides, and reference materials is now accessible through the **Help** section in your **admin profile menu**.

* **Where to find it**: In the application, go to your profile (top-right corner) and select **Help**
* **Requirements**: You’ll need to be on **Version 7.0.0.2** or later to access this feature

This change ensures that admins have fast, secure access to the most up-to-date support content, right inside Reporting Hub.

<figure><img src="/files/vMRmRlDnIdOvSa4r8QTg" alt="" width="121"><figcaption><p>Click to enlarge</p></figcaption></figure>

You should see the help section that looks like this.

<figure><img src="/files/WgLnmQCKCI70rnMczAxa" alt=""><figcaption></figcaption></figure>

### I do not see the tutorials when accessing via my app.

If you are unable to see the in-app help center, it is likely due to your browser settings blocking third party cookies. See below how to enable for Chrome and Edge

#### Google Chrome

1. In the URL bar, paste in `chrome://settings/cookies`
2. Either allow third party cookies or add your Reporting Hub application URL to the allowed sites list

<figure><img src="/files/7KMxw98OtJYeDOfaWnKj" alt=""><figcaption></figcaption></figure>

#### Microsoft Edge

1. In the URL bar, paste in `edge://settings/privacy/cookies`
2. Either disable block third-party cookies or add your Reporting Hub application URL to the allowed sites list making sure to check **Include third-party cookies on this site**.

<figure><img src="/files/hoYqN1y4i1sZQ5pKh1G9" alt=""><figcaption></figcaption></figure>


# Overview of BI Genius

## What is  BI Genius?

**BI Genius** is a white-label AI agent building platform that allows your organization to deliver secure, no-code, conversational analytics experiences powered by your existing Power BI Semantic Models and enterprise data sources deployed entirely within your environment.

BI Genius is an AI-powered assistant that transforms the way end users interact with your data. Rather than relying solely on dashboards or pre-built reports, users can simply ask questions in natural language and receive instant, accurate responses, whether as summaries or visuals.

BI Genius is designed for flexibility, control, and enterprise-grade deployment. It runs entirely within your Azure environment, giving you full control over data access, governance, and customization.

<figure><img src="/files/4CZ6N7GYqJzOKYPOwtLC" alt=""><figcaption></figcaption></figure>

## How it Works

At its core, BI Genius connects to your Power BI Semantic Models and optionally other knowledge sources. It uses Azure OpenAI and natural language understanding to interpret user queries and generate responses grounded in your data.

The result: A fully branded, AI-driven analytics experience your users can trust.

### Key Components

| Component                               | Description                                                            |
| --------------------------------------- | ---------------------------------------------------------------------- |
| **White-Label Agent**                   | Fully customizable branding and experience for your users.             |
| **Power BI Semantic Model Integration** | Connects directly to your existing data models.                        |
| **Azure-Hosted Deployment**             | Deployed securely in your environment for full control and compliance. |
| **Multi-Source Support**                | Extendable to other datasets, or external documentation.               |
| **No-Code Configuration**               | Setup and customization requires no coding.                            |

### Why It's Different

Unlike Microsoft Copilot or other SaaS analytics assistants, BI Genius:

* **Is not tied to Microsoft Fabric licensing or workspace limitations**
* **Is not bound to Power BI’s native UI**
* **Allows full control of data sources, and security settings**
* **Can be embedded into any application or web portal**
* **Can be extended to data sources outside of Microsoft Fabric**

Whether you want to enhance your internal reporting or deliver branded AI experiences to customers, BI Genius is designed to fit seamlessly into your ecosystem.


# BI Genius Deployment Step-by-Step

Installing BI Genius is simple, easy and takes approximately 20 minutes. The Reporting Hub web application and required [Azure services](/getting-started/required-azure-services) can all be fully deployed by following our guided installation service.&#x20;

Your Reporting Hub app must be version 7.2.0.0 or higher to support BI Genius. View instructions on updating your Reporting Hub app by visiting your in-app documentation. In your application, open the Admin menu by selecting your profile icon and then Help > Self-Serve Guided Updates.

