Embedded Power BI Analytics, Multi-Tenant and White-Labeled

Embedding is plumbing; orchestration is the product. Whether Reporting Hub is your customer-facing application or sits inside the one you already have, you get the same governed layer — tenant isolation, per-tenant assignment, admin-configured agents, and AI insights that never leave your Azure environment.

Delivery modes

Your application, or ours

Embedded analytics does not require you to already have somewhere to embed it. Reporting Hub delivers governed Power BI to external users two ways, and the platform underneath is identical in both.

  Reporting Hub as your platform Embedded in your application
What your customer opens A branded analytics platform at your own domain Analytics inside the product they already use
Right when Reporting is the product, or you have no customer-facing app You already have a product customers log into
Branding Your logo, colours, domain, navigation and per-tenant themes Inherits your application’s shell
Sign-in Customers sign in to your platform Customers are already signed in to your app
Typical fit Consulting and services firms, enterprises, internal-to-external programmes SaaS products and vertical platforms
Availability Included on every tier Growth and Enterprise+; add-on on Core and Launch
Tenant isolation, RLS, versioning, BI Genius, audit Identical Identical

The difference is only where your customer arrives. Everything after that — which tenant they resolve to, which reports they can open, what BI Genius is allowed to tell them, what gets written to the audit trail — is the same orchestration layer doing the same work.

You are not choosing permanently, either. Firms commonly run both: a branded platform for clients who have no system of their own, and an embedded experience for the ones who want reporting inside a product they already own.

Embedded delivery

What ships with embedded delivery

Everything needed to put governed Power BI and AI inside your own application, without per-user licensing.

Embed Within Your Existing Application

Power BI Embedded under the hood, orchestration on top — your app, your brand, each customer’s data scoped correctly from the first render.

Multi-Tenant by Design

Dynamic dataset binding and per-tenant access mean one deployment serves every customer — isolated, governed, and consistent.

Governed AI in Your Product

BI Genius surfaces explainable AI insights inside your app, bounded by the scope you configure per tenant — a sellable AI tier, not a liability.

No Per-User Licensing

Unlimited external users on flat tiers. No Power BI seats for your customers, and no F64 — BI Genius runs on the Embedded or Fabric capacity you already have.

Per-Tenant Assignment

A report reaches a customer only once an admin has assigned it to that tenant, so what each audience can open is settled in configuration rather than by hand.

Enterprise SSO

Microsoft Entra ID, Okta, and Auth0 support for seamless sign-in from your application, with role-based access behind it.

The gap

Power BI Embedded renders. It doesn’t govern.

Power BI Embedded is a rendering capability, and a good one — Reporting Hub uses it in both delivery modes. It puts a report on a screen. Everything that turns a rendered report into something you can hand a customer is left for you to build.

What delivery actually needs Power BI Embedded alone With Reporting Hub
A report rendered for an external user Included Same engine, underneath
Somewhere for that user to arrive You build the application A branded platform, or your own app
Each customer sees only their own data You build it Per-tenant isolation, by default
Which reports each audience can open You build it Assigned per tenant by an admin
Customer sign-in You build it Entra ID, Okta, Auth0
Licensing for external users Capacity you size and pay for Unlimited users on a flat tier
AI insight, scoped per customer Not included BI Genius, configured per tenant
Approval before AI reaches a customer Not included Set by an admin, before exposure
A record of what was delivered, to whom You build it Audit trail included

None of that is a criticism of Power BI Embedded. It is the right rendering layer, which is why it sits underneath ours. The gap is that rendering is where it stops — and if you do not already have an application, rendering is not even the first problem you have.

Cost

Flat tiers, not per-seat and not capacity

Two licensing models make customer-facing analytics expensive, and most teams hit one before they hit a technical limit. Per-user licensing charges you for every customer who opens a report. Capacity licensing asks you to size and pay for a SKU before you know your load.

Reporting Hub does neither. Every tier includes unlimited external users, because your customers authenticate against your platform or your application rather than against Power BI. Cost tracks the infrastructure you need, not how successful the product becomes.

Tier Per month Branded platform Embed in your app
Core $199 Included Add-on
Launch $399 Included Add-on
Growth $699 Included Included
Enterprise+ $999 Included Included

No customer needs a Power BI seat at any tier, however many of them there are. Compare plans, or see how teams package analytics into a billable tier.

The Microsoft cost that stays yours

Reporting Hub runs on a Power BI capacity inside your own Azure subscription — either a Power BI Embedded capacity (A or EM SKU) or a Fabric capacity (F SKU). One of the two is required. Microsoft bills it to your Azure subscription directly, and it sits alongside your Reporting Hub tier rather than inside it.

What you do not need is an F64. F64 is the point at which Power BI stops charging per viewer, and it is the number most teams are quoted — around $5,000 a month, and $10,000+ at F128. BI Genius runs against your existing semantic models on whichever capacity you already have, so adding a governed AI tier does not force a capacity upgrade.

And because a capacity bills for compute whether or not anyone is signed in, Reporting Hub includes a Fabric/Embedded Capacity Manager that pauses it when idle. Evenings, weekends and holidays are most of the week.

Multi-tenancy

One deployment. Every customer. Isolated by design.

