# Reporting Hub Knowledge Center

### Watch our Platform Demo!

{% embed url="<https://youtu.be/Fs7IcrAhqtM>" %}

### Turn-Key Power BI Delivery Platform using *Power BI Embedded*&#x20;

The Reporting Hub is a web-based business intelligence platform that seamlessly integrates with Power BI using Embedded technology. It is a plug 'n' play white label application that deploys to your Azure environment and allows you to instantly deliver Power BI in a more efficient and cost effective manner.

#### See the Reporting Hub featured in Microsoft Documentation:&#x20;

{% embed url="<https://learn.microsoft.com/en-us/power-bi/developer/embedded/embedded-analytics-accelerators>" %}

#### Watch the Microsoft Partner Solution Showcase:

{% embed url="<https://microsoft.github.io/PartnerResources/skilling/microsoft-partner-showcase/reportinghub>" %}

## How Does it Work?

![](/files/kRnub5aFTflpLtMreven)

Reporting Hub integrates with your Power BI Tenant and Microsoft Entra ID (or other supported Auth Scheme) within YOUR Azure environment. The entire solution is contained within your environment and no changes are required to your existing data architecture or Power BI content.

## Understanding Microsoft Licensing Terms

When deploying and operating the Reporting Hub, it's important that you understand and are in compliance with Microsoft's Power BI licensing terms.  It is the customer's responsibility to ensure compliance with Microsoft with respect to your use of Power BI.&#x20;

Please see link below from Microsoft to learn and ensure compliance with special attention paid to the following section:

**"Microsoft Power BI**

**Definitions**

“Customer Application” means an application or any set of applications that adds primary and significant functionality to the Embedded Capabilities and that is not primarily a substitute for any portion of Microsoft Power BI services.

“Embedded Capabilities” means the Power BI APIs and embedded views for use by an application.

**Hosting Exception for Embedded Capabilities**

Customer may create and maintain a Customer Application and, despite anything to the contrary in Customer’s volume licensing agreement, combine Embedded Capabilities with Customer Data owned or licensed by Customer or a third party, to create a Customer Application using the Embedded Capabilities and the Customer Data together. Any Power BI content accessed by the Customer Application or its end users must be stored in Microsoft Power BI Premium capacity. Customer may permit third parties to access and use the Embedded Capabilities in connection with the use of that Customer Application. Customer is responsible for that use and for ensuring that these terms and the terms and conditions of Customer’s volume licensing agreement are met by that use.

**Limitations**

Customer may not

* resell or redistribute the Microsoft Power BI services, or
* allow multiple users to directly or indirectly access any Microsoft Power BI feature that is made available on a per user basis."

{% embed url="<https://www.microsoft.com/licensing/terms/en-US/productoffering/MicrosoftPowerPlatform/EAEAS#ServiceSpecificTerms>" %}

## Getting Started

Follow our handy guides to get started with everything you need.

{% content-ref url="/pages/YU5Ppdk3phslmIwIOwhE" %}
[Required Azure Services](/getting-started/required-azure-services)
{% endcontent-ref %}

{% content-ref url="/pages/mR5xkJjszCkXSyreMmIV" %}
[Deployment Step-by-Step](/getting-started/deployment-step-by-step)
{% endcontent-ref %}


# Required Azure Services

Everything you need to deploy the Reporting Hub

The Reporting Hub is a cloud based web application that is installed and deployed directly to your Azure Environment. In order to deploy the Reporting Hub the following Azure Services are required.  &#x20;

{% hint style="success" %}
**Good to know:** The Reporting Hub Installer will install and properly configure all required Azure resources along with the application itself with your Azure Resource Group.  If preferred, you can also manually install the Azure resources.
{% endhint %}

## Azure Services Required

* [x] [Fabric Capacity or Power BI Embedded Capacity](#power-bi-embedded-capacity)
* [x] [Azure App Service](#azure-app-service)
* [x] [Azure SQL Database](#azure-sql-database)
* [x] [Azure Translator (Free)](#azure-translator)

{% hint style="info" %}
**Please note:** Any and all Azure services are not included within the Reporting Hub subscription. These services are deployed to your organizations' Azure instance and will fall under your Azure subscription. Any and all Azure subscription fees are the responsibility of your organization. &#x20;
{% endhint %}

### Fabric Capacity/Power BI Embedded Capacity

The Reporting Hub is a plug 'n' play, no-code solution for Power BI embedded analytics. The Capacity (Power BI Embedded Capacity or Microsoft Fabric Capacity) allows you to share your Power BI content with users who don't have a Power BI or Microsoft license. Both Fabric and Power BI Embedded Capacities are capacity-based licenses, which means you are paying for a dedicated amount of computing resources vs. a specific number of users. We recommend organizations start with a ***F2 node*** and scale according to need. For more information on pricing and capacity planning, please refer to the Microsoft documentation link below.&#x20;

{% hint style="success" %}
**Good to know:** The Reporting Hub Capacity Manager will allow you to reduce this monthly capacity cost by programmatically activating and pausing your Capacity based on usage. By default, the Reporting Hub will keep your Capacity paused when not in use. When your capacity is paused, you will not incur costs.
{% endhint %}

{% embed url="<https://azure.microsoft.com/en-ca/pricing/details/power-bi-embedded>" %}

{% hint style="info" %}
**NEW Fabric Capacities** are now supported!  With Reporting Hub *version 6.4*, you can now take advantage of Microsoft's new Fabric Capacities with your Reporting Hub.&#x20;
{% endhint %}

{% embed url="<https://azure.microsoft.com/en-ca/pricing/details/microsoft-fabric/>" %}

We recommend using the Microsoft Fabric Capacity Metrics app to monitor your Fabric usage.

{% embed url="<https://learn.microsoft.com/en-us/fabric/enterprise/metrics-app>" %}

Visit our [Embedded Capacity Admin](broken://pages/am2cyvZprcdF7v7BvOuV) page for more details on Power BI Embedded Capacity.

### Azure App Service

An Azure App Service is a fully managed service with built-in infrastructure maintenance, security patching and scaling for web apps within Azure. The Reporting Hub application instance is deployed and hosted to this App Service within your Azure environment. We recommend a ***S1*** ***instance*** for production scenarios. Please refer to the Microsoft documentation link below for more information. &#x20;

{% embed url="<https://azure.microsoft.com/en-ca/pricing/details/app-service/windows>" %}

{% hint style="info" %}
**Please note:** The minimum App Service tier required is a **B1** Basic Service Plan. The Free or Shared plans *WILL NOT* support the application.&#x20;
{% endhint %}

### Azure SQL Database

An Azure SQL Database is required to store the Reporting Hub application configuration, log and audit files. This database is very small and can run on the lowest database tier available in Azure.  If your organization does not have an exiting Azure SQL instance, we recommend a single database **'Basic' Service Tier** and **'DTU' Purchase model.** For more information on region specific pricing please refer to the Microsoft documentation link below.

{% embed url="<https://azure.microsoft.com/en-us/pricing/details/azure-sql-database/single>" %}

### Azure Translator

The Reporting Hub is a multi-language application that can be configured into any language. The Azure Translator service is used to complete language translation. There is **no cost** to this service as the Reporting Hub leverages the free service instance only. This service is required even if you do not plan on using the multi-languages feature.

{% embed url="<https://azure.microsoft.com/en-us/products/cognitive-services/translator/#overview>" %}

## What if I don't have an Azure Instance?

**No Azure? No problem!**&#x20;

All you need to do is follow the link below to set up a Pay As You Go Azure account to get started. Once you have an Azure subscription in place you can proceed with deploying the Reporting Hub.&#x20;

{% embed url="<https://azure.microsoft.com/en-us/pricing/purchase-options/pay-as-you-go>" %}


# Deployment Step-by-Step

Get up and running with the Reporting Hub!

{% hint style="success" %}
**Get Started** with a 30-day Growth tier free trial. No obligation, no credit card required. *Please note:* *Azure services costs may still apply.*
{% endhint %}

**Deployment has two parts, and both are required before you can embed content.**&#x20;

First, **install** the Reporting Hub application (step 1). Then complete the configuration (steps 3–4): **Configure Power BI** requires a **Fabric or Power BI administrator**, and **Configure Reporting Hub** requires a **Reporting Hub Global Admin** (by default, the user who ran the install). Until configuration is done, no content can be embedded. Before you start, confirm who will handle each part.

#### 1. Install and deploy the Reporting Hub *(Azure Global Admin & Subscription Owner)*

{% content-ref url="/pages/1H8wP6dzjP8qdChwnaMg" %}
[Self-Serve Guided Install](/getting-started/deployment-step-by-step/self-serve-guided-install)
{% endcontent-ref %}

#### **2. Add AI with BI Genius (***Azure Global Admin & Subscription Owner)*

Your plan includes a BI Genius starter agent. Deploy it at the end of the install, or any time afterward.

{% content-ref url="/pages/8xuFfRGmiEWM9bp08DyU" %}
[BI Genius Deployment Step-by-Step](/bi-genius/bi-genius-deployment-step-by-step)
{% endcontent-ref %}

#### **3. Configure your Power BI Tenant settings** & Workspace *(Fabric or Power BI Admin)*

{% content-ref url="/pages/ZTurS8WKwsHYDkpOORRM" %}
[Enable Power BI Service Settings](/getting-started/deployment-step-by-step/enable-power-bi-service-settings)
{% endcontent-ref %}

#### **4. Configure your Reporting Hub App Settings** *(Reporting Hub Global Admin)*

{% content-ref url="/pages/D6QLOw6IhUgl69x7qJL6" %}
[Configure Reporting Hub App Settings](/getting-started/deployment-step-by-step/configure-reporting-hub-app-settings)
{% endcontent-ref %}

#### **5. Learn to use Reporting Hub**

{% content-ref url="/pages/fmYjHXgF7pL3ZhniLF1B" %}
[Learn to Use Reporting Hub](/getting-started/deployment-step-by-step/learn-to-use-reporting-hub)
{% endcontent-ref %}


# Self-Serve Guided Install

Install and deploy the Reporting Hub with our guided install service

{% hint style="success" %}
**Get started** with a 30-day Growth-tier free trial. No obligation, no credit card required. *Please note:* *Azure services costs may still apply.*
{% endhint %}

Our guided installer deploys the Reporting Hub web application and all required [Azure services](/getting-started/required-azure-services) into your own Azure environment, one wizard page at a time. For every Azure resource, you can either **select an existing resource** or **create a new one**.

Here's the full deployment journey. This page covers the install itself and turning on AI; the last two stages are quick configuration steps on their own pages.

<table><thead><tr><th width="199">Stage</th><th width="309">What you'll do</th><th>Where</th></tr></thead><tbody><tr><td><strong>1. Install &#x26; deploy</strong></td><td>Grant consent, choose your subscription and resource group, configure your Azure resources, then deploy and launch Reporting Hub.</td><td>This page (steps 1–12)</td></tr><tr><td><strong>2. Add AI (BI Genius)</strong></td><td>Deploy required services for AI: PostgreSQL and Azure AI Foundry.</td><td>Step 13: <a href="/pages/8xuFfRGmiEWM9bp08DyU">Deploy BI Genius</a></td></tr><tr><td><strong>3. Configure Power BI</strong></td><td>Enable the required Power BI tenant settings and connect your workspaces.</td><td><a href="/pages/ZTurS8WKwsHYDkpOORRM">Enable Power BI Service Settings</a></td></tr><tr><td><strong>4. Configure Reporting Hub</strong></td><td>Sync your groups, set up your Global Tenant, and set your home page.</td><td><a href="/pages/D6QLOw6IhUgl69x7qJL6">Configure Reporting Hub App Settings</a></td></tr></tbody></table>

## Before You Begin

* [x] You have an active Azure Pay-as-you-go subscription.
* [x] You have [Global Admin](https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#global-administrator) and [Subscription Owner](https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal-subscription-admin) roles within your Azure subscription.
* [x] You have a Power BI online account.
* [x] You are agreeing to install the required [Azure services](/getting-started/required-azure-services).
* [x] You agree to the following Azure services setup conditions:

{% hint style="warning" %}
**Azure Services Setup Conditions**: *Any and all Azure services are not included within your Reporting Hub subscription. These services are deployed to your organizations' Azure instance and reside within your Azure subscription. Any and all Azure subscription fees are the responsibility of your organization. Once deployed any changes or ongoing administration of these services are the responsibility of your organization.*
{% endhint %}

***

<h2 align="center"><a href="https://thereportinghub.com/trial">Click here to start the installation</a></h2>

***

{% hint style="warning" %}
**Using existing Azure resources?** Use the [**Azure service settings**](#azure-services-configuration-settings) reference at the bottom of this page to confirm each resource is configured correctly, and correct any mismatched settings before continuing, otherwise the installation will fail.
{% endhint %}

## Installation Steps

{% stepper %}
{% step %}

### **Grant Application Admin Consent**&#x20;

After signing in, you'll be prompted to grant application admin consent to the Reporting Hub Installer application. This lets the Installer deploy the Azure services and Reporting Hub web application within your Azure environment. You must grant consent to proceed.

