Microsoft Certified: Power BI Data Analyst AssociateDeploy and maintain assetsMedium

A data analyst has created a Power BI dataset and report that uses a web API as its data source. The web API requires an API key for authentication. The analyst needs to ensure that the API key is securely stored and used when the dataset refreshes in the Power BI service. Where should the API key be configured?

  1. ADirectly in the M query within Power BI Desktop.
  2. BIn the dataset settings in the Power BI service, under Data source credentials.
  3. CAs a parameter in Power Query Editor and then stored in the Power BI service.
  4. DAs an environment variable on the Power BI Gateway server.
Show answer & explanation

Correct answer: B. In the dataset settings in the Power BI service, under Data source credentials.

For cloud data sources requiring credentials like API keys, Power BI service securely stores these under the Data source credentials section within the dataset settings. This ensures the key is not embedded in the PBIX file and is managed centrally.

Why the other options are wrong

  • A. Embedding the API key directly in the M query is insecure as it becomes part of the PBIX file and potentially visible.
  • C. While parameters can be used for dynamic values, the API key itself should be stored as a credential, not just a parameter, for security.
  • D. An on-premises data gateway is not used for cloud data sources like web APIs, so environment variables on a gateway server are irrelevant here.

Power BI Cloud Data Source Credentials

Power BI allows secure storage of credentials, such as API keys or usernames/passwords, for cloud data sources directly within the dataset settings in the Power BI service.

  • Stored securely in Power BI service
  • Not embedded in PBIX files
  • Managed per dataset

Memory trick: Keep your cloud keys safe in the service's vault.

More Deploy and maintain assets questions