Serving many customers from one Power BI environment is where most external analytics programmes break. There are two ways to do it, and only one of them survives contact with the tenth customer.

The obvious way
A workspace and a copy per customer

Ten customers means ten copies of the same logic. Every change is ten edits, every edit is a chance to miss one, and the copies have already begun to drift apart.

Reporting Hub
One definition, bound at render

Dynamic dataset binding attaches a single report to the right customer's semantic model at the moment it loads. One change reaches every tenant, and no copy exists to drift.

What happens when a customer opens a report

Identical whether they arrived at your branded platform or your own application.

  1. The customer signs in — to your platform, or to your application. Never to Power BI.
  2. Their identity is passed to Reporting Hub.
  3. Reporting Hub resolves which tenant they belong to and binds the report to that tenant's semantic model.
  4. Your existing Power BI row-level security applies on top, scoping what they see within that model.
  5. If they ask BI Genius a question, it answers inside the scope an admin configured for that tenant — and nowhere outside it.
  6. What was delivered, to whom, and when is written to the audit trail.

None of those steps requires a copy of the report, a Power BI licence for the customer, or a change to the semantic model your analysts already maintain.

Implementation

From install to first customer

Reporting Hub deploys into your own Azure environment through a Microsoft-validated guided installer. There is no data migration step, because nothing moves.

Install
Into your Azure tenant

The guided installer provisions Reporting Hub and its Azure services inside your own environment. Most teams are running in about ten minutes.

Connect
What you already have

Point Reporting Hub at your existing workspaces and semantic models. Nothing is rebuilt, migrated or re-modelled.

Define tenants
Who sees what

Map which customer sees which content, and theme each tenant to match the brand they expect.

Choose arrival
Portal, embed, or both

Brand the platform and point it at your own domain, embed it into your existing application, or do both for different customers. Sign-in runs on Entra ID, Okta or Auth0.

Configure BI Genius
Scope before exposure

Set each tenant’s agent scope — which sources it can reach and what it may answer — before any customer can use it.

Go live
Domain or release

Send customers to your domain, or ship the embed with your next release.

Steps two through five are configuration, not engineering. The alternative — building the platform itself, plus tenant isolation, AI governance, audit logging and identity integration — is the twelve-to-eighteen-month project this page opened with.

Questions

Embedded Analytics FAQs

We don’t have an application to embed into. Can we still use this?

Yes — and this is the more common starting point. Reporting Hub is a complete multi-tenant analytics platform in its own right: your logo, your colours, your domain, per-tenant themes and navigation. Your customers sign in to it directly. The branded platform is included on every tier; embedding into an application you already own is the additional option, not the baseline.

How is this different from using Power BI Embedded directly?

Embedding is one technical capability — it gives you an iframe, not a system. Building the rest yourself means multi-tenant access control, AI governance, audit logging, and identity integration: a 12-to-18-month engineering project before your first customer sees a chart. Reporting Hub ships that layer on day one.

Do we need Microsoft Fabric?

No — but you do need a capacity. Reporting Hub runs on either a Power BI Embedded capacity (A or EM SKU) or a Fabric capacity (F SKU), deployed into your own Azure subscription and billed there by Microsoft. What you do not need is an F64, the tier at which Power BI stops charging per viewer, because BI Genius works against the semantic models you already have. Here is exactly where Fabric and Copilot fit — and where they don’t.

Which tier includes embedding?

Embedding into your own application is included on Growth and Enterprise+ plans, and available as an add-on on Core and Launch. The white-labeled portal experience is included on every tier. Compare plans.

Do our customers need Power BI licenses?

No. External users are unlimited on every tier and authenticate against your application — not against Power BI. No per-seat fees at any customer count.

Can we start with the branded platform and embed later?

Yes. It is the same deployment, the same tenants and the same governance either way — changing how customers arrive does not mean rebuilding what they arrive at. Embedding is included on Growth and Enterprise+ and available as an add-on on Core and Launch, so it is a plan change rather than a project.

Can we keep our existing reports and semantic models?

Yes — that is the point of the design. Reporting Hub sits after Power BI and orchestrates what it produces. Your datasets, semantic models and reports are used as they are. Nothing is rebuilt, re-modelled or migrated, and your analysts keep working the way they already do.

How do our customers sign in?

Through your branded platform or your own application, using Microsoft Entra ID, Okta or Auth0. Customers never see a Power BI sign-in and never need a Power BI account. Role-based access and your existing row-level security decide what each of them can see once they are through.

Does AI inference leave our Azure environment?

No. BI Genius runs inside your own Azure tenant along with the rest of the platform. Prompts and data are not sent to an external service, there is no third-party hosting layer, and there is no data egress — AI inference included.

Can different customers get different AI capabilities?

Yes. BI Genius agents are configured per tenant, so what an agent can reach and what it may answer is set separately for each customer before that customer can use it. That is also what makes a premium AI tier possible: you can sell it to some tenants and not others.

What happens when we update a report?

Because every tenant is bound to one report definition rather than a copy, an update reaches all of them at once. Reports are assigned per tenant, so a change reaches an audience when you assign it, rather than drifting into some tenants and not others.
Book a Demo