{% hint style="info" %}
Reporting Hub Installer is a Microsoft **'*****verified***' application, and Shift Analytics Inc. is a Microsoft ISV Partner as identified on the Admin Consent page. This [admin consent](https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/manage-application-permissions?pivots=portal) can be revoked at anytime following deployment via your Azure Portal.
{% endhint %}

<div align="center"><figure><img src="/files/obbCQF4rIXOYUi18kpZg" alt="" width="213"><figcaption><p>Admin Consent Form</p></figcaption></figure></div>
{% endstep %}

{% step %}

### Select the Azure Tenant & Subscription

* Choose the **Azure Tenant** and **Subscription** from the dropdown lists.
* Select **Next**.

{% hint style="warning" %}
If the **Select Subscription used for the Reporting Hub** dropdown is empty, you may not have **Subscription Owner** permission for any Azure Subscriptions.
{% endhint %}

<div align="center"><figure><img src="/files/vRcLq4ZytN4RUaZU08wp" alt="" width="375"><figcaption><p>Select the Azure Subscription</p></figcaption></figure></div>
{% endstep %}

{% step %}

### Select your Azure Resource group

You can select an existing resource group **or** add a new one. We recommend creating a new resource group to keep your Reporting Hub resources organized.

* **Existing resource group:** select it from the dropdown, then select **Next**. If you're using existing Azure resources, choose the resource group those resources belong to.
* **New resource group:**&#x20;
  * Select **Add New.**
  * Enter a **Name**, and choose a **resource group region**.
  * Select **Check Resource Availability** to confirm the required resources can be deployed in that region.
    * **App Service**
    * **SQL Database**
    * **Fabric Capacity**&#x20;
  * When each shows a green check, select **Next**.

<div><figure><img src="/files/HV0KAQdRUBXdrX8hRaZN" alt=""><figcaption><p>Check your Azure Resource Quota</p></figcaption></figure> <figure><img src="/files/04KzHIvqDWMuX6zRof8e" alt=""><figcaption><p>All resources have Quota for this region.</p></figcaption></figure></div>

{% hint style="warning" %}
If a resource is flagged as unavailable in your chosen region, **Next** stays disabled. Select **I'll choose a different region (you'll be prompted)** to deploy that resource elsewhere, or see [**Request a Quota Increase**](/getting-started/deployment-step-by-step/self-serve-guided-install/quota) to request capacity in your preferred region.
{% endhint %}
{% endstep %}

{% step %}

### Select your Azure SQL Server and database

* **Existing SQL Server:** select it from the dropdown, then select an existing database **or** create a new one. You'll be prompted to sign in with your SQL Server credentials. **Any data in an existing database will be overwritten.**

{% hint style="warning" %}
When using an existing SQL Server, you must sign in with **SQL authentication** credentials. Microsoft Entra ID credentials will **not** work here.\
**Any data in an existing database will be overwritten.**
{% endhint %}

* **New SQL Server:**&#x20;
  * Select **Add New.**
  * Name your **SQL Server and database.**
  * Select **Next**.

<figure><img src="/files/vnvZv9rTFoirAUPyszZs" alt="" width="375"><figcaption><p>Creating a new SQL Server and database</p></figcaption></figure>
{% endstep %}

{% step %}

### Select your Azure App Service.

{% hint style="success" %}
Good to Know: Your app service name determines the default domain for your website: `<AppServiceName>.azurewebsites.net`.
{% endhint %}

* **Existing App Service:** select the App Service, then select an existing slot **or** select **Add New**, then select **Next**.
* **New App Service:**&#x20;
  * Select **Add New.**
  * Enter a **Name.**
  * Select a **Tier.**
  * Select **Next**.

<figure><img src="/files/9hMq6e2NosTdPykX0mMY" alt="" width="375"><figcaption><p>Creating a new App Service</p></figcaption></figure>
{% endstep %}

{% step %}

### Select your Fabric or Embedded capacity

{% hint style="warning" %}
By default, Reporting Hub manages (pauses and resumes) the capacity you select or create here based on in-app activity. If you select an existing capacity, this may affect existing Power BI/Fabric workloads on it.
{% endhint %}

* **Existing capacity:** select it from the dropdown and select **Next**.
* **New capacity:**&#x20;
  * Select **Add New.**
  * **Create Fabric capacity** is checked by default. If you want to deploy an A1 Embedded capacity instead, uncheck the box.&#x20;
  * Name your **capacity**.
  * Select **Next**.

<figure><img src="/files/hqVEdv1mkh63Yrs3tohC" alt="" width="375"><figcaption><p>Create a new Fabric Capacity</p></figcaption></figure>
{% endstep %}

{% step %}

### Select your Azure Translator

* **Existing Translator:** select it from the dropdown and select **Next**.
* **New Translator:**&#x20;
  * Select **Add New.**
  * Name your **Translator**.
  * Select **Next**.

<figure><img src="/files/QHf8066l2arf0uDZnzte" alt="" width="375"><figcaption><p>Create a Translator</p></figcaption></figure>
{% endstep %}

{% step %}

### Register your Entra ID application.

{% hint style="warning" %}
**IMPORTANT:** Note down your **Application name** and **Service Principal name;** you'll need them later when granting access within the Power BI Service.
{% endhint %}

* **Name your Application:** this is your Reporting Hub app registration.
* **Name your Service Principal:** this creates an Entra ID **security group** with the app registration as a member. You'll use this security group in the next stage, when you enable your Power BI settings.
* Select **Microsoft SSO.**
* Select **Next.**

{% hint style="success" %}
**Tip:** Give the application and the service principal the **same name** so they're easy to find together later.
{% endhint %}

<figure><img src="/files/2GFItpfHVjnXMUqdLiV2" alt="" width="375"><figcaption><p>Name the Entra ID App Registration</p></figcaption></figure>
{% endstep %}

{% step %}

### Review the deployment checks

The installer deploys, or connects to, each Azure resource:&#x20;

* **Azure SQL Server and Database**
* **Azure App Service**
* **Power BI Embedded/Fabric capacity**
* **Azure AI Translator**
* **Entra ID application**.&#x20;

Each shows **Deploying…**, then **Deployed**. Once every resource shows **Deployed**, select **Next**. If any shows **Failed**, see the callout below.

{% hint style="danger" %}
**Deployment failures:** Review the [**Installation Failures**](/getting-started/installation-failures) page and follow the steps for the error you're seeing. If the error relates to location or region, see [Quota](/getting-started/deployment-step-by-step/self-serve-guided-install/quota).
{% endhint %}

<div><figure><img src="/files/qc4HE2xXTJ6vhBqu1xnR" alt="" width="375"><figcaption><p>Confirming Resource Deployment</p></figcaption></figure> <figure><img src="/files/rMj9PO101GscUgTZBDg2" alt="" width="375"><figcaption><p>Successfully Deployed All Resources</p></figcaption></figure></div>
{% endstep %}

{% step %}

### Grant admin consent for your new Reporting Hub application

You'll be prompted to grant consent for permission on your new Reporting Hub Azure Entra ID application. This allows your Reporting Hub instance to access your Microsoft tenant and Power BI. The name shown at the top of the consent screen matches the **Application name** you set in step 8, so you can confirm you're granting consent to the right application.

{% hint style="info" %}
This consent grants permission for *your* deployed instance of Reporting Hub to access *your* Microsoft tenant details, including Power BI. It will show as "unverified". This is expected, since you haven't verified your application yet. To verify your application, see Microsoft's [Mark App As Publisher Verified](https://learn.microsoft.com/en-us/azure/active-directory/develop/mark-app-as-publisher-verified) documentation. Note, verifying your app is not required.
{% endhint %}

<div><figure><img src="/files/Z382Jc8DDG1ZIUgg1ROn" alt="" width="375"><figcaption><p>Application Consent Explanation</p></figcaption></figure> <figure><img src="/files/TIPFHKDGzzszllrHnOn5" alt=""><figcaption><p>Granting Consent</p></figcaption></figure></div>
{% endstep %}

{% step %}

### Complete the installation and contact form

After you grant consent, the installer copies the application files. This may take several minutes, depending on your Azure region.&#x20;

On the **Starting application** page, fill in&#x20;

* Your **Application Registration Information** of the best contact person for your company.
* The short **Power BI Adoption** questions.
* Then select **Save Contact Data** to continue.

{% hint style="success" %}
The Reporting Hub team uses these details to get in touch and help with your onboarding. This step is required to finish the installation.
{% endhint %}

<div><figure><img src="/files/9ICSV7uqR4AeGqO4xPaD" alt="" width="375"><figcaption><p>Files Installation</p></figcaption></figure> <figure><img src="/files/OcZfJPbH6TVIMkhq6Jyz" alt="" width="375"><figcaption><p>Fill in your details, then select Save Contact Data to proceed</p></figcaption></figure></div>
{% endstep %}

{% step %}

### Launch your application

On the **Success!** page, select the link to your new Reporting Hub application to open it. If the installation fails instead, review the [Installation Failures](/getting-started/installation-failures) page.

{% hint style="success" %}
**Check your inbox.** Whoever ran the installation also receives a confirmation email from **Reporting Hub Install Information**, subject: **The ReportingHub Install,** listing all your deployment details: application URL, Azure subscription name, resource group, Azure AD application and service principal names and IDs, and capacity name. \
Keep it handy; you'll need the **application** and **service principal** names when you configure Power BI.
{% endhint %}

<figure><img src="/files/IYAwucCf4CCsKcyc7CjG" alt="" width="375"><figcaption><p>Select the link to access your application</p></figcaption></figure>
{% endstep %}

{% step %}

### (Optional) Add AI: Deploy BI Genius

{% hint style="info" %}
**Prefer to set up AI later?** You can skip this step and deploy BI Genius at any time by following the [BI Genius Deployment Step-by-Step](/bi-genius/bi-genius-deployment-step-by-step) guide. As with your other Reporting Hub resources, the PostgreSQL and Azure AI Foundry resources are deployed to your own Azure subscription, so Azure usage costs apply.
{% endhint %}

Your plan includes **BI Genius,** governed, no-code AI agents that answer questions on your Power BI semantic models in plain language, inside your own Azure tenant, with every answer showing its sources, reasoning, and DAX. Your plan comes with a **starter agent**, so you can turn on AI right at the end of the installation.

Because your Reporting Hub App Service is already deployed, BI Genius reuses it and only deploys the two extra Azure resources it needs:

* **Azure Database for PostgreSQL** (flexible server)
* **Azure AI Foundry** (Azure OpenAI)

To turn on AI now, select the **add BI Genius** link on the **Success!** page, or go to [license.thereportinghub.com/install?id=bigenius](https://license.thereportinghub.com/install?id=bigenius), and follow the prompts to select or create these resources, just as you did for your Reporting Hub resources.&#x20;

For details on each option, see the [BI Genius Deployment Step-by-Step](/bi-genius/bi-genius-deployment-step-by-step) guide.

{% content-ref url="/pages/8xuFfRGmiEWM9bp08DyU" %}
[BI Genius Deployment Step-by-Step](/bi-genius/bi-genius-deployment-step-by-step)
{% endcontent-ref %}
{% endstep %}
{% endstepper %}

## Next (Required): Configure Power BI

{% hint style="danger" %}
You're not done yet. You **must complete** the Power BI Service Settings and Reporting Hub App Settings configurations before you can embed any content in your application.
{% endhint %}

Once the Reporting Hub application is installed, configure Power BI tenant settings and Reporting Hub settings to start adding content to\
\
The Power BI settings are enabled by a **Fabric or Power BI administrator**; the Reporting Hub App Settings require a **Reporting Hub Global Admin** (by default, the user who ran the install).

