Power BI includes a powerful feature called Publish to Web, which allows users to share interactive reports publicly without requiring viewers to sign in. While this tool simplifies access, it can also create security risks if misused. In this guide, you’ll learn what “Publish to Web” does, how Microsoft updated it for better governance, and how to manage access responsibly.
What Does “Publish to Web” Do?
Power BI’s “Publish to Web” lets users create an iframe embed code that displays a report on a webpage. Anyone who visits the page can interact with the report, even if they don’t have a Power BI account.
Users often embed these reports into blog posts, internal pages, or marketing sites. Because this method removes any authentication requirements, organizations must take extra care not to expose sensitive data.
Real-World Example
Microsoft showcases its financials on the Investor Relations page using this feature. Since public companies in the U.S. must disclose investor data, this use of “Publish to Web” helps meet that regulatory requirement in a user-friendly format.
What’s Changed Recently?
Until recently, Power BI allowed all users to generate embed codes by default. As a result, some organizations unknowingly published sensitive data. To strengthen data protection, Microsoft adjusted this default behavior.
Key Updates
- Power BI now blocks new embed code generation by default.
- Existing embed codes still work, so teams don’t lose access to already published reports.
- Even Power BI admins must receive explicit permission to create new codes unless their accounts belong to an allowed group.
This change gives organizations better control over public data sharing.
How to Enable “Publish to Web” for Specific Teams
You can still let approved users publish reports by configuring settings in the Admin Portal.
How to Do It:
- Go to the Power BI Admin Portal.
- Click on Tenant Settings.
- Find the Publish to Web section.
- Select Allow existing and new embed codes.
- Restrict access to specific security groups instead of the entire organization.
By assigning access to only trusted users, such as data leads or content teams, you reduce the risk of accidental data leaks.
How to Monitor and Manage Embed Codes
Ongoing management ensures your organization maintains control over shared content.
For Individual Users
- Open Power BI.
- Click the gear icon and choose Manage Embed Codes.
- View your published codes and remove any that are outdated or no longer needed.
For Admins
- Access the Admin Portal.
- Go to Embed Codes.
- Review all published codes, who created them, and which workspace they belong to.
- Revoke access or delete codes if necessary.
In one case, a company believed no one used “Publish to Web.” After checking the portal, they found dozens of active reports. Clearly, regular reviews are essential.
Best Practices for Using “Publish to Web”
To use this feature safely and effectively:
- Avoid sharing sensitive information, such as HR data, customer records, or internal financials.
- Use it for public-facing content like investor dashboards, press kits, or promotional analytics.
- Assign publishing rights to small, trusted groups through the Admin Portal.
- Review embed codes regularly to ensure compliance with your organization’s data policies.
- Educate your teams on the appropriate use of the feature.
When your organization follows these steps, you minimize risks while making the most of Power BI’s capabilities.
Final Thoughts
“Publish to Web” in Power BI simplifies public reporting and opens new opportunities for engagement. With Microsoft’s recent changes, you now have more control over how your organization uses this feature. By managing access carefully and reviewing reports consistently, you can share insights without compromising data security.
Are you using “Publish to Web”? Did you know about these recent updates? Share your experience in the comments below.
Want to improve your Power BI skills?
Explore Data Bear’s Power BI Training for expert-led instruction tailored to your reporting needs.







