Activating Backup for Power BI (text version)

Before Power BI workspaces can be backed up, three separate places need to agree on who's allowed to do it: the Nexetic Backup Portal, the Microsoft Entra admin center, and the Microsoft Fabric admin portal. Setup moves back and forth between them — two ID values get copied from one place to another along the way.

 

Required access

One Global Administrator can complete every phase below.

See which role each phase needs

To split the work across people, each phase only needs:

  • Phase 1: Global Administrator
  • Phase 2: Groups Administrator or User Administrator
  • Phase 4: Fabric Administrator or Power Platform Administrator
  • Phase 5 (Grant access): Admin of that workspace — or Fabric Administrator/Global Administrator for any workspace

These are Microsoft-side roles. Completing any step also requires Nexetic Backup Portal access — automatic for Global Administrators and Privileged Role Administrators, otherwise granted separately by your Nexetic admin.



Connecting your tenant for Power BI backup


Phase 1 · Create the backup application (Nexetic Backup Portal)

Creates the backup service's own identity in your Microsoft tenant and grants it the Microsoft Graph permissions it needs, so the other two systems have something to recognize and trust later.

  1. Sign in to the Nexetic Backup Portal. Select the application switcher (top-left corner) → Power BI, then select the Settings gear (top-right).
  2. Select Admin consentGrant admin consent. Sign in as a Global Administrator and select Accept. This provisions the backup application's identity (its service principal) in your tenant — the step is complete when Backup application provisioned appears.
  3. Select Access group. Next to the displayed Service principal Object ID, select Copy to copy that value to your clipboard — you'll need it in the next phase.

     

Phase 2 · Create the access group (Microsoft Entra admin center)

Fabric doesn't grant access to individual applications directly — it grants access to a security group. This phase creates that group and adds the backup application to it as a direct member.

  1. Sign in to the Microsoft Entra admin center. Select Entra IDGroupsAll groupsNew group.
  2. On the New Group page, enter:
    • Group type: Security
    • Group name: a clear name, such as Power BI backup service principals
    • Group description: optional, e.g. Allows the backup application to access Power BI and Fabric APIs
    • Microsoft Entra roles can be assigned to the group: No
    • Membership type: Assigned. 
    • Leave Owners and Members empty for now, then select Create.
  3. Once the group appears under All groups, open it and confirm that Group type is Security and Membership type is Assigned.
  4. Open the group → MembersAdd members. Find the backup application using the Object ID you copied in Phase 1 and select Select. It must be a direct member of the group, not added through another group.
  5. On the group's Overview or Properties page, copy the group's Object ID — not the tenant ID or application ID.

     

Phase 3 · Link the access group (Nexetic Backup Portal)

Tells the backup portal which security group to trust, then checks that the backup application really is a member of it.

  1. Back in the Nexetic Backup Portal, return to Access group (same Settings page as Phase 1) and paste the group's Object ID into Security group Object ID. Select Save and verify. Once Access group shows a check mark, move on to Phase 4.

     

Phase 4 · Allow the group in Fabric (Microsoft Fabric admin portal)

Two tenant-wide switches control whether any service account — including the backup application — is allowed to call the admin and public APIs backup depends on. Both need to be turned on for the group you just created.

  1. In Microsoft Fabric (app.fabric.microsoft.com), select the Settings gear → Admin portalTenant settings. For each of the following, select Specific security groups, add the group from Phase 2, and select Apply:
  • Admin API settings → Service principals can access read-only admin APIs
  • Developer settings → Service principals can call Fabric public APIs

 

Phase 5 · Confirm and start backup (Nexetic Backup Portal)

Confirms the Fabric settings were applied, marks the tenant as fully connected, then turns on the recurring backup schedule and loads the workspaces to protect.

  1. Back in the Nexetic Backup Portal, return to Fabric tenant settings (the third connection step, on the same Settings page as Phases 1 and 3), check the confirmation box, and select Save confirmation. All three connection steps should now show a check mark, and the page should read "Tenant ready."  
  2. Important

    Nexetic cannot automatically verify that these two tenant settings were turned on. Double-check both are enabled — if they're missed, backup will not run, even though setup will otherwise look complete.

  3. Under Scheduled backup, select Enable backup.
  4. Select View workspacesSync workspaces to load the tenant's Power BI workspaces.
  5. For each workspace showing Missing under Access, select Grant access and complete the authorization.
  6. Select Run backup to start the first backup.

Good to know: the "Access group" and "Fabric tenant settings" steps on the Settings page stay locked until the step before them is complete — if a step looks disabled, finish the one above it first.

How you'll know it worked: track the backup's progress under Task Manager. Setup is complete once Fabric tenant settings shows Tenant ready and Scheduled backup shows Enabled (both in Settings), each workspace shows Granted under Access (in Workspaces), and a date appears under Last successful backup on the Dashboard.



Keep coverage up to date (Nexetic Backup Portal)

Your Power BI tenant keeps changing after setup — new workspaces get created, and access is sometimes granted outside this flow. Two habits keep backup coverage current as your platform grows.

  • If a workspace's access was granted manually (outside this flow), select Verify access next to it.
  • Select Sync workspaces again whenever new Power BI workspaces are created, so they're picked up for backup.

 

Was this article helpful?
0 out of 0 found this helpful

Articles in this section