## Requirements

**Please review the checklist below before getting started:**

* [x] You have an active Azure Pay-as-you-go subscription.
* [x] You have [Global Admin](https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#global-administrator) and [Subscription Owner](https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal-subscription-admin) roles within your Azure subscription to complete the installation.
* [x] You have a Power BI online account.
* [x] You have a Reporting Hub web app, version 7.0.0.9 or higher.
* [x] You are agreeing to install the required Azure services:&#x20;
  * Azure Database for [PostgreSQL flexible server](https://azure.microsoft.com/en-us/pricing/details/postgresql/flexible-server/)
  * Azure Web App
  * Azure AI Foundry ([Azure OpenAI](https://azure.microsoft.com/en-us/pricing/details/cognitive-services/openai-service/))
* [x] You agree to the following Azure services setup conditions:

{% hint style="warning" %}
**Azure Services Setup Conditions**: *Any and all Azure services are not included within your BI Genius subscription. These services are deployed to your organizations' Azure instance and reside within your Azure subscription. Any and all Azure subscription fees are the responsibility of your organization. Once deployed, any changes or ongoing administration of these services are the responsibility of your organization.*
{% endhint %}

#### Ready to Get Started?  Click the link below and follow along!

{% embed url="<http://license.thereportinghub.com/install/bigenius>" fullWidth="false" %}

{% hint style="info" %}
**Need Help?** Contact our support team at [https://support.thereportinghub.com](https://support.thereportinghub.com/).  A dedicated team member will be available to assist with your deployment.&#x20;
{% endhint %}

## Follow Along With Our Guided Tutorial

The tutorial below outlines the step-by-step process to install and deploy BI Genius and associated Azure services within your Azure environment. For each Azure resource, you will have the option to select an existing resource or create a new resource.&#x20;

## Installation Steps

1. If prompted, grant **Application Admin Consent**: After signing in, you may be prompted to grant application admin consent to the Reporting Hub Installer application. This consent will allow the Installer application to deploy the applicable Azure services and BI Genius application within your Azure environment. You must grant consent to proceed and complete the installation.\
   \
   This is the same installer application used for the Reporting Hub, so you may have already granted it permission.

   <div align="center"><figure><img src="/files/wzNPgumzM3tLUozu1XYx" alt="" width="188"><figcaption><p>Admin consent form</p></figcaption></figure></div>

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>BI Genius Installer is a Microsoft <strong>'</strong><em><strong>verified</strong></em>' application and Shift Analytics Inc. is a Microsoft ISV Partner as identified on the Admin Consent page. This <a href="https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/manage-application-permissions?pivots=portal">admin consent</a> can be revoked at anytime following deployment via your Azure Portal.</p></div>

2. Start by selecting your **Azure Subscription** and **Azure Subscription** from the dropdown list and click **Next**.

   <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p>If the <strong>Select Subscription used for the BI Genius</strong> dropdown is empty, you may not have <strong>Subscription Owner</strong> permission for any Azure Subscriptions.</p></div>

   <div align="center"><figure><img src="/files/fKotwYU8aK3x6W0beVVz" alt="" width="563"><figcaption></figcaption></figure></div>

3. Select the **Reporting Hub application** and **domain** (slot) you want to add BI Genius to. Your Reporting Hub application must be version 7.0.0.9 or higher; the installer will verify that your selected Reporting Hub app is the minimum required version. Click **Next**.

<div align="center"><figure><img src="/files/9UozgRbVdJR5CwurFe0j" alt="" width="563"><figcaption></figcaption></figure></div>

4. Next, select your **Azure Resource Group**. Regional availability of the [required resources](#requirements) is limited. If a resource is not currently offered in your selected region, a notification will appear. You can keep your resource group in the selected region, but will need to choose a different region for the BI Genius resources.