Follow these two guided tutorials to finish your deployment:

{% content-ref url="/pages/ZTurS8WKwsHYDkpOORRM" %}
[Enable Power BI Service Settings](/getting-started/deployment-step-by-step/enable-power-bi-service-settings)
{% endcontent-ref %}

{% content-ref url="/pages/D6QLOw6IhUgl69x7qJL6" %}
[Configure Reporting Hub App Settings](/getting-started/deployment-step-by-step/configure-reporting-hub-app-settings)
{% endcontent-ref %}

***

#### Azure Services Configuration Settings

{% hint style="info" %}
**Please note**: this section only applies if you're using pre-existing Azure services. If you are creating new services as part of the guided installation process, you can omit this section as the installer will ensure these services are configured correctly.
{% endhint %}

The details below are a reference **if needed** during installation. If you've already deployed your application successfully, continue to the Power BI Service Settings link above.

If you'd prefer to create the Azure services manually before running the installer, the minimum service requirements and configuration details are below. Ensure all of your Azure services settings match these values, then run the installer and select the resources you created. All Azure services can be scaled further as your needs grow.

All Azure services must be in the same Azure subscription. All services except the Translator must be in the same resource group, which you'll select during installation. They do not need to be in the same region.

<details>

<summary>Azure SQL Database</summary>

If a setting is not specified here, use the default value in the Azure portal.

**When creating the database, ensure:**

* Set the Azure **Subscription** and **Resource group** to the same as your other Reporting Hub services are in.
* If you are creating a new database for your Reporting Hub, we recommend the following settings:
  * Set **Want to use SQL elastic pool?** to **No**.
  * Set **Workload environment** to **Production**.
  * Set **Compute + storage** **service tier** to **Basic (DTU-based purchasing model) 5 DTUs**.
  * Set **Backup storage redundancy** to **Geo-redundant backup storage**.
* The database must be empty.

</details>

<details>

<summary>Azure SQL Server</summary>

If a setting is not specified here, use the default value in the Azure portal.

**When creating the Server, ensure:**

* Set the Azure **Subscription** and **Resource group** to the same as your other Reporting Hub services are in.
* Set **Authentication method** to **use both SQL and Microsoft Entra authentication**.
* Set the **Microsoft Entra admin**. We recommend setting it to the user that will perform the Reporting Hub installation.
* Set the **Server Admin login** and **password**, or, if using an existing server, ensure you have the credentials. You can validate that your credentials are correct by logging in through the Query Editor on the Azure portal.
* Under **Networking**, enable **Allow Azure services and resources to access this server**.

Once the server has been created, under **Security** > **Networking**,&#x20;

* Ensure **Public network access** is set to **Selected networks**.

</details>

<details>

<summary>Azure App Service</summary>

If a setting is not specified here, use the default value in the Azure portal.

**When creating the App Service, ensure:**

* **App Type** should be **Web App**.
* Set **Subscription** and **Resource group** to the resource group that your other Reporting Hub services are in.
* Uncheck "**Secure unique default hostname on**".
* Set **Publishing model** to **Code**.
* Set **Runtime stack** to **.NET 10 (LTS)**.
* Set **Operating system** to **Windows**.
* Set **Pricing plan** to **Basic B1** or **Standard S1**.
* We recommend setting **Enable Application Insights** to **No**.

Once the App Service has been created, under **Settings** > **Configuration**:&#x20;

* Set **Platform** to **64 Bit**.
* Set **SCM Basic Auth Publishing** to **On**.
* Set **FTP Basic Auth Publishing** to **On.**
* Set **FTP state** to **All allowed**.

</details>

<details>

<summary>Azure Translator</summary>

* Set **Pricing tier** to **Free F0**.

</details>


# Request a Quota Increase in Azure

How to request an Azure quota increase when the installer flags that a required resource isn't available in your selected region.

When you select your **resource group region** in the Reporting Hub installer, the installer checks your Azure subscription's quota for each required resource — **App Service**, **SQL Database**, and **Fabric Capacity** — in that region. Any resource without quota in the selected region is marked with a red icon, and you can't continue until you either:

* Confirm that you will create that resource in a different region (by selecting **Will select region on creation**), **or**
* Request a quota increase for the resource in your preferred region and then retry the installation.

The path you take depends on the resource:

* **App Service** quota requests are submitted through the **My Quotas** blade.
* **SQL Database** and **Fabric Capacity** quota requests are submitted through a Microsoft support ticket.

Microsoft typically processes support tickets within a few business days.

#### When to Request a Quota Increase

Request a quota increase if:

* You need all Reporting Hub resources to live in a specific region for compliance, latency, or data residency reasons.
* The flagged resource is the only one without quota in your preferred region and you don't want to split deployment across regions.

If you are flexible on region for the flagged resource, the simpler path is to select **Will select region on creation** in the installer and choose a different region for that resource when prompted. See Installation Failures for details on multi-region deployments.

#### Minimum Quota Required

When you submit the quota request, ask for the minimum required for Reporting Hub:

| Resource            | Deployment SKU    | Quota to Request              |
| ------------------- | ----------------- | ----------------------------- |
| **App Service**     | **S1** (Standard) | `1` unit of S1                |
| **SQL Database**    | **Basic**         | `1` vCore (via Region access) |
| **Fabric Capacity** | **F2**            | `2` Capacity Units (CU)       |

You can request a higher value if you plan to scale, but these minimums are enough to complete the installation.

### Request a Quota Increase for App Service

Use the **My Quotas** blade for App Service requests.

1. Go to the **My Quotas** blade in the Azure portal: <https://portal.azure.com/#view/Microsoft_Azure_Capacity/QuotaMenuBlade/~/myQuotas>.
2. At the top of the page, set the filters:
   1. For **Provider**, select **App Service**.
   2. For **Region**, select the region you want to deploy into.
   3. Leave **Subscription** set to the subscription you're installing Reporting Hub into.
3. In the results list, find the **S1** quota and select the pencil **Edit** icon on the right of the row.
4. In the **New quota request** field, enter `1` and select **Submit**.
5. If the request can't be approved automatically, the same form will open a Microsoft support ticket. Complete and submit it.

### Request a Quota Increase for SQL Database or Fabric Capacity

Use the **Help + support** blade for SQL Database and Fabric Capacity requests. These always go through a Microsoft support ticket.

1. Go to the **Help + support** blade in the Azure portal: <https://portal.azure.com/#view/Microsoft_Azure_Support/HelpAndSupportBlade>.

<figure><img src="/files/Hy4anc4RgEMiPZRdCAi0" alt="" width="313"><figcaption></figcaption></figure>

2. In the **Tell us about the issue** field, enter `quota` and select **Go**.
3. For **Which service are you having an issue with?**, select **Service and subscription limits (quotas)**.
4. For **Which subscription are you having an issue with?**, select the subscription you're installing Reporting Hub into.
5. For **What issue are you having?**, set **Problem type** to the service the installer flagged:
   * **SQL database** for SQL Database quota.
   * **Microsoft Fabric** for Fabric Capacity quota.
6. Select **Next**.
7. On the **Service and Subscription Limits (Quotas)** card, select **Create a support request**.

<figure><img src="/files/KzpaNn6d8UVcydHBwHOZ" alt="" width="317"><figcaption></figcaption></figure>

8. On the **Problem description** tab, set **What is your issue related to?** to **Azure services**. The **Issue type**, **Subscription**, and **Quota type** fields are pre-filled from your previous selections — confirm they're correct, then select **Next**.
9. On the **Additional details** tab, under **Request details**, select **Enter details** to open the **Quota details** panel.
10. Fill in the panel based on the resource:
    * **For SQL Database:**
      1. Set **SQL database quota type** to **Region access**.
      2. Set **Location** to the region you want to deploy into.
      3. Set **Expected Consumption** to `1` (one vCore is enough for the Basic tier — Reporting Hub uses approximately 100–125 DTU).
      4. Optionally add context in **Description** (for example, *Deploying Reporting Hub, requires SQL Database access in this region*).
      5. Select **Save and continue**.
    * **For Fabric Capacity:**
      1. Set **Location** to the region you want to deploy into.
      2. Set **QuotaBucket** to **CapacityQuota**.
      3. Set **New limit (CU)** to `2` (the F2 SKU is 2 Capacity Units, which is enough to deploy Reporting Hub). Request a higher value if you plan to scale.
      4. Select **Save and continue**.
11. Complete the remaining fields on the **Additional details** tab (advanced diagnostic information, support method, contact info), then select **Next**.
12. On the **Review + create** tab, review your request and select **Create** to submit.

{% hint style="warning" %}
Microsoft typically processes quota support tickets within a few business days. This processing time is **outside of Reporting Hub's control**. If your installation timeline is tight, consider deploying the flagged resource in an alternate region while you wait for approval.
{% endhint %}

### Return to the Installer

Once Microsoft has approved your quota request:

1. Return to the [Reporting Hub installer](https://license.thereportinghub.com/install).
2. Re-run the installation, selecting the same region you requested quota for.
3. The quota check on the **Resource Group** page should now show a green check for the resource that was previously flagged.
4. Continue through the remaining installation steps as described in [Self-Serve Guided Install](/getting-started/deployment-step-by-step/self-serve-guided-install).


# Enable Power BI Service Settings

Give the Reporting Hub permission to access Power BI

For Reporting Hub (an Entra ID app) to access Power BI content and APIs, a **Fabric or Power BI Admin** needs to enable a set of tenant admin settings and then configure each workspace you want to use.

This page has two parts:

1. [**Enable Power BI tenant admin settings**](#enable-power-bi-tenant-settings)**:** turn on the settings Reporting Hub needs.
2. [**Configure your Power BI workspaces**](#power-bi-workspace-configuration)**:** make each workspace available to Reporting Hub.

## Enable Power BI Tenant Settings

Reporting Hub needs the following tenant settings enabled:

* [x] Allow XMLA endpoints and Analyze in Excel with on-premises datasets
* [x] Embed content in apps
* [x] Allow Service principals can create workspaces, connections, and deployment pipelines&#x20;
* [x] Allow Service principals can call Fabric public APIs
* [x] Allow service principals to create and use profiles
* [x] Enable Enhance admin APIs responses with detailed metadata
* [x] Grant Permission to workspaces

All of these are in the Power BI [**Admin portal**](https://app.powerbi.com/admin-portal/tenantSettings) under **Tenant settings**.

{% hint style="info" %}
**This applies to every setting below.** You can enable each toggle for your **entire organization** or for a **specific security group**. If you choose a specific security group, you must add the Reporting Hub Service Principal security group you created in **step 8** of the installation process.
{% endhint %}

### 1. Integration Settings

**1.A. Allow XMLA endpoints and Analyze in Excel with on-premises datasets**

* In the [**Admin portal**](https://app.powerbi.com/admin-portal/tenantSettings)**,** go to **Tenant settings**
* Scroll to **Integration settings**
* Enable the **Allow XMLA endpoints and Analyze in Excel with on-premises datasets.** ([Microsoft reference](https://learn.microsoft.com/en-us/power-bi/enterprise/service-premium-connect-tools#security))

<div align="center"><figure><img src="/files/9Aw19ymt9Q2AFkhQz92E" alt="" width="361"><figcaption><p>This is usually enabled by default.</p></figcaption></figure></div>

{% hint style="warning" %}
**Note:** If you choose 'specific security group', you must add the Reporting Hub Service Principal security group you created in step 8 of the installation process.
{% endhint %}

### 2. Developer Settings

**2.A. Embed content in apps**

* Scroll to **Developer Settings**
* Enable **Embed content in apps**.

{% hint style="info" %}
**Note:** If you choose 'specific security group', you must add the Reporting Hub Service Principal security group you created in step 7 of the installation process.
{% endhint %}

<figure><img src="/files/nnAaqIs2lOmKA9qIHJL2" alt="" width="375"><figcaption><p>This is usually enabled by default.</p></figcaption></figure>

**2.B. Service principals can create workspaces, connections, and deployment pipelines**

* Scroll down to **Developer Settings**&#x20;
* Enable the **Service principals can create workspaces, connections, and deployment pipelines**.

