Azure Active Directory
As with other Microsoft Azure services, Power BI relies on Azure Active Directory (AAD) to authenticate and authorize users. Therefore, even if Power BI is the only service being utilized, organizations can leverage AAD’s rich set of identity management and governance features, such as conditional access policies, multi-factor authentication (MFA), and business-to-business collaboration.
For example, a conditional access policy can be defined within the Azure portal that blocks access to Power BI based on the user’s network location, or that requires MFA given the location and the security group of the user. Instructions for creating conditional access policies are covered in the Conditional access policies section later in this chapter.
Additionally, organizations can invite external users as guest users within their AAD tenant to allow for seamless distribution of Power BI content to external parties, such as suppliers or customers....