   * If using an existing Resource Group, select it from the dropdown list and click **Next**. If you are using existing Azure resources instead of creating new ones, select the Resource Group that those resources belong to. Click **Next**.
   * If adding a new Resource Group, select **Add New** from the dropdown list. Enter a **Name** and select a **Resource Group Region**.  Click **Next.**

   <figure><img src="/files/uBVeO8qjTBJVubjDUzza" alt=""><figcaption></figcaption></figure>

5. Select your **Azure App Service**. Currently, you must create a new App Service for your BI Genius.&#x20;

   1. Select **Add New**.
   2. Enter a **Name** for your app service. The name can only contain alphanumeric characters, hyphens, parentheses, and underscores. Since BI Genius will be embedded in your application, the name is not public-facing.
   3. Select an app service **Tier**.
   4. Then, click **Next**.&#x20;

   <figure><img src="/files/8ihiiKNgABzywR08j109" alt=""><figcaption></figcaption></figure>

6. Select your **PostgreSQL Server**. You can choose an existing one or create a new one.&#x20;

   1. Select a **Region**.&#x20;
   2. Select a **Tier**; we recommend starting with Standard\_B1ms.
   3. Select **Storage**; we recommend starting with 32 GiB.
   4. Enter a **Server name** and **Database name**.&#x20;
      1. The server name can only contain lowercase letters, numbers, and hyphens. It must be between 3 and 63 characters long. It can't start or end with a hyphen. It also must be globally unique. &#x20;
      2. The database name can only contain alphanumeric characters and hyphens. It must be between 1 and 63 characters long.

   <figure><img src="/files/USgX964tndJvG5izL4Bb" alt=""><figcaption></figcaption></figure>

7. Select your **Azure OpenAI Service**.&#x20;

   1. In the dropdown menu, select **Add New**.
   2. Select a **Region**.
   3. Enter an **Azure OpenAI Service Account Name**.

   <figure><img src="/files/aCluGXrhVtwzrWM8jja0" alt=""><figcaption></figcaption></figure>

8. Name your Entra ID **Application** and **Service Principal**.

   1. **Application** is the name of your BI Genius App Registration
   2. **Service Principal** is the name of the Entra ID Security Group that the installer will create and add the App Registration as a member of.

   <figure><img src="/files/nG9pMpY5r0F0ANnsaoCF" alt=""><figcaption></figcaption></figure>

9. The installer will check that the selected Azure resources exist or are deployed. Once they're all deployed, select **Next**.&#x20;

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>If there are any failures, hover over the information icon in the failed status bar and note the error message that appears. Then, contact our support team at <a href="https://support.thereportinghub.com/">https://support.thereportinghub.com</a> so we can assist in the resolution.<br><strong>If you see a region-related error, see</strong> <a href="#deployment-failure-location-not-available"><strong>this section</strong></a><strong>.</strong></p></div>

   <figure><img src="/files/8TOyhMpGgdZ1DcVKQpak" alt=""><figcaption></figcaption></figure>

10. The BI Genius installation will begin. This step may take several minutes.

11. The installer will run a series of checks and start your new BI Genius application.&#x20;

    <div><figure><img src="/files/BKVWUc1wLpG1THrGR3YR" alt=""><figcaption></figcaption></figure> <figure><img src="/files/1rpXCV3s6qqgQLiihXki" alt=""><figcaption></figcaption></figure></div>

### Next Steps: Power BI Configuration

When the app has been successfully installed, you will need to ensure that BI Genius has been granted adequate permission in your Power BI tenant and to your Power BI workspaces.

{% content-ref url="/pages/NAoSwQdnIvvf1FL2tv2S" %}
[Enable Power BI Service Settings](/bi-genius/bi-genius-deployment-step-by-step/enable-power-bi-service-settings)
{% endcontent-ref %}

## Incomplete Installations

The installer provisions Azure resources incrementally during the setup process. If you exit the installation before it completes, some resources may remain active and could incur costs.&#x20;

If you stop the installer after the **Select your Azure Resource Group** step, we recommend reviewing your Azure portal to identify and delete any resources or objects the installer may have created. This includes reviewing your Entra ID for the App Registration and Security Group created in step 8.