{% hint style="info" %}
**Note:** If you choose 'specific security group', you must add the Reporting Hub Service Principal security group you created in step 8 of the installation process.
{% endhint %}

<figure><img src="/files/2GgjbY0KpTpkbHo8vKhk" alt="" width="350"><figcaption></figcaption></figure>

**2.C. Service principals can call Fabric public APIs**

* Scroll down to **Developer Settings**&#x20;
* Enable the **Service principals can call Fabric public APIs.**

{% hint style="info" %}
**Note:** If you choose 'specific security group', you must add the Reporting Hub Service Principal security group you created in step 8 of the installation process.
{% endhint %}

<figure><img src="/files/JM9oZgdIkWsJzK34TrAu" alt="" width="324"><figcaption></figcaption></figure>

**2.D. Allow service principals to create and use profiles**&#x20;

* Scroll down to **Developer Settings**
* Enable the **Allow service principals to create and use profiles.**

{% hint style="info" %}
**Note:** If you choose 'specific security group', you must add the Reporting Hub Service Principal security group you created in step 7 of the installation process.
{% endhint %}

<figure><img src="/files/cCGVh8Sweg7z9OyOa0kn" alt="" width="254"><figcaption></figcaption></figure>

### **3. Admin API Settings**

**3.A. Enable Enhance admin APIs responses with detailed metadata**&#x20;

* Scroll down to **Admin API Settings**
* Enable the **Enhance admin APIs responses with detailed metadata.**&#x20;

To learn more about the Admin API Settings, visit this [Microsoft reference.](https://learn.microsoft.com/en-us/fabric/admin/service-admin-portal-admin-api-settings#enhance-admin-apis-responses-with-detailed-metadata)

{% hint style="info" %}
**Note:** If you choose 'specific security group', you must add the Reporting Hub Service Principal security group you created in step 7 of the installation process.
{% endhint %}

<div align="center"><figure><img src="/files/FOPkpLnJM39mxLmXBJeb" alt="" width="361"><figcaption></figcaption></figure></div>

## Power BI Workspace Configuration

For each workspace you want to use in Reporting Hub, complete three steps:

* [x] [Assign your workspace to your fabric or embedded capacity](#assign-your-workspace-to-your-embedded-capacity)
* [x] [Add the Reporting Hub application to your workspace](#add-the-reporting-hub-application-to-your-workspace)
* [x] [Add the workspace to your Reporting Hub Global Tenant](#add-the-workspace-to-a-reporting-hub-tenant)

{% hint style="warning" %}
**Please note:** your personal '*My Workspace*' can not be added to the Reporting Hub.
{% endhint %}

### 1. Assign your workspace to your Embedded or Fabric Capacity

To add a Power BI workspace to a capacity, you'll need to:

1. Log in to: <https://app.powerbi.com>
2. Open the workspace you want to integrate with Reporting Hub. If this is your first time, we recommend starting with a **non-production** workspace.
3. Select **Workspace Settings**.

<figure><img src="/files/2dS112K6yVAHhCpES4H9" alt=""><figcaption></figcaption></figure>

4. Select the **Workspace Type** tab
5. Select **Edit.**
6. Select the license mode **Embedded** *or* **Fabric**.&#x20;
7. If you have more than one embedded capacity, select the one that is being managed by Reporting Hub.
8. Click **Apply**.

{% hint style="warning" %}
**If capacity is greyed out:** The capacity selection will only be visible to you if you are a [**Capacity administrator**](https://learn.microsoft.com/en-us/fabric/admin/capacity-settings?tabs=fabric-capacity#add-and-remove-admins) and the [**capacity is currently active**](https://learn.microsoft.com/en-us/fabric/enterprise/pause-resume#resume-your-capacity). If the capacity is paused, you can start it by either going to the Azure portal and starting the capacity or by signing into Reporting Hub, and the application will start the capacity automatically.
{% endhint %}

<img src="/files/kV8TGawUSqwiiyNXTbhs" alt="Note that it will say License Info instead of Premium" width="375">

### 2. Add the Reporting Hub Application to your Workspace

After assigning the capacity as the workspace license, you need to give your Reporting Hub application access to the workspace.

1. In your Reporting Hub application, navigate to **App Settings** > **App Information.**&#x20;
2. Copy the **Name** of your service principal and note the **Client ID.**

<figure><img src="/files/tg3f79sNOVjiUNEFsNn2" alt=""><figcaption></figcaption></figure>

3. Navigate back to the workspace in the [Power BI Service](https://app.powerbi.com). Ensure this is the same one from first step.
4. Select **Manage Access**&#x20;

![](/files/6l6L3Bcaezal9HlUVOkP)

5. Select **+ Add people or groups**.

![](/files/kGrrGYzTDcYPEZdesHYZ)

5. In the 'Enter name or email' field, type the **Name** that you copied from your application&#x20;
6. Select the one that shows an **AppID** under the name.&#x20;
   1. If you see multiple apps with the same name, select the one with the **AppID** that matches the **Client ID** in your app.
7. Set the permission to **Admin.**&#x20;
8. Click **Add.**

<img src="/files/IKlXmOeDrgZxbBejqExj" alt="" width="375">

{% hint style="info" %}
By using the application, workspaces are typically available in the Reporting Hub within minutes. If you choose the security group instead of the application, workspaces will take longer (hours or even next day) to become available in the Reporting Hub application.
{% endhint %}

{% hint style="danger" %}
**Service principal not showing up?** Ensure you have enabled your [Power BI Tenant settings](#enable-power-bi-tenant-admin-settings) and that your [Service principals can call Fabric public APIs](#id-2.c.-allow-service-principals-can-call-fabric-public-apis) setting is either enabled for the entire organization or that the application service principal you want to add is a member of one of the specified groups.

Sometimes copying and pasting adds an invisible character and the name may not appear. Try to type the name in, and you should see it in the list.
{% endhint %}

## Next:  Configure Reporting Hub App Settings

Now that the workspace is on your capacity and your Reporting Hub application has permission, assign the workspace to your Reporting Hub Global Tenant. We cover this in the next step.

{% content-ref url="/pages/D6QLOw6IhUgl69x7qJL6" %}
[Configure Reporting Hub App Settings](/getting-started/deployment-step-by-step/configure-reporting-hub-app-settings)
{% endcontent-ref %}


# Configure Reporting Hub App Settings

**You must be a Reporting Hub Global Admin to complete these steps.** The default Global Admin is the user who ran the installation. To grant Global Admin to additional users, go to **App Settings** > **Manage Seats**

With Power BI configured, finish your deployment inside Reporting Hub. There are three steps:

* Sync your groups
* Configure your Global Tenant settings
* Set your home page

## 1.  Sync Your Groups

{% hint style="success" %}
Security groups are used to assign permissions to tenants and content within Reporting Hub.
{% endhint %}

After installation, Reporting Hub is integrated with Entra ID (or the scheme you set in the optional step above), but it does not automatically sync your users and security groups. Sync your groups to make them available in Reporting Hub.

1. From your user profile, select **App Settings** > **Manage Groups**.
2. Select **Sync Groups**.&#x20;

This pulls all your security groups into Reporting Hub so they can be granted permissions throughout the app. For more detail, see the **Manage Groups** page in the in-app documentation.

<figure><img src="/files/b7fTvkcctIMybBgnvg9H" alt=""><figcaption></figcaption></figure>

## 2. Configure Your Global Tenant Settings

{% hint style="success" %}
**Good to know:** Your Power BI Workspaces map to your Reporting Hub tenants. You can have as many workspaces mapped to a tenant as you would like.
{% endhint %}

After installation, your Reporting Hub tenant has no user permissions and no access to your Power BI workspaces yet. Set these up from your Global Tenant settings.

1. In Reporting Hub, select your user profile, then **App Settings** > **Tenant Admin**.
2. Select **Refresh Workspaces and Capacities**.

<figure><img src="/files/Pje49wMeb0Hj5X0hPrPs" alt=""><figcaption><p>Select Refresh Workspaces &#x26; Capacities</p></figcaption></figure>

3. In the **Action** column on the table, select the **ellipses.**
4. Select **Edit.**

<figure><img src="/files/oERdjFmph8uOhWvH9t5H" alt="" width="563"><figcaption><p>Select Edit</p></figcaption></figure>

5. Fill out the Tenant Settings form and click **Save.**

<table><thead><tr><th width="206">Field</th><th width="117">Required?</th><th>Description</th></tr></thead><tbody><tr><td><strong>Tenant Administrator</strong></td><td>Yes</td><td>The user who manages this tenant. After installation, the user who ran setup is a <strong>Platform Admin</strong> with <strong>Global Permissions. Select</strong> their name from the dropdown to make them the Tenant Administrator. To add more admins, use the <strong>Manage Seats</strong> page in <strong>App Settings</strong>.</td></tr><tr><td><strong>Power BI Workspaces</strong></td><td>Yes</td><td>Select the workspace(s) you want to integrate from the dropdown. Each workspace must first be configured in Power BI.</td></tr><tr><td><strong>Parent Group</strong></td><td>Optional</td><td>The top-level security group that controls access to the tenant. Leave blank to allow your entire organization; set it to restrict access to specific security groups. Users and groups must belong to this Parent Group to access the tenant.</td></tr></tbody></table>

{% hint style="info" %}
**Don't see your workspace?** If your Power BI workspace isn’t showing up in the app, it may be due to configuration or permission issues. Head over to our Troubleshooting Guide in-app to find out how to resolve it.
{% endhint %}

<figure><img src="/files/YTCJj1FkZEYcO7Zgcq4B" alt=""><figcaption><p>Tenant Settings Form</p></figcaption></figure>

## Next: Learn to Use Reporting Hub

You're now ready to start building your app and go live. Continue to Learn to Use Reporting Hub to work through the community onboarding space, where loading content, branding, tenant planning, and setting your home page are all covered.

{% content-ref url="/pages/fmYjHXgF7pL3ZhniLF1B" %}
[Learn to Use Reporting Hub](/getting-started/deployment-step-by-step/learn-to-use-reporting-hub)
{% endcontent-ref %}


# Learn to Use Reporting Hub

With deployment and configuration complete, it's time to learn your way around Reporting Hub and start building your app. The **community onboarding space** walks you through everything, step by step, loading content, branding your app, planning tenants, adding your team, and setting your home page.

## Start in the Community Onboarding Space

After you finish configuring, your app opens on a **Getting Started** home page.&#x20;

Select **Go to Getting Started guide** to open the **Just Installed? Start Here** space in the Reporting Hub Community.

<figure><img src="/files/ebFbGBEQeaLFgK2u5voO" alt="" width="375"><figcaption><p>How the application looks right after install.</p></figcaption></figure>

The onboarding space is your step-by-step guide for everything after deployment. Work through the posts in order, and like each one to keep track of where you are:

* Book your trial kick-off call
* Configure Power BI & Global Tenant settings (video tutorial of Stage 3 & 4)
* Add your team
* Tenant planning
* Set your app branding
* …and more

## Where to Get Help

* **Community:** ask questions and share ideas in the [Reporting Hub Community](https://community.thereportinghub.com).
* **Knowledge Center:** In the app, go to **Profile Menu**, and then **Help** for full reference documentation for the platform.
* **Support:** Contact our team at <https://support.thereportinghub.com>.
* **Onboarding call:** Need hands-on help? Book an onboarding call from the Getting Started page or the community onboarding space.


# Installation Failures

Common errors you may encounter during installation

**Pre-Install Quota Check.** When you select your resource group region, the installer now checks your Azure subscription's quota for **App Service**, **SQL Database**, and **Fabric Capacity** in that region. A green check means quota is available. A red icon means there is no quota in the selected region — you can't continue until you either:

* Select **Will select region on creation** for the flagged resource (you'll be prompted to choose a different region for that resource later), or
* Request a quota increase for that resource in your preferred region, then retry. {% endhint %}

#### Troubleshooting Deployment Failures

If you reach the deployment check page and the deployment fails, complete the cleanup steps below before trying again.

In most failed deployments, **many resources are still created successfully**. In the Azure portal, you’ll typically see **all Reporting Hub resources except the one that failed**. When you rerun the installer, you can select those existing resources instead of recreating them. In the example below, everything was deployed except for the Azure SQL Server/Database

<figure><img src="/files/Na7MZzWIgNXxn7jB76S8" alt=""><figcaption></figcaption></figure>

## Clean Up Reporting Hub Entra ID Objects

A failed installation will still create Entra ID objects (an app registration and a security group). Delete those before retrying. You named these objects in step 7 of the Self-Serve Guided Install.

#### Delete the App Registration

1. In the Azure portal, go to **Microsoft Entra ID**.
2. Under **Manage**, select **App registrations**.
3. Select **All applications**.
4. Find your **Reporting Hub** app registration.
5. Select it, then select **Delete**.

#### Delete the Security Group

1. In the Azure portal, go to **Microsoft Entra ID**.
2. Under **Manage**, select **Groups**.
3. Select **All groups**.
4. Search for the security group **created during installation**.
5. Select it, then select **Delete**.

## Resource Not Available in Your Region (Quota Restriction)

The installer checks your subscription's quota for **App Service**, **SQL Database**, and **Fabric Capacity** when you select a resource group region. If a resource has no quota in that region, the installer marks it with a red icon and blocks you from continuing.

