Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Register now to learn Fabric in free live sessions led by the best Microsoft experts. From Apr 16 to May 9, in English and Spanish.

Reply
mjfulke
Employee
Employee

More information on encryption methods used by the Enterprise Gateway

Hello,  

 

I need to provide more detailed information on how the enterprise gateway securely transmits data over servicebus.  Before the security team will approve use of the Enterprise Gateway we need more about the methods and protocols used on the non-standard ports

 

Information provided at https://powerbi.microsoft.com/en-us/documentation/powerbi-gateway-enterprise/#ports is good but they need to know specifically what is being used to encrypt communication over 9350-9354 and more details about AMQP over 5671-5672 (is it using Kerberos and SSL). The more detail the better...   Thank you

4 REPLIES 4
Greg_Deckler
Super User
Super User

Oh, one other thing, and I believe it is on port 9350 but may have that specific port wrong, but if you see data going to Brazil over that port, that is likely telemetry data and you can turn that off when you configure the gateway.


@ me in replies or I'll lose your thread!!!
Instead of a Kudo, please vote for this idea
Become an expert!: Enterprise DNA
External Tools: MSHGQM
YouTube Channel!: Microsoft Hates Greg
Latest book!:
The Definitive Guide to Power Query (M)

DAX is easy, CALCULATE makes DAX hard...

Thanks for your reply.

Greg_Deckler
Super User
Super User

Here are a few things to consider looking at:

 

  1. Reference link to the trust center article. It is a listing of ISO, HIPAA and other security/privacy certifications of Power BI by independent auditors: https://powerbi.microsoft.com/en-us/blog/power-bi-added-to-microsoft-trust-center/
  2. Power BI Security article with the link to whitepaper: https://powerbi.microsoft.com/en-us/documentation/powerbi-admin-power-bi-security/
  3. Local Enterprise Gateway service communicates with Power BI Service via secure connection to a designated range of IP addresses.  The Gateway creates outbound connection to Azure Service Bus and there are no inbound ports.  You can find more details here: https://powerbi.microsoft.com/en-us/documentation/powerbi-gateway-enterprise/#Ports
  4. I know that the Power BI team is available for deep dives on the Enterprise Gateway, you might try contacting Sergei Gundorov, sergeig@microsoft.com, and ask if you could set one up. 

@ me in replies or I'll lose your thread!!!
Instead of a Kudo, please vote for this idea
Become an expert!: Enterprise DNA
External Tools: MSHGQM
YouTube Channel!: Microsoft Hates Greg
Latest book!:
The Definitive Guide to Power Query (M)

DAX is easy, CALCULATE makes DAX hard...

One other tidbit of information, and this is specific to iOS but perhaps similar encryption methods are used by the gateway, for the iOS app,

 

  • Local cache of security tokens are encrypted by ADAL and OS (Keychain in particular).
  • Local cache of other stuff is encrypted as long as Intune enforces overall drive encryption.

@ me in replies or I'll lose your thread!!!
Instead of a Kudo, please vote for this idea
Become an expert!: Enterprise DNA
External Tools: MSHGQM
YouTube Channel!: Microsoft Hates Greg
Latest book!:
The Definitive Guide to Power Query (M)

DAX is easy, CALCULATE makes DAX hard...

Helpful resources

Announcements
Microsoft Fabric Learn Together

Microsoft Fabric Learn Together

Covering the world! 9:00-10:30 AM Sydney, 4:00-5:30 PM CET (Paris/Berlin), 7:00-8:30 PM Mexico City

PBI_APRIL_CAROUSEL1

Power BI Monthly Update - April 2024

Check out the April 2024 Power BI update to learn about new features.

April Fabric Community Update

Fabric Community Update - April 2024

Find out what's new and trending in the Fabric Community.

Top Solution Authors
Top Kudoed Authors