# Enable Power BI Service Settings

After you have installed BI Genius, you need to ensure that it has been granted adequate permission in your Power BI tenant and given access to your Power BI workspaces.

## Enable Power BI Tenant Admin Settings

1. Go to **Tenant Settings** in the [Power BI Admin portal](https://app.powerbi.com/admin-portal/tenantSettings)&#x20;
2. For each [permission in the list below](#the-permissions-which-must-be-enabled-are), ensure that:
   1. It is **Enabled.**
   2. **Apply to** is set to: **The entire organization** or **Specific security groups**.&#x20;

If a permission is *Enabled for a subset of the organization*, add the security group that contains your BI Genius app (this is the Service Principal name you provided on the Entra ID Application Registrations step of the installer). Once you have added the security group, select **Apply**.

<figure><img src="/files/K86OJ07NZdxW7O1S69Nz" alt=""><figcaption><p>Example of enabling a PBI Tenant setting for a subset of the organization</p></figcaption></figure>

#### The permissions which must be enabled are:

* [x] Allow XMLA endpoints and Analyze in Excel with on-premises semantic models
* [x] Semantic model execute queries REST API
* [x] Service principals can call Fabric public APIs
* [x] Enhance admin APIs responses with detailed metadata
* [x] Enhance admin APIs responses with DAX and mashup expressions

## Connect Your Power BI Workspace

1. Log in to the [Power BI service](https://app.powerbi.com/).
2. On the left menu, select **Workspaces** and then choose the Workspace you want BI Genius to access.
3. From the top menu, select **Manage access**.
4. Select **Add people or groups**.
5. Begin typing the name of your BI Genius app registration. (This is the name that you entered on the Entra ID Application Registrations page of the installer in the Name your Application field.) Look for an option that contains an AppID field and select it.

   <figure><img src="/files/UwHoElvcHDmpNXxRoWDu" alt="" width="375"><figcaption></figcaption></figure>
6. Select **Admin** from the role dropdown.

   <figure><img src="/files/l9Lhi3svCI40CfJHu5eg" alt="" width="375"><figcaption></figcaption></figure>
7. Select **Add**.


# Enable BI Genius in Reporting Hub

Once you have installed BI Genius and enabled the appropriate permissions in the Power BI Service, you can enable BI Genius in your Reporting Hub tenants. You must enable BI Genius for a tenant and create an agent in order to add BI Genius to content pages in your Reporting Hub app.

### Enable BI Genius for a Reporting Hub Tenant <a href="#enable-bi-genius-for-a-reporting-hub-tenant" id="enable-bi-genius-for-a-reporting-hub-tenant"></a>

1. Select your profile icon and select **App Settings** to navigate to the Tenant Admin menu.
2. Next to the tenant you want to enable BI Genius for, select the **ellipsis (...)** and then **Edit**.

<figure><img src="/files/utST3olDo17cVnOqah4X" alt=""><figcaption><p>Edit Tenant</p></figcaption></figure>

3. At the top, select the **Report Options** tab.

<figure><img src="/files/DR4ZbNSpAgJOPLRRBpEX" alt=""><figcaption><p>Report Options tab</p></figcaption></figure>

3. Enable the toggle next to **BI Genius**.

<figure><img src="/files/t4BhvsJx3ZIRttdzuvlJ" alt="" width="563"><figcaption><p>Enable BI Genius Togglet</p></figcaption></figure>

3. Confirm the change by selecting **Yes** on the **Are you sure you want to change this?** pop-up.

<figure><img src="/files/vUTo3jYHYrIE8PHGsRWR" alt="" width="375"><figcaption><p>Confirm Changes</p></figcaption></figure>

3. BI Genius has been enabled for the tenant.

<figure><img src="/files/qffkQ99RvRGmZFKSaYtw" alt="" width="563"><figcaption><p>BI Genius is enabled</p></figcaption></figure>


# BI Genius Required Services


# BI Genius vs. Co-Pilot for Power BI

While both **BI Genius** and **Microsoft Co-Pilot for Power BI** offer AI-powered analytics experiences, they serve very different needs when it comes to flexibility, branding, deployment, and control.