You have two options:

1. **Deploy the flagged resource in a different region.** Select the **Will select region on creation** checkbox next to the flagged resource and continue. You'll be prompted to choose a region for that resource when it's created.
2. **Request a quota increase for your preferred region.** Use this if you need all resources in the same region for compliance, latency, or data residency reasons.

{% content-ref url="/pages/RP5Mb9RFz5iB9wIimXXU" %}
[Request a Quota Increase in Azure](/getting-started/deployment-step-by-step/self-serve-guided-install/quota)
{% endcontent-ref %}

## Other Common Issues

#### Installer does not proceed after selecting a resource group

This usually means your account does not have the **Subscription Owner** role.

* If you are a Contributor, you can often proceed by selecting an existing resource group (instead of creating a new one).
* Otherwise, either:
  * activate/get the **Azure Subscription Owner** role for your account, or
  * ask an Azure admin in your organization to complete the installation.

#### Blank screen with “Microsoft login failed.”

This is typically caused by the account signing in **not having a Power BI Service account yet** (common in brand-new Azure tenants). You can double-check this by viewing the error in the URL bar. To fix this:

1. Go to [`https://app.powerbi.com`](https://app.powerbi.com/)`.`
2. Sign in with the same email used for the installer.
3. Confirm the account is successfully created/accessible, then retry the installation.

#### SQL Credentials Failing

If you are selecting an existing SQL server, the installer will prompt you to enter your SQL admin credentials. Your Entra ID credentials will not work here, you must use [SQL Authentication.](https://learn.microsoft.com/en-us/azure/azure-sql/database/logins-create-manage?view=azuresql#authentication-and-authorization)

#### The progress bar says 100%, but has not moved past that.

If this happens, then likely the installation was successful, but the installer timed out. To verify if the installation completed, navigate to the Azure App Service via the Azure Portal. On the overview page, select the default domain, and the application should start.

<figure><img src="/files/xPXqYy92DJugCatXzx2s" alt=""><figcaption></figcaption></figure>

#### Azure Kudo Services has been blocked

<figure><img src="/files/rrzWglbh5AYHXJenFCPV" alt="" width="563"><figcaption></figcaption></figure>

This typically means that the settings configuration on the Azure App Service is incorrect. If you created the resource manually, ensure that the [App Service Configuration](https://docs.thereportinghub.com/getting-started/deployment-step-by-step/self-serve-guided-install#azure-services-configuration-settings) Settings are correct.&#x20;

#### Reinstall&#x20;

Run the [Reporting Hub installer](https://license.thereportinghub.com/install) again and create all resources in the new region you selected.

## Contact Support

If none of the above cover the issue you are encountering, you can [reach out to our support team](https://support.thereportinghub.com/) to create a ticket. You’ll need to create a support account first—use the **Sign Up** link in the top right corner of the Support page.\
\
Where it says Application URL, input **Installation Error**.


# Azure Marketplace Install

Install the Reporting Hub through the Azure Marketplace

You can install the Reporting Hub using [our installer](https://license.thereportinghub.com/install/installer), or through the Azure marketplace. This guide will explain the differences between the two installation methods and describe the requirements and steps for installing through Azure Marketplace.

## Comparison with Installer Methods

Regardless of which installation method you choose, the latest version of the Reporting Hub will be installed in your environment.

The biggest differences when you install via the Azure Marketplace versus using our installer are:

* There is no free trial period when you install through the Azure Marketplace.&#x20;
* Can only deploy a Power BI Embedded capacity (instead of a Fabric capacity). We will update our offering to include the Fabric capacity option soon.
* Translator service isn't deployed automatically through Azure Marketplace and requires manual configuration.

## Installing through the Azure Marketplace

### Create a Managed Identity

Before you install through the Azure Marketplace, you must create a Managed Identity. You must also assign the necessary permissions to the Managed Identity. The Managed Identity requires contributor access on the Azure subscription where the app will be installed, as well as Application Administrator and Groups Administrator permissions in the directory.

#### Create a User Assigned Managed Identity

1. In the Azure portal, select **Managed Identities**.
2. Select **Create**.
3. Select the appropriate **Subscription** in which you'd like to deploy all of the Reporting Hub app resources.
4. Select the **Resource Group** you'd like to use, or create a new one.
5. Select a **Region** you'd like to deploy your Azure resources in.&#x20;
6. **Name** your managed identity.
7. Select **Review + Create** to review your settings and select **Create**.&#x20;

#### Give Managed Identity the Necessary Entra ID Permissions

This allows the managed identity to create the app registration required for your Reporting Hub application.

1. In the Azure portal, select **Microsoft Entra ID**.&#x20;
2. Under **Manage**, select **Roles and administrators**.&#x20;
3. From the list of roles, select:&#x20;
   1. **Application Administrator**
   2. **Groups Administrator**
4. Select **Add assignments**.&#x20;
5. Search for the name of the managed identity and select it. Select **Add**.

#### Give Managed Identity the Necessary Permissions on Azure Subscription

This allows the managed identity to create the necessary resources on the Azure subscription.

1. In the Azure portal, select **Subscriptions**.
2. Select the relevant subscription.
3. Select **Access control (IAM)** on the left menu.
4. On the top menu select **Add** and then **Add role assignment**.
5. Select the **Privileged administrator roles** tab and then select **Contributor**. Select **Next**.
6. Leave the **Assign access to** field set to **User, group, or service principal**. Click **Select members**.
7. Search for the Managed Identity you created, select it, and hit the **Select** button below.
8. Select **Review + assign** at the bottom of the screen.

### Deploy through the Azure Marketplace

{% embed url="<https://azuremarketplace.microsoft.com/marketplace/apps/shiftanalyticsinc1663186612563.reportinghub_prod_003?tab=overview>" %}

1. Open the link above in a new tab to view our Azure Marketplace offering and select **Get It Now**.
2. Sign in to the Microsoft Azure Marketplace.
3. Choose a [Plan](https://thereportinghub.com/pricing) and select **Create**.&#x20;

   1. You must select a paid plan; there is no free trial period when you install through the Azure Marketplace. If you'd like to install with a free trial period, [use our installer](/getting-started/deployment-step-by-step/self-serve-guided-install) instead.&#x20;

   <figure><img src="/files/I8osnd8mabcrhu9d0PbV" alt=""><figcaption></figcaption></figure>
4. Select your Azure **Subscription** and the **Resource group** that your Managed Identity is in.
5. Select the **Region** that you'd like to deploy all of the Reporting Hub resources in.
6. Enter a name for the **Managed Application** and the **Managed Resource Group**. Select **Next**.

   <figure><img src="/files/og8o6YKPmeIqiFybiK8a" alt=""><figcaption></figcaption></figure>
7. On the App Service Setup page, you will be presented the option to either use an existing App Service or add a new App Service.&#x20;

   * To use an existing App Service, check the **Use existing App Service** box and select an App Service and deployment slot. Select **Next**.
   * To create a new App Service, enter an **App Service Name**. Select a **Tier**; you can scale up your App Services plan later. Select **Next**.&#x20;

   <figure><img src="/files/lmHNWIjOatYsABEJZDXp" alt=""><figcaption></figcaption></figure>
8. On the Database Setup page, you can either use an existing Azure SQL Server or create a new one.&#x20;

   * To use an existing server, select the **Use existing Azure SQL Server** box and select it from the list.
   * To create a new server, enter a **SQL Server Name**.

   Enter a **Database Name**. Select **Next**.

   <figure><img src="/files/hRX8YT1NGbvRslVSEm8Z" alt=""><figcaption></figcaption></figure>
9. On the Database Credentials page, enter a **SQL Server Username**, **Password**, and enter the **Password** again to confirm. If you are creating a new SQL server, the server admin credentials will be what you enter here. If you are using an existing server, please ensure that you are entering the correct server admin credentials here — the installer is unable to validate them here. Select **Next**.

   <figure><img src="/files/4XV6K1naQ9iBZDyGuF8z" alt=""><figcaption></figcaption></figure>
10. On the Embedded Capacity Setup page, you have the option of creating a new Embedded Capacity or using an existing one.

    * To use an existing capacity, check the **Use existing capacity** box and select a capacity from the list. Only capacities in the resource group you have selected will be available to select. Select **Next**.
    * To create a new capacity, enter a **Capacity Name** and an **Administrator Email** for the user you'd like to set as the capacity's administrator. You can add additional capacity administrators later on. Select **Next**.

    <figure><img src="/files/lxf3bPRGQu0D667yRMN5" alt=""><figcaption></figcaption></figure>
11. On the Identity page, select **Add** and then select the user assigned managed identity you created earlier. Select **Next**.

    <figure><img src="/files/K6vK2pOCovSoyjIKK9z9" alt=""><figcaption></figcaption></figure>
12. Review your terms. You can read The Reporting Hub's Terms of Use and Privacy Policy, as well as the Azure Marketplace Terms, and select **I agree to the terms and conditions above**. Select **Create**.&#x20;

    <figure><img src="/files/8vVUDR4jxIEESmwJItux" alt=""><figcaption></figcaption></figure>
13. The wizard will deploy your Reporting Hub app in your Azure environment. After deployment, navigate to your App Service and select the domain from the Overview page to launch your Reporting Hub.

After deployment, enable Power BI Settings and configure your Reporting Hub app settings. Additionally, if you want to translate your Reporting Hub into a language other than English, [link a Translator service to your Reporting Hub app](#add-a-translator-optional). &#x20;

### Enable Power BI Service Settings

Follow the instructions linked below.

{% content-ref url="/pages/ZTurS8WKwsHYDkpOORRM" %}
[Enable Power BI Service Settings](/getting-started/deployment-step-by-step/enable-power-bi-service-settings)
{% endcontent-ref %}

### Configure Reporting Hub App Settings

Follow the instructions linked below.

{% content-ref url="/pages/D6QLOw6IhUgl69x7qJL6" %}
[Configure Reporting Hub App Settings](/getting-started/deployment-step-by-step/configure-reporting-hub-app-settings)
{% endcontent-ref %}

### Add a Translator (Optional)

#### Create a Translator service in Azure&#x20;

1. In the Azure portal, search for **Translators** in the top search bar and select **Translators**.&#x20;
2. Select **Create**.&#x20;
3. Choose a **Subscription** and **Resource group**; it doesn't have to be in the same subscription or resource group that your Web App is in.&#x20;
4. Choose a **Region** that is the same as or close to the region your Web App is in.&#x20;
5. Enter a **Name** for your Translator.&#x20;
6. Set the **Pricing tier** as **Free**.&#x20;

   <figure><img src="/files/AJff06ABqtD1CMJ07MU4" alt=""><figcaption></figcaption></figure>
7. On the **Network** tab, select **All networks, including the internet, can access this resource**.&#x20;

   <figure><img src="/files/ukmlhDbdbqN2zVKdVFDI" alt=""><figcaption></figcaption></figure>
8. Select **Review + Create** and then **Create** to create the resource.&#x20;

#### Add Translator Keys to Reporting Hub App

After the Translator has been created, you need to add its keys to your Reporting Hub app's settings.

1. Select the Translator in your Azure portal.
2. Under **Resource Management**, select **Keys and Endpoint**.&#x20;

   <figure><img src="/files/Q0pGTTnwgJanmz0iK4NG" alt=""><figcaption></figcaption></figure>
3. Select **Show Keys** and copy KEY 1, KEY 2 and Location/Region to a notes app, like notepad.&#x20;

   <figure><img src="/files/pT3sxzySKYVak7h3Gcps" alt=""><figcaption></figcaption></figure>
4. Navigate to your **App Services** list; you can use the search bar at the top of the page. &#x20;

   <figure><img src="/files/CA7c0qAjd6c11X8Ob1mG" alt=""><figcaption></figcaption></figure>
5. From the list of App Services, select your Reporting Hub app service.&#x20;
   1. If you deployed your Reporting Hub app to a specific slot on your app service, then expand the **Deployment** menu in the left menu pane; select **Deployment slots**; and select the desired slot.&#x20;
6. On the left menu, expand the **Development Tools** menu and select **Advanced Tools**.&#x20;

   <figure><img src="/files/EIA6Y7aORy1OxpLqDZRP" alt=""><figcaption></figcaption></figure>
7. Select **Go ->** and Kudu tools will open in a new tab.&#x20;

   <figure><img src="/files/Mwt2s4WvxyN76x1uj4cG" alt=""><figcaption></figcaption></figure>
8. On the Kudu page, in the top menu, select **Tools** and **Zip Push Deploy**.&#x20;

   <figure><img src="/files/n4wO44w29KRSoMu9z0RN" alt=""><figcaption></figcaption></figure>
9. Scroll down in the file list and find `appsettings.json`. Select the **pencil icon** next to it.&#x20;

   <figure><img src="/files/EAg2PuL9raxRqipoPno3" alt=""><figcaption></figcaption></figure>
10. In the text editor on the page, find **"key1"** and replace the text beside it with the KEY1 value from step 3. Ensure the key value is inside quotation marks.&#x20;

    <figure><img src="/files/uEk3L9G4r0h2HP0kWgvV" alt=""><figcaption></figcaption></figure>
11. Find **"key2"** and replace the text beside it with the KEY2 value from step 3.&#x20;
12. Find **"location"** and replace the text beside it with the translator region you copied in step 3.&#x20;
13. Select **Save**.


