How to Access Power BI Embedded APIs from an External B2C Tenant App
Question details
The user needs to know how an application registered in an external Microsoft Entra B2C tenant can authenticate and access Power BI Embedded APIs hosted in a separate corporate B2B tenant.
- Product
- Power BI Embedded
- Device & OS
- not provided
- Scenario
- Setting up cross-tenant authentication for a custom application to embed Power BI reports via API.
- Observed behavior
- The user is evaluating the feasibility and required architecture for cross-tenant API access, app permissions, and authentication flows.
Ensure you have global administrator or privileged role administrator permissions in both the Microsoft Entra B2C tenant and the target corporate B2B tenant where Power BI is hosted.
Review Cross-Tenant Configuration and App Registration
Verify the app registration, tenant consent, and service principal configurations across both Azure tenants to allow secure API access.
Implementing cross-tenant authentication requires careful configuration of service principals and API permissions to ensure the external application can communicate with Power BI.
In the Microsoft Entra B2C tenant, register your application and configure the authentication flow to support the necessary user identities.
In the corporate B2B tenant, set up a service principal (App-only authentication) or grant admin consent for the cross-tenant application to access the Power BI Service APIs.
Navigate to the Power BI Admin portal and ensure that the service principal or registered app is added as an Admin or Member to the workspace containing the reports to be embedded.
Ensure that the Power BI workspace is assigned to a dedicated Premium or Embedded capacity to properly support embedding for external users.
Consult the Microsoft Fabric Community for Specialized Architecture
Since cross-tenant B2C to B2B authentication flows can be highly complex, engaging with Microsoft Developer experts is recommended to validate your architecture.
Try WPS Office for Your Documentation and Data Analysis Needs
While configuring complex Azure architectures like Power BI cross-tenant authentication requires Microsoft services, you can rely on WPS Office for planning, documenting, and presenting your architecture designs. WPS Office is a lightweight, fully-featured suite that is highly compatible with Microsoft Word, Excel, and PowerPoint.
- 1. Download WPS Office: Visit the official WPS Office website and download the installer for your operating system.
- 2. Install and Launch: Follow the on-screen instructions to install the suite and open WPS Writer, Spreadsheet, or Presentation.
- 3. Start Documenting: Create or open your existing Microsoft Office files to start planning your app registrations and API integration processes.

Frequently Asked Questions
Can I use the 'User-owns-data' embedding approach across different tenants?
Cross-tenant 'User-owns-data' scenarios are generally not natively supported without complex Azure AD B2B collaboration setups. The 'App-owns-data' (Service Principal) approach is strongly recommended for embedding Power BI content in an external app.
Does the service principal need a Power BI Pro license?
No, a service principal does not require a Power BI Pro license. However, the workspace where the content resides must be backed by a Power BI Premium or Embedded capacity.
Why am I getting an unauthorized error when calling the Power BI Embedded API?
Unauthorized errors typically occur if the service principal has not been granted explicit access to the Power BI workspace, or if the 'Allow service principals to use Power BI APIs' tenant setting is disabled in the Power BI Admin portal.
How do I enable Service Principals in Power BI?
Go to the Power BI Admin portal, navigate to Tenant settings, scroll down to Developer settings, and enable 'Allow service principals to use Power BI APIs'. It is recommended to restrict this permission to specific security groups for safety.