This article breaks down the key differences so you can understand where BI Genius fits—and why many organizations choose it to power their AI-driven reporting strategy.

## At a Glance: Key Differences

| Feature                         | BI Genius                                                        | Co-Pilot for Power BI                                                     |
| ------------------------------- | ---------------------------------------------------------------- | ------------------------------------------------------------------------- |
| **Deployment Model**            | Fully deployed in your own Azure environment                     | SaaS-based, Microsoft-hosted                                              |
| **White-Label Experience**      | Yes — fully customizable branding                                | No — branded as Microsoft Co-Pilot                                        |
| **Power BI License Dependency** | Not tied to Fabric or F64 capacity licensing                     | Requires Microsoft Fabric licensing                                       |
| **UI Independence**             | Can be embedded outside Power BI (e.g., web apps, portals)       | Only works within Power BI interface.  Not supported by Power BI Embedded |
| **Prompt & UX Control**         | Full control over prompt direction and instructions              | Limited configuration                                                     |
| **Data Source Flexibility**     | Extendable beyond Power BI (e.g., internal docs, online sources) | Limited to Power BI datasets and Fabric content                           |
| **Security & Compliance**       | Self-hosted for complete control over data and access            | Data processed in Microsoft’s cloud                                       |
| **Multi-Tenant Support**        | Yes — ideal for customer-facing use cases                        | No — user-based inside a single tenant                                    |

## Design Philosophy

**Co-Pilot for Power BI** is optimized for internal users working within the Microsoft ecosystem. It’s a great productivity tool for analysts or stakeholders who are already using the Power BI interface and want to explore reports or datasets conversationally.

**BI Genius**, on the other hand, is built for organizations that need:

* **External delivery** of AI-powered analytics (e.g., customers, partners)
* **Full branding control** (white-label)
* **Deployment flexibility** (web apps, portals, intranets)
* **Data sovereignty and compliance** (self-hosted)

It complements your existing Power BI investment while freeing you from Microsoft constraints or limitations.

## When to Choose BI Genius

Choose **BI Genius** if you want to:

* Provide **AI analytics access to external users** without requiring a Power BI license
* Embed a **conversational analytics experience** into your own apps, websites, or client portals
* Maintain **control over hosting, data residency, and security**
* Extend beyond Power BI to include **documentation, or custom knowledge sources**
* Differentiate your analytics offering with **a branded AI experience**


# BI Genius Architecture Overview

**BI Genius** is designed to be secure, scalable, and fully controllable, giving organizations the ability to deploy their own AI-powered analytics assistant without relying on third-party hosting or SaaS platforms.

This article outlines the **core architecture of BI Genius**, highlighting the key components, how they interact, and where the solution is deployed.

## High-Level Architecture

BI Genius follows a **modular, cloud-native architecture** built entirely on Azure. It’s composed of the following primary components:

#### 1. **AI Agent (Frontend)**

* A customizable, white-labeled web component that can be embedded into any application or portal
* Provides the user interface for natural language interactions (chat, voice, or text input)
* Sends user queries to the backend engine for interpretation and response

#### 2. **Orchestration Engine (API Layer)**

* Receives user input and routes it through the appropriate processing pipeline
* Handles conversation flow, session management, and security checks
* Applies prompt engineering logic and instructions based on your configuration

#### 3. **Data Context Engine**

* Connects to your **Power BI Semantic Models** using XMLA and DAX queries
* Optionally connects to additional sources such as internal knowledge bases, PDFs, SharePoint, or public websites
* Assembles and structures the data context to be used by the AI model

