Available on Enterprise plan.
Authentication flow
The NTLM authentication can be used with Power BI Desktop or with Power BI Service and the on-premises data gateway.Power BI Desktop
Initiated by Power BI Desktop, NTLM authentication works as follows:- Power BI Desktop is launched under a specific user account via the
runascommand. - Power BI Desktop performs an NTLM challenge-response authentication and passes the credentials of that account to the Cube Cloud deployment.
- The Cube Cloud deployment verifies the credentials.
cube user:
Power BI Service
Initiated by Power BI Service, NTLM authentication works as follows:- The gateway is configured with a master user account.
- When users interact with a Power BI report in Power BI Service, their user principal name (UPN) is passed to the gateway.
- The gateway performs an NTLM challenge-response authentication and passes the the credentials of the master user account to the Cube Cloud deployment. It also passes the UPN of the interacting user.
- The Cube Cloud deployment verifies the credentials and changes the user name to the UPN of the interacting user.
Configuration
Using NTLM authentication requires configuring the deployment to verify the credentials. To use NTLM authentication with Power BI Service, you also need to install the on-premises data gateway first.Installing the gateway
You need to have the on-premises data gateway installed on a Windows Server machine. It should be configured to authenticate with a master user account. It can be a local user on the machine or a domain user. Its credentials must match the XMLA service account configured in Cube — the user name must match exactly, including the format and letter case (e.g.,svc-account@example.com).
The Windows machine running the gateway should be joined to the corporate Active
Directory or Entra ID where your business users have their accounts. The service account running
the gateway needs minimal permissions but must exist in that same directory.
Verifying the credentials
NTLM connections are verified against the XMLA service account credentials set on the Settings → Power BI page of your deployment. They are stored in theCUBE_XMLA_API_USER and CUBE_XMLA_API_PASSWORD environment variables and default to
the deployment’s SQL API credentials.
All NTLM connections are validated against this single shared password — per-user
passwords are not supported with NTLM. Users other than the service account must exist
as Cube users. A mismatch fails with
Authentication failed due to invalid username or password.
Cube changes the session user to the UPN of the interacting user only if the connection
authenticated as the XMLA service account. The UPN must resolve to a Cube user — see
provisioning users with SCIM. The can_switch_sql_user
configuration option can be used to customize this
check.