# Reporting Hub Architecture

The Reporting Hub is an Azure-based application that is installed and deployed within your Azure environment. It integrates with your existing Microsoft tenant and communicates with Power BI Embedded via Microsoft APIs. The following Azure services are required to run the Reporting Hub:

1. Power BI Embedded or Fabric Capacity
2. Azure App Service
3. Azure SQL Database

Below is a diagram highlighting the high level architecture.

![](/files/eJ82Ocd1ceEEGnuDhy9a)

## How it works with Power BI

The Reporting Hub communicates with Power BI Embedded via Microsoft APIs. The below list includes the key communication areas:

* Connects to authorized Power BI Workspaces, Reports and Dashboards
* Applies Row-level-security (RLS) based on authenticated user
* Built-in capacity optimizer manages Power BI Embedded Capacity availability based on usage
* Connections to data sources are established through Power BI&#x20;
* Works with all Power BI Embedded, Fabric and Power BI Premium Microsoft licenses

{% hint style="success" %}
**Important:** Your data is **NEVER** accessed by, made available to, or, stored within the Reporting Hub web application. &#x20;
{% endhint %}

## Component Functions

### Microsoft Entra ID (B2B)

Microsoft Entra ID (formerly called Azure Active Directory or AAD) is the default authentication method for the Reporting Hub. Entra ID B2B allows you to add guest users (outside of your tenant). Users and Groups are managed in Entra ID and are used to provide access to navigation options, reports and row-level security.&#x20;

{% hint style="info" %}
**Note:** The Reporting Hub also supports Okta, OpenID Connect & Auth0 authentication schemes. See App Settings > Authentication Admin in your [in-app help](/tutorials-and-references/in-app-help) for more information.
{% endhint %}

### Power BI Embedded

Power BI Embedded is the Microsoft license required to share Power BI content with un-licensed users. Your embedded capacity is applied to the Power BI workspaces you wish to make available to the Reporting Hub.&#x20;

### Azure App Service

The Reporting Hub is a stand-alone application instance installed directly within your Azure environment. An Azure App Service is required to 'host' the application.&#x20;

### Azure SQL Database

All the Reporting Hub application configuration data (logos, themes, navigation, report security, and audit logs) are stored in this Azure SQL Database.&#x20;

### Reporting Hub License Manager

The Reporting Hub license manager is a separate application that runs within the Reporting Hub Azure environment. Your locally deployed Reporting Hub application instance periodically communicates with the license manager to validate subscription.

{% hint style="info" %}
**Important:** Communication between your application and the Reporting Hub license manager is a simple ping via strongly encrypted keys. No data of any kind is stored with the license manager.  The Reporting Hub license manager can request and read the locally deployed Reporting Hub instance application log files by default.  Read access to the application log files can be disabled and blocked by the customer if desired.&#x20;
{% endhint %}

<details>

<summary>Log files made available to Reporting Hub license manager </summary>

The Reporting Hub application log has 2 types of entries:

**Information:**

* Entries to show if the app can access the database --> checkdatabase information Returned: found org
* Entries to show CapacityManager function
* Entries to show number of active tenants
* CapacityManagement function when started

&#x20;                                       when CapacityManagement/CapacityResume&#x20;

&#x20;                                       when CapacityManagement/Pause

&#x20;                                       when CapacityManagment/Refresh Schedule

* Entries for Cache Management

&#x20;                            When it skipped and when it cleared Memory

* Entries for Checking Ad App Secret

&#x20;                            when was the app secrete checked /updated

**Exceptions:**

* It records all the Exceptions and the functions involved along with debug information the application gets from Microsoft or the Reporting Hub App itself

&#x20;

</details>

#### Related Article

For more information on the Azure services required please reference:

{% content-ref url="/pages/YU5Ppdk3phslmIwIOwhE" %}
[Required Azure Services](/getting-started/required-azure-services)
{% endcontent-ref %}


# AaaS end-to-end Architecture

How to deliver Analytics-as-a-Service with the Reporting Hub & Microsoft Fabric

## What is Analytics-as-a-Service (AaaS)?&#x20;

The concept of Analytics-as-a-Service (AaaS) is similar to a Software-as-a-Service (SaaS) business model, however the main 'service' that you're providing is analytics-based content, typically in the form of pre-configured data visualization, models and insights.  Effectively, an AaaS business solution is still delivered as SaaS, so the two concepts are linked.

## How to Accelerate Delivery of your AaaS Solution

Historically, delivering an AaaS solution was a significant technical undertaking involving complex processes and disparate tools and workloads.  With the introduction and release of Microsoft Fabric much of the data framework can now be streamlined and delivered more efficiently and cost effectively.  The Reporting Hub then provides a no-code turn-key delivery platform for Power BI analytics content, with the complete solution contained within a Customer's Azure environment.

Microsoft Fabric together with the Reporting Hub provides a complete end-to-end framework to accelerate the delivery of an AaaS solution. &#x20;

## AaaS Solution Framework&#x20;

The Reporting Hub together with Microsoft Fabric presents a seamless solution framework to deliver AaaS.  The AaaS solution accelerator framework as shown below highlights how the Reporting Hub can be viewed as an extension of your data workloads for the purposes of delivering analytics content at scale to end-users via a plug'n'play front-end application.  &#x20;

<figure><img src="/files/mrYb2sTiAc8MuU5ctQGS" alt=""><figcaption></figcaption></figure>

## AaaS Solution Architecture Example

The below solution architecture diagram is a basic example that is meant to highlight the overall workflow, tools and workloads to deliver an AaaS solution.  The specific attributes of the architecture could vary in many different ways, but the overall process is generally consistent. &#x20;

<figure><img src="/files/NuJtmTAzOfmGZ5Qp979s" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**Please Note:**  Although the above solution architecture depicts Microsoft Fabric as the underlying recommended data framework, other data frameworks and tools can also be used.  The Reporting Hub is designed for seamless integration with Power BI using Power BI Embedded APIs, however the underlying data infrastructure can vary.
{% endhint %}

## Related Microsoft Content

{% embed url="<https://learn.microsoft.com/en-us/fabric/get-started/microsoft-fabric-overview>" %}

{% embed url="<https://learn.microsoft.com/en-us/fabric/onelake/onelake-overview>" %}

{% embed url="<https://learn.microsoft.com/en-us/power-bi/developer/embedded/embedded-analytics-power-bi>" %}


# Security & Trust Center

Your resource center for all security, privacy and compliance information related to a Reporting Hub deployment

The Reporting Hub takes security, privacy and compliance seriously and our goal is to ensure you have all the information you need to ensure your success.&#x20;

## Reporting Hub Architecture

The Reporting Hub is a fully deployed web-app that is installed within the customers Azure environment.  Our [Reporting Hub Architecture](/concepts/reporting-hub-architecture) documentation provides all the relevant information you will need to understand how the application works within Azure.   &#x20;

The Reporting Hub's policies can be found on our website here:

{% embed url="<https://thereportinghub.com/policies>" %}

## Security & Compliance Considerations for Reporting Hub’s Solution Deployment

At Reporting Hub, we understand the importance of security and compliance in enterprise environments. However, one of the challenges we consistently face is that many security questionnaires and audits operate under the assumption that we function as a traditional SaaS provider. Our solution is fundamentally different in its deployment model, which directly impacts how various security standards apply to us.

#### **Fully Deployed in Customer Environments – No Data Access**

Unlike most SaaS offerings that host customer data on their own infrastructure, Reporting Hub’s solution is fully deployed within the customer’s environment. This means:

* We **do not store, process, or transmit customer data** on our infrastructure.
* Customers maintain **full control over their data security and compliance** within their own Azure cloud.&#x20;
* Reporting Hub has **no access to customer data**, ensuring data sovereignty and eliminating risks associated with third-party data storage.

#### **Why Traditional Security Audits & Certifications May Not Apply**

Many security frameworks such as **SOC 2 and ISO 27001** are designed to assess a company’s ability to protect customer data **within its own infrastructure**. Since Reporting Hub does not store or have access to customer data, many of the security controls and requirements outlined in these frameworks do not apply to our solution.

For example:

* **SOC 2** focuses on the security, availability, and confidentiality of customer data stored within a vendor's systems. Since we do not handle customer data, these controls are not relevant.
* **ISO 27001** pertains to information security management systems (ISMS) for data stored within an organization’s environment. However, since our software runs **entirely within the customer’s environment**, their own security policies govern data protection, not ours.

#### **How We Address Security Concerns**

Although traditional SaaS compliance frameworks do not apply, we take security seriously and provide the following assurances:

1. **Secure Code Development** – We follow industry best practices for secure software development, including regular code reviews, static/dynamic security testing, and adherence to OWASP standards.
2. **Minimal Attack Surface** – Since our solution does not rely on an external multi-tenant infrastructure, the attack surface is limited to what is already protected within the customer’s own security framework.
3. **Customer-Managed Access Control** – Since the solution is deployed within the customer’s environment, they retain full control over **identity and access management (IAM), authentication, and authorization policies**.
4. **No Data Retention Risks** – Unlike SaaS providers that must implement data protection mechanisms, Reporting Hub does not retain any customer data, eliminating concerns around data leaks or breaches.
5. **Compliance Alignment** – While traditional SaaS security frameworks do not apply, we align with **customer security policies** and ensure our software integrates seamlessly into existing security models.

#### **Custom Security Assessments**

Since security audits are often based on predefined templates for SaaS solutions, we recommend that customers work with us to tailor security assessments that are **relevant to our specific deployment model**. Instead of evaluating Reporting Hub as a data processor or cloud service provider, security reviews should focus on:

* **Software security practices** (e.g., secure development lifecycle, vulnerability management).
* **Integration security** (e.g., how the solution interacts with customer data sources securely).
* **Deployment security** (e.g., customer-configurable security controls within their environment).

While SOC 2, ISO 27001, and similar frameworks are important for traditional SaaS vendors, they are **not applicable to Reporting Hub** due to our deployment model. Instead, our security posture is built around **secure software development, integration security, and customer-controlled deployment**.

We are happy to work with customers to address any security concerns within the **context of their specific environment** and ensure that Reporting Hub meets their security and compliance requirements without unnecessary overhead from frameworks that do not apply.

## Reporting  Hub Security & Compliance Overview Document

{% file src="/files/LWV9m5IZxnkSuwZgqeFD" %}

## Reporting Hub Application Security Controls

<details>

<summary>Reporting Hub Compliance - Audit Logging</summary>

The Reporting Hub includes built-in logging functionality with both application and audit logs. The logs are captured and stored in the Azure App Service within the client's environment. Below is a list of the information captured in the logs.