#### 4. **Azure OpenAI Integration**

* Leverages **Azure-hosted OpenAI services** for natural language understanding and generation
* Operates entirely within your Azure subscription—no data is sent to external SaaS providers
* Interacts with structured data and knowledge to generate grounded, reliable responses

#### 5. **Admin & Configuration Portal**

* Used to configure prompt behavior, data sources, branding, user access, and security settings
* Supports versioning, access controls, and environment-specific settings
* Enables non-technical users to manage and maintain the AI assistant

## Security & Deployment

**Fully Deployed in Your Azure Environment**\
All components are deployed inside your Azure subscription—ensuring full control over data, access, and compliance.

**No Customer Data Leaves Your Network**\
The entire interaction—from user prompt to AI response—occurs within your infrastructure.

**Role-Based Access Control (RBAC)**\
Fine-grained permissioning allows you to restrict features, data sources, or user types.  Power BI RLS fully supported.

## Summary

* BI Genius is **deployed entirely in your Azure environment**—you control everything.
* It’s built for **Power BI-centric analytics**, but can also ingest external content.
* You get a **branded, embeddable AI assistant** without giving up data sovereignty or flexibility.


# Understanding Query Logic in BI Genius

Built for Explainability. Designed for Trust.

BI Genius is not a black box. While it leverages powerful AI to understand and respond to user questions, every step of the process is **explainable, auditable, and grounded in your data**.

This article explains how BI Genius handles user queries, what happens behind the scenes, and how we prioritize transparency in every interaction.

## What is Query Logic?

In BI Genius, ***query logic*** refers to the step-by-step process the system follows when a user asks a question—transforming natural language into an accurate, data-driven response.

This process involves:

1. **Understanding the user’s intent**
2. **Mapping the request to your data model**
3. **Constructing a DAX, SQL query or structured explanation**
4. **Returning the result with contextual reasoning**

Every one of these steps is traceable and explainable—by design.

## The Basic Query Flow

Here’s a simplified breakdown of how BI Genius processes a query:

#### 1. **Intent Parsing (AI Layer)**

* The user types a natural language question (e.g., “How did sales perform last quarter?”).
* Azure OpenAI interprets the request, identifies relevant metrics, dimensions, and time filters.

#### 2. **Context Assembly**

* BI Genius references your Power BI Semantic Model to locate the appropriate tables, measures, and filters.
* Optional external knowledge (e.g., glossary terms, documentation) may be used to disambiguate or enrich the query.

#### 3. **Query Generation**

* BI Genius builds a **DAX query** (or narrative logic) tailored to your model.
* This query is assembled transparently—you can view and audit the logic used.

#### 4. **Execution and Response**

* The query is executed against your dataset via XMLA or REST APIs.
* The response is returned to the user—optionally with a **plain-language explanation of how the result was calculated**.

***

### 🔍 Example

**User Prompt:**

> “What were the top 5 regions by profit last year?”

**BI Genius Explanation (visible to user):**

> “I calculated this by filtering your ‘Profit’ measure by last calendar year, then sorting by region and returning the top 5 results.”

**Technical View:**

```dax
DAX Expression

TOPN(5, 
     SUMMARIZE('Sales', 'Region'[Name], "Profit", [Total Profit]), 
     [Total Profit], DESC)
```

## Why Explainability Matters

Transparency builds trust, especially when AI is involved in data interpretation. BI Genius was built with explainability in mind to ensure:

**Accuracy** — users can verify the logic used in a response

**Trust** — especially in regulated industries or critical decision workflows

**Learning** — users grow more confident in both BI Genius and the underlying data

**Compliance** — audits are supported with traceable, interpretable query steps

## Customization & Control

* You can configure whether users see **just the answer**, or the underlying **query logic breakdown**.
* **Query Audit Logs** for Admins: View historical query chains and logic trees for traceability and providing troubleshooting assistance.&#x20;


