ODM Consents
Power BI requires consents to be granted for Core Basic, Migration Basic and Migration Power BI for both source and target tenants.
- Logon to On Demand Migration (ODM)
- Select or Create a Project
- Click Tenants from the left navigation bar
- Click Edit Consents on the source tenant
- Grant consents for the following
- Core - Basic
- Migration - Basic
- Migration Power BI
- Repeat the granting of consents on the target tenant
Basic Consent
Power BI Consent
Power BI REST API Access
There are additional requirements for Power BI to assign the ODM Consents (Service Principals) to the Microsoft Power BI REST API. The first step is to create a security group so that the Service Principal can be added as a member and then this security group will be added to the Power BI REST API.
Security Group Creation
- Login to with your tenant credentials.
- Open the Microsoft Entra ID service page.
- Click Groups from the navigation panel. Then click New Group.
- In the New Group page, setup the group as described below:
- Group type = Security
- Group name = name of the group. For example, ODMPBI
- Group description = short description about the group. For example, ODM Power BI Migration.
- Under Members, click No members selected
- In the Add members list that opens, search and select Quest On Demand - Migration - Power BI. Then click Select at the bottom of the page.
- Click Create. The group is created with the Quest On Demand - Migration - Power BI service principal as a member.
Add Security Group to the Microsoft Power BI REST API
- Log into the Power BI service portal at . with your tenant credentials.
- Click the Settings icon in the top bar and then click Admin portal.
- From the navigation panel, click Tenant settings.
- Scroll down to the Developer Settings section.
- Ensure for each of the following sections, that each are enabled and the security group that was created is added as a specific security groups
- Embed content in apps
- Service principals can use Fabric APIs
- Allow service principals to create and use profiles
- Scroll down to the Admin API settings section
- Ensure for each of the following sections, that each are enabled and the security group that was created is added as a specific security groups
- Allow service principals to use read-only admin APIs
- Enhance admin APIs responses with detailed metadata
- Enhance admin APIs responses with DAX and mashup expressions
Add Security Group to workspaces in scope of migration (Source tenant only)
- For each workspace you want to migrate (Source tenant only) open the Workspace and click Manage Access
- Add the security group that was created and grant admin access
Create or Match AccountsHow to Create and Match Accounts from ODM AccountsSet Default Target Admin UserFor a Workspace migration at least one admin account is needed in the target tenant for a migrated workspace to be visible and for allowing administration such as sharing permissions.
The default target admin account is available under Configure Project to handle this scenario and add the default admin user when there is no account matching between a source admin and target admin on the ODM Accounts section.