**Application Logging**

* Any exceptions/errors encountered by the application
* Information messages for Power BI embedded capacity operations and scheduled tasks in the Reporting Hub

**Audit Logging**

* Content page security changes - which security groups and/or individuals are assigned to a content page. This includes if a group/individual's RLS role changes.
* AD group - when sync groups is initiated, groups that were added/removed are tracked
* Application roles - when a user or user group's application role changes (user, content admin, application admin)
* Changes to Tenant admin - any changes made to on a tenant admin page (parent group, assigned workspaces, authentication scheme, billing, etc.)
* Power BI settings - any changes made to the capacity, time out settings, Power BI gateway\*, scheduled refresh
* Scheduled tasks - add, modify, delete scheduled tasks
* Subscription changes\* - when customer upgrades/downgrades their license

</details>

## Microsoft Security, Privacy & Compliance Documentation

The Reporting Hub is an Azure web application, built within the Azure framework using Microsoft APIs. The benefit of using the Reporting Hub is that you are taking advantage of all the built-in Microsoft security. The below list has been compiled to simplify the sourcing of this relevant information:

Microsoft Trust Center:

{% embed url="<https://www.microsoft.com/en-us/trust-center/product-overview>" %}

Microsoft Data Protection & Privacy:

{% embed url="<https://www.microsoft.com/en-ca/trust-center/privacy>" fullWidth="false" %}

Azure App Service Security:

{% embed url="<https://learn.microsoft.com/en-us/azure/app-service/overview-security>" %}

Power BI Security

{% embed url="<https://learn.microsoft.com/en-ca/power-bi/enterprise/service-admin-power-bi-security>" %}

{% embed url="<https://learn.microsoft.com/en-us/power-bi/guidance/whitepaper-powerbi-security>" %}

Data Protection in Power BI

{% embed url="<https://learn.microsoft.com/en-ca/power-bi/enterprise/service-security-data-protection-overview>" %}

Power Platform Compliance and Data Privacy

{% embed url="<https://learn.microsoft.com/en-us/power-platform/admin/wp-compliance-data-privacy>" %}

Power BI Governance & Compliance - Metadata Scanning

{% embed url="<https://learn.microsoft.com/en-ca/power-bi/enterprise/service-admin-metadata-scanning>" %}

Power BI Embedded Security:

{% embed url="<https://learn.microsoft.com/en-us/power-bi/developer/embedded/embedded-row-level-security>" %}

Embedded Analytics Access Tokens:

{% embed url="<https://learn.microsoft.com/en-ca/power-bi/developer/embedded/embed-tokens?tabs=embed-for-customers>" %}

Service Principal Profiles Security:

{% embed url="<https://learn.microsoft.com/en-ca/power-bi/developer/embedded/embed-multi-tenancy>" %}

Microsoft Compliance Offerings:

{% embed url="<https://learn.microsoft.com/en-us/compliance/regulatory/offering-home>" %}


# In-App Help

Our full library of step-by-step tutorials, troubleshooting guides, and reference materials is now accessible through the **Help** section in your **admin profile menu**.

* **Where to find it**: In the application, go to your profile (top-right corner) and select **Help**
* **Requirements**: You’ll need to be on **Version 7.0.0.2** or later to access this feature

This change ensures that admins have fast, secure access to the most up-to-date support content, right inside Reporting Hub.

<figure><img src="/files/vMRmRlDnIdOvSa4r8QTg" alt="" width="121"><figcaption><p>Click to enlarge</p></figcaption></figure>

You should see the help section that looks like this.

<figure><img src="/files/WgLnmQCKCI70rnMczAxa" alt=""><figcaption></figcaption></figure>

### I do not see the tutorials when accessing via my app.

If you are unable to see the in-app help center, it is likely due to your browser settings blocking third party cookies. See below how to enable for Chrome and Edge

#### Google Chrome

1. In the URL bar, paste in `chrome://settings/cookies`
2. Either allow third party cookies or add your Reporting Hub application URL to the allowed sites list

<figure><img src="/files/7KMxw98OtJYeDOfaWnKj" alt=""><figcaption></figcaption></figure>

#### Microsoft Edge

1. In the URL bar, paste in `edge://settings/privacy/cookies`
2. Either disable block third-party cookies or add your Reporting Hub application URL to the allowed sites list making sure to check **Include third-party cookies on this site**.

<figure><img src="/files/hoYqN1y4i1sZQ5pKh1G9" alt=""><figcaption></figcaption></figure>


# Overview of BI Genius

## What is  BI Genius?

**BI Genius** is a white-label AI agent building platform that allows your organization to deliver secure, no-code, conversational analytics experiences powered by your existing Power BI Semantic Models and enterprise data sources deployed entirely within your environment.

BI Genius is an AI-powered assistant that transforms the way end users interact with your data. Rather than relying solely on dashboards or pre-built reports, users can simply ask questions in natural language and receive instant, accurate responses, whether as summaries or visuals.

BI Genius is designed for flexibility, control, and enterprise-grade deployment. It runs entirely within your Azure environment, giving you full control over data access, governance, and customization.

<figure><img src="/files/4CZ6N7GYqJzOKYPOwtLC" alt=""><figcaption></figcaption></figure>

## How it Works

At its core, BI Genius connects to your Power BI Semantic Models and optionally other knowledge sources. It uses Azure OpenAI and natural language understanding to interpret user queries and generate responses grounded in your data.

The result: A fully branded, AI-driven analytics experience your users can trust.

### Key Components

| Component                               | Description                                                            |
| --------------------------------------- | ---------------------------------------------------------------------- |
| **White-Label Agent**                   | Fully customizable branding and experience for your users.             |
| **Power BI Semantic Model Integration** | Connects directly to your existing data models.                        |
| **Azure-Hosted Deployment**             | Deployed securely in your environment for full control and compliance. |
| **Multi-Source Support**                | Extendable to other datasets, or external documentation.               |
| **No-Code Configuration**               | Setup and customization requires no coding.                            |

### Why It's Different

Unlike Microsoft Copilot or other SaaS analytics assistants, BI Genius:

* **Is not tied to Microsoft Fabric licensing or workspace limitations**
* **Is not bound to Power BI’s native UI**
* **Allows full control of data sources, and security settings**
* **Can be embedded into any application or web portal**
* **Can be extended to data sources outside of Microsoft Fabric**

Whether you want to enhance your internal reporting or deliver branded AI experiences to customers, BI Genius is designed to fit seamlessly into your ecosystem.


# BI Genius Required Azure Services

Everything you need to deploy the BI Genius

BI Genius deploys two Azure services into your own Azure environment, alongside your existing Reporting Hub app.

{% hint style="info" %}
BI Genius **reuses your existing Reporting Hub Azure App Service;** no additional App Service, SQL Database, capacity, or Translator is required.
{% endhint %}

### Services BI Genius Deploys

| Service                                                                                                                                | Purpose                                                                                                                            | Recommended starting point                                                       |
| -------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- |
| **Azure Database for** [**PostgreSQL flexible server**](https://azure.microsoft.com/en-us/pricing/details/postgresql/flexible-server/) | Stores BI Genius configuration, agents, and query history.                                                                         | **Standard\_B1ms** tier, **32 GiB** storage. Scale up later in the Azure portal. |
| **Azure AI Foundry (**[**Azure OpenAI**](https://azure.microsoft.com/en-us/pricing/details/cognitive-services/openai-service/)**)**    | Hosts the AI models that power BI Genius agents. Deployed to your own tenant, so your data and inference stay in your environment. | The three default models below. Add or change models any time.                   |

### AI Models and Token Costs

Because BI Genius runs on **Azure AI Foundry in your own tenant, it does not restrict which AI models you can use.** The installer deploys a working set of models by default, and you can deploy and select any other model available in Azure AI Foundry afterward.

**Deployed by default:**

<table><thead><tr><th width="224">Model</th><th>Used for</th></tr></thead><tbody><tr><td><strong>GPT (latest)</strong></td><td>The primary chat/reasoning model behind agent answers.</td></tr><tr><td><strong>GPT mini</strong></td><td>A smaller, lower-cost model for lighter or faster requests.</td></tr><tr><td><strong>text-embedding-3-small</strong></td><td>Generates embeddings for semantic search and matching.</td></tr></tbody></table>

After installation, you can deploy additional models in Azure AI Foundry and choose which ones an agent uses from **BI Genius AI Settings**. See AI Settings to select models, and Token Limits in Azure to manage rate limits.

#### How token costs work

The models run in **your own Azure subscription**, so token usage is billed **directly by Azure at Azure OpenAI pricing** for whichever models you deploy. **Reporting Hub does not add any token charge.** Rates are pay-as-you-go and vary by model (input and output tokens are priced separately; embedding models are priced per token).

For current, per-model rates:

* [Azure OpenAI Service pricing](https://azure.microsoft.com/en-us/pricing/details/cognitive-services/openai-service/)
* [Azure pricing calculator](https://azure.microsoft.com/en-us/pricing/calculator/) — estimate cost based on your expected model and token volume.

{% hint style="info" %}
Because you own the Azure AI Foundry resource, you have full visibility and control over model choice and spend.
{% endhint %}

### Key Points

The installer automatically configures both required resources. These services deploy to your own Azure environment rather than Reporting Hub's infrastructure, **and all Azure subscription fees, including AI token usage, are the responsibility of your organization.**

Your Reporting Hub app must be version **7.7.0 or higher** to deploy BI Genius.


# BI Genius Deployment Step-by-Step

Your Reporting Hub app must be version **7.7.0 or higher** to support BI Genius. To update, open your application's Admin menu (select your profile icon), then **Help** > **Self-Serve Guided Updates**.

**BI Genius attaches to an existing Reporting Hub app and reuses its App Service**, so only two extra Azure resources are deployed:&#x20;

* **Azure Database for PostgreSQL**
* **Azure AI Foundry (Azure OpenAI)**.&#x20;

You can start deployment from the **Add BI Genius** link on the Reporting Hub installer's **Success!** page, or go to the BI Genius installer directly at any time. Both follow the steps below.

## Before You Begin

**Please review the checklist below before getting started:**

* [x] You have an active Azure Pay-as-you-go subscription.
* [x] You have [Global Admin](https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#global-administrator) and [Subscription Owner](https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal-subscription-admin) roles within your Azure subscription.
* [x] You have a Reporting Hub web app, version **7.7.0 or higher**.
* [x] You are agreeing to install the required Azure services:&#x20;
  * Azure Database for [PostgreSQL flexible server](https://azure.microsoft.com/en-us/pricing/details/postgresql/flexible-server/)
  * Azure AI Foundry ([Azure OpenAI](https://azure.microsoft.com/en-us/pricing/details/cognitive-services/openai-service/))
* [x] You agree to the following Azure services setup conditions:

{% hint style="warning" %}
**Azure Services Setup Conditions**: *Any and all Azure services are not included within your BI Genius subscription. These services are deployed to your organizations' Azure instance and reside within your Azure subscription. Any and all Azure subscription fees are the responsibility of your organization. Once deployed, any changes or ongoing administration of these services are the responsibility of your organization.*
{% endhint %}

***

<h2 align="center"><a href="https://license.thereportinghub.com/install/bigenius">Click here to start the installation</a></h2>

{% hint style="info" %}
**Need Help?** Contact our support team at [https://support.thereportinghub.com](https://support.thereportinghub.com/).  A dedicated team member will be available to assist with your deployment.&#x20;
{% endhint %}

***

## Installation Steps

The installer walks you through one page at a time. For each Azure resource, you can select an existing resource or create a new one.

{% hint style="info" %}
If you removed the Reporting Hub installer enterprise application before, you may be prompted to grant **application admin consent**. This is the same installer used for Reporting Hub, so you may have already granted it.
{% endhint %}

{% stepper %}
{% step %}

### Select your Azure Subscription

* Choose your **tenant** and the **subscription of your existing Reporting Hub app**
* Select **Install Now**.

{% hint style="warning" %}
Installing BI Genius involves a **restart of your Reporting Hub Azure App Service**. Plan for a brief interruption for your end users before you continue to **Install Now**.
{% endhint %}

<figure><img src="/files/DovE5s3rVmZmdbyfUlYC" alt="" width="375"><figcaption><p>Select your Azure Subscription</p></figcaption></figure>
{% endstep %}

{% step %}

### Select your existing Reporting Hub App Service.

* Select your **existing Reporting Hub app** and **domain**.&#x20;
* The installer confirms your app meets the minimum version. You'll see **"Reporting Hub Installation found!"** with the detected version (7.7.0 or higher). Make sure the correct application is selected
* Select **Next**.

<figure><img src="/files/LkIPXnRTKIEBNs88I3Di" alt="" width="375"><figcaption><p>Select your Reporting Hub App Service</p></figcaption></figure>
{% endstep %}

{% step %}

### Confirm your Azure Resource Group

* This field is **read-only** and shows the resource group of your Reporting Hub app. Verify it's the resource group that holds your Reporting Hub resources.
* Select **Next**.

<figure><img src="/files/86Mngg7GUxmsbGktL1vS" alt="" width="375"><figcaption><p>Verify this is the name of your Reporting Hub Resource Group</p></figcaption></figure>
{% endstep %}

{% step %}

### Select your PostgreSQL server.

* **Existing server:** select it from the dropdown, then select **Next**.
* **New server:**&#x20;
  * Select **Add New.**

    Select a **Region**.

    1. Select a **Tier:** we recommend starting with **Standard\_B1ms**.
    2. Select **Storage:** we recommend starting with **32 GiB**.
    3. Enter a **Server name** and **Database name**:
       * The **server name** can only contain lowercase letters, numbers, and hyphens, must be 3–63 characters, can't start or end with a hyphen, and must be globally unique.
       * The **database name** can only contain alphanumeric characters and hyphens, and must be 1–63 characters.
* Select **Next**.

