Forum Discussion
Cloud App security and guest users
Hi there,
We're just working on enabling access for some external users to access our Power BI content. We've got that working fine with test users, and they can be invited or added to an Access Package and get access as you'd expect. To be ultra secure, we wanted to use Cloud App Security to really limit what the B2B guest users can do, so we've used conditional access app control to implement that.
Unfortunately when a guest user now attempts to access content on our tenant (via things that work for non-MCAS'd users like an email link generated by Power BI, by an app link generated by one of our users or just by visiting app.powerbi.com/ctid=<tenantid>), they get thrown back to their own organisations Power BI home page. The usual MCAS message appears and even Azure Terms of use and MFA setup popup and work properly, but a few redirects later and they just get redirected straight back to app.powerbi.com.
I've also tried this on 2 completely clean tenants which just have the bog standard app control policy applied and it does the same thing: MCAS kicks in, redirects a few times and dumps you back to your home tenants Power BI portal.
It's almost as if MCAS is stripping out the tenant ID from the URL when it shouldnt be. Nothing that I've been able to find in the documentation says this isnt a supported feature. Is this a bug or just unsupported for now?
Thanks!
1 Reply
- AnonymousNot applicable
Hi DavidCousinsT ,
Not very clear, have you checked this document about the Considerations and limitations about using Microsoft Cloud App Security controls in Power BI.
Best Regards,
Jay