<figure><img src="/files/upPze6Oquy5t2389I4UQ" alt="" width="375"><figcaption><p>Create a PostgreSQL Server and Database</p></figcaption></figure>
{% endstep %}

{% step %}

### Select your Azure OpenAI Service

* **Existing service:** select it from the dropdown, then select **Next**.
* **New service:**&#x20;
  * Select **Add New.**&#x20;
  * Choose a **Region.**
  * Enter an **Azure OpenAI Service Account Name**
  * Select **Next**.

<figure><img src="/files/aCluGXrhVtwzrWM8jja0" alt="" width="375"><figcaption><p>Create an Azure Foundry/OpenAI Service</p></figcaption></figure>
{% endstep %}

{% step %}

### Review the deployment checks and select Next.

The installer verifies or deploys your selected Azure resources. Once they're all deployed, select **Next**.

<figure><img src="/files/C71uG8kaFvmdV0hbHvTC" alt="" width="375"><figcaption><p>Checking Deployment</p></figcaption></figure>
{% endstep %}

{% step %}

### Launch the application

The BI Genius installation begins! This may take several minutes. The installer then runs a series of checks and starts your new BI Genius application.

Click on the URL to access the BI Genius admin page in your Reporting Hub App.

<div><figure><img src="/files/BKVWUc1wLpG1THrGR3YR" alt=""><figcaption></figcaption></figure> <figure><img src="/files/1rpXCV3s6qqgQLiihXki" alt=""><figcaption></figcaption></figure></div>
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
If there are any failures, hover over the information icon in the failed status bar and note the error message that appears. Then, contact our support team at [https://support.thereportinghub.com](https://support.thereportinghub.com/) so we can assist in the resolution.
{% endhint %}

## Next (Required): Power BI Configuration

When the app has been successfully installed, you will need to ensure that BI Genius has been granted adequate permission in your Power BI tenant and to your Power BI workspaces.

{% content-ref url="/pages/NAoSwQdnIvvf1FL2tv2S" %}
[BI Genius Enable Power BI Service Settings](/bi-genius/bi-genius-deployment-step-by-step/bi-genius-enable-power-bi-service-settings)
{% endcontent-ref %}

## Incomplete Installations

The installer provisions Azure resources incrementally during the setup process. If you exit the installation before it completes, some resources may remain active and could incur costs.&#x20;

If you stop the installer after the **Select your Azure Resource Group** step, we recommend reviewing your Azure portal to identify and delete any resources or objects the installer may have created. This includes reviewing your Entra ID for the App Registration and Security Group created in step 8.


# BI Genius Enable Power BI Service Settings

After you have installed BI Genius, you need to ensure that it has adequate permission in your Power BI tenant and access to your Power BI workspaces.

BI Genius uses the **same Entra ID app registration as Reporting Hub**, so it can already access any workspace that's integrated with Reporting Hub. You still need to confirm the tenant admin settings below (a few are specific to BI Genius), but you only need to grant workspace access again if you add a **new** workspace

## Enable Power BI Tenant Admin Settings

BI Genius uses the same Power BI tenant settings as Reporting Hub, plus two additional ones.

1. First, make sure **all of the Reporting Hub Power BI tenant settings** are enabled; see **Enable Power BI Service Settings**. If you've already deployed Reporting Hub, these are likely already on.

{% content-ref url="/pages/ZTurS8WKwsHYDkpOORRM" %}
[Enable Power BI Service Settings](/getting-started/deployment-step-by-step/enable-power-bi-service-settings)
{% endcontent-ref %}

2. Then, in the [Power BI Admin portal](https://app.powerbi.com/admin-portal/tenantSettings) under **Tenant settings**, enable these two additional settings that BI Genius requires:

* [x] Semantic model execute queries REST API
* [x] Enhance admin APIs responses with DAX and mashup expressions

For each setting,&#x20;

1. Set **Apply to** to **The entire organization** or **Specific security groups**.
2. If you scope it to specific groups, add the **Reporting Hub Service Principal security group** (the one created during your Reporting Hub installation, which BI Genius reuses)
3. Select **Apply**.

<figure><img src="/files/K86OJ07NZdxW7O1S69Nz" alt=""><figcaption><p>Example of enabling a PBI Tenant setting for a subset of the organization</p></figcaption></figure>

## Connect Your Power BI Workspace

{% hint style="success" %}
**This step is optional.** Because BI Genius uses the same app registration as Reporting Hub, it can already access any workspace that's integrated with Reporting Hub. Follow the steps below only if you want to give BI Genius access to a **new** workspace that isn't yet connected to Reporting Hub.
{% endhint %}

1. Log in to the [Power BI service](https://app.powerbi.com/).
2. On the left menu, select **Workspaces**&#x20;
3. Choose the Workspace you want BI Genius to access.
4. From the top menu, select **Manage access**.
5. Select **Add people or groups**.
6. Begin typing the name of your **Reporting Hub app registration** (the **Name your Application** value you entered on the Entra ID Application Registrations page of the Reporting Hub installer).
7. Select the option that shows an **AppID** underneath it.
8. Select **Admin.**
9. Select **Add.**

![](/files/xrz6j3OXFcw4wXSu9lHc)


# BI Genius vs. Co-Pilot for Power BI

While both **BI Genius** and **Microsoft Co-Pilot for Power BI** offer AI-powered analytics experiences, they serve very different needs when it comes to flexibility, branding, deployment, and control.

This article breaks down the key differences so you can understand where BI Genius fits—and why many organizations choose it to power their AI-driven reporting strategy.

## At a Glance: Key Differences

| Feature                         | BI Genius                                                        | Co-Pilot for Power BI                                                     |
| ------------------------------- | ---------------------------------------------------------------- | ------------------------------------------------------------------------- |
| **Deployment Model**            | Fully deployed in your own Azure environment                     | SaaS-based, Microsoft-hosted                                              |
| **White-Label Experience**      | Yes — fully customizable branding                                | No — branded as Microsoft Co-Pilot                                        |
| **Power BI License Dependency** | Not tied to Fabric or F64 capacity licensing                     | Requires Microsoft Fabric licensing                                       |
| **UI Independence**             | Can be embedded outside Power BI (e.g., web apps, portals)       | Only works within Power BI interface.  Not supported by Power BI Embedded |
| **Prompt & UX Control**         | Full control over prompt direction and instructions              | Limited configuration                                                     |
| **Data Source Flexibility**     | Extendable beyond Power BI (e.g., internal docs, online sources) | Limited to Power BI datasets and Fabric content                           |
| **Security & Compliance**       | Self-hosted for complete control over data and access            | Data processed in Microsoft’s cloud                                       |
| **Multi-Tenant Support**        | Yes — ideal for customer-facing use cases                        | No — user-based inside a single tenant                                    |

## Design Philosophy

**Co-Pilot for Power BI** is optimized for internal users working within the Microsoft ecosystem. It’s a great productivity tool for analysts or stakeholders who are already using the Power BI interface and want to explore reports or datasets conversationally.

**BI Genius**, on the other hand, is built for organizations that need:

* **External delivery** of AI-powered analytics (e.g., customers, partners)
* **Full branding control** (white-label)
* **Deployment flexibility** (web apps, portals, intranets)
* **Data sovereignty and compliance** (self-hosted)

It complements your existing Power BI investment while freeing you from Microsoft constraints or limitations.

## When to Choose BI Genius

Choose **BI Genius** if you want to:

* Provide **AI analytics access to external users** without requiring a Power BI license
* Embed a **conversational analytics experience** into your own apps, websites, or client portals
* Maintain **control over hosting, data residency, and security**
* Extend beyond Power BI to include **documentation, or custom knowledge sources**
* Differentiate your analytics offering with **a branded AI experience**


# BI Genius Architecture Overview

**BI Genius** is designed to be secure, scalable, and fully controllable, giving organizations the ability to deploy their own AI-powered analytics assistant without relying on third-party hosting or SaaS platforms.

This article outlines the **core architecture of BI Genius**, highlighting the key components, how they interact, and where the solution is deployed.

## High-Level Architecture

BI Genius follows a **modular, cloud-native architecture** built entirely on Azure. It’s composed of the following primary components:

#### 1. **AI Agent (Frontend)**

* A customizable, white-labeled web component that can be embedded into any application or portal
* Provides the user interface for natural language interactions (chat, voice, or text input)
* Sends user queries to the backend engine for interpretation and response

#### 2. **Orchestration Engine (API Layer)**

* Receives user input and routes it through the appropriate processing pipeline
* Handles conversation flow, session management, and security checks
* Applies prompt engineering logic and instructions based on your configuration

#### 3. **Data Context Engine**

* Connects to your **Power BI Semantic Models** using XMLA and DAX queries
* Optionally connects to additional sources such as internal knowledge bases, PDFs, SharePoint, or public websites
* Assembles and structures the data context to be used by the AI model

#### 4. **Azure OpenAI Integration**

* Leverages **Azure-hosted OpenAI services** for natural language understanding and generation
* Operates entirely within your Azure subscription—no data is sent to external SaaS providers
* Interacts with structured data and knowledge to generate grounded, reliable responses

#### 5. **Admin & Configuration Portal**

* Used to configure prompt behavior, data sources, branding, user access, and security settings
* Supports versioning, access controls, and environment-specific settings
* Enables non-technical users to manage and maintain the AI assistant

## Security & Deployment

**Fully Deployed in Your Azure Environment**\
All components are deployed inside your Azure subscription—ensuring full control over data, access, and compliance.

**No Customer Data Leaves Your Network**\
The entire interaction—from user prompt to AI response—occurs within your infrastructure.

**Role-Based Access Control (RBAC)**\
Fine-grained permissioning allows you to restrict features, data sources, or user types.  Power BI RLS fully supported.

## Summary

* BI Genius is **deployed entirely in your Azure environment**—you control everything.
* It’s built for **Power BI-centric analytics**, but can also ingest external content.
* You get a **branded, embeddable AI assistant** without giving up data sovereignty or flexibility.


# Understanding Query Logic in BI Genius

Built for Explainability. Designed for Trust.

BI Genius is not a black box. While it leverages powerful AI to understand and respond to user questions, every step of the process is **explainable, auditable, and grounded in your data**.

This article explains how BI Genius handles user queries, what happens behind the scenes, and how we prioritize transparency in every interaction.

## What is Query Logic?

In BI Genius, ***query logic*** refers to the step-by-step process the system follows when a user asks a question—transforming natural language into an accurate, data-driven response.

This process involves:

1. **Understanding the user’s intent**
2. **Mapping the request to your data model**
3. **Constructing a DAX, SQL query or structured explanation**
4. **Returning the result with contextual reasoning**

Every one of these steps is traceable and explainable—by design.

## The Basic Query Flow

Here’s a simplified breakdown of how BI Genius processes a query:

#### 1. **Intent Parsing (AI Layer)**

* The user types a natural language question (e.g., “How did sales perform last quarter?”).
* Azure OpenAI interprets the request, identifies relevant metrics, dimensions, and time filters.

#### 2. **Context Assembly**

* BI Genius references your Power BI Semantic Model to locate the appropriate tables, measures, and filters.
* Optional external knowledge (e.g., glossary terms, documentation) may be used to disambiguate or enrich the query.

#### 3. **Query Generation**

* BI Genius builds a **DAX query** (or narrative logic) tailored to your model.
* This query is assembled transparently—you can view and audit the logic used.

#### 4. **Execution and Response**

* The query is executed against your dataset via XMLA or REST APIs.
* The response is returned to the user—optionally with a **plain-language explanation of how the result was calculated**.

***

### 🔍 Example

**User Prompt:**

> “What were the top 5 regions by profit last year?”

**BI Genius Explanation (visible to user):**

> “I calculated this by filtering your ‘Profit’ measure by last calendar year, then sorting by region and returning the top 5 results.”

**Technical View:**

```dax
DAX Expression

TOPN(5, 
     SUMMARIZE('Sales', 'Region'[Name], "Profit", [Total Profit]), 
     [Total Profit], DESC)
```

## Why Explainability Matters

Transparency builds trust, especially when AI is involved in data interpretation. BI Genius was built with explainability in mind to ensure:

**Accuracy** — users can verify the logic used in a response

**Trust** — especially in regulated industries or critical decision workflows

**Learning** — users grow more confident in both BI Genius and the underlying data

**Compliance** — audits are supported with traceable, interpretable query steps

## Customization & Control

* You can configure whether users see **just the answer**, or the underlying **query logic breakdown**.
* **Query Audit Logs** for Admins: View historical query chains and logic trees for traceability and providing troubleshooting assistance.&#x20;


