<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prevent end-user from uploading malicious file types in Report Server</title>
    <link>https://community.fabric.microsoft.com/t5/Report-Server/Prevent-end-user-from-uploading-malicious-file-types/m-p/550081#M8600</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="33561" data-lia-user-login="Jon-Heide" class="lia-mention lia-mention-user"&gt;Jon-Heide&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Yes, this is whitelisted under the&amp;nbsp;TrustedFileFormat property, editable through SQL Management Studio when you connect to the PBIRS instance.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;BR /&gt;This setting does not prevent user from downloading/uploading malicious file types&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/sql/reporting-services/tools/server-properties-advanced-page-reporting-services?view=sql-server-2017" target="_blank"&gt;https://docs.microsoft.com/en-us/sql/reporting-services/tools/server-properties-advanced-page-reporting-services?view=sql-server-2017&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;TrustedFileFormat&lt;/STRONG&gt;&amp;nbsp;Set all the external file formats that open within the browser under the Reporting Services portal site. &lt;U&gt;External file formats not listed prompts to download the option in the browser. &lt;/U&gt;The default values are jpg, jpeg, jpe, wav, bmp, pdf, img, gif, json, mp4, web, png.&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Oct 2018 16:53:20 GMT</pubDate>
    <dc:creator>ynt</dc:creator>
    <dc:date>2018-10-23T16:53:20Z</dc:date>
    <item>
      <title>Prevent end-user from uploading malicious file types</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Prevent-end-user-from-uploading-malicious-file-types/m-p/545182#M8508</link>
      <description>&lt;P&gt;We recently performed penetration testing and&amp;nbsp;found several vulnerabilities including the issue with unrestricted file upload that pose significant risk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a configuration in Power BI Report Server to &lt;SPAN&gt;use a whitelist method&lt;/SPAN&gt;&amp;nbsp;to prevent end-user from uploading malicious file type like .exe, .py, etc.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2018 01:25:20 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Prevent-end-user-from-uploading-malicious-file-types/m-p/545182#M8508</guid>
      <dc:creator>ynt</dc:creator>
      <dc:date>2018-10-18T01:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent end-user from uploading malicious file types</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Prevent-end-user-from-uploading-malicious-file-types/m-p/549044#M8578</link>
      <description>&lt;P&gt;Yes, this is whitelisted under the&amp;nbsp;TrustedFileFormat property, editable through SQL Management Studio when you connect to the PBIRS instance.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 21:23:48 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Prevent-end-user-from-uploading-malicious-file-types/m-p/549044#M8578</guid>
      <dc:creator>Jon-Heide</dc:creator>
      <dc:date>2018-10-22T21:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent end-user from uploading malicious file types</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Prevent-end-user-from-uploading-malicious-file-types/m-p/549045#M8579</link>
      <description>&lt;P&gt;You can also use server permissions to disallow users from uploading content in general.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 21:26:11 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Prevent-end-user-from-uploading-malicious-file-types/m-p/549045#M8579</guid>
      <dc:creator>Jon-Heide</dc:creator>
      <dc:date>2018-10-22T21:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent end-user from uploading malicious file types</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Prevent-end-user-from-uploading-malicious-file-types/m-p/550081#M8600</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="33561" data-lia-user-login="Jon-Heide" class="lia-mention lia-mention-user"&gt;Jon-Heide&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Yes, this is whitelisted under the&amp;nbsp;TrustedFileFormat property, editable through SQL Management Studio when you connect to the PBIRS instance.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;BR /&gt;This setting does not prevent user from downloading/uploading malicious file types&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/sql/reporting-services/tools/server-properties-advanced-page-reporting-services?view=sql-server-2017" target="_blank"&gt;https://docs.microsoft.com/en-us/sql/reporting-services/tools/server-properties-advanced-page-reporting-services?view=sql-server-2017&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;TrustedFileFormat&lt;/STRONG&gt;&amp;nbsp;Set all the external file formats that open within the browser under the Reporting Services portal site. &lt;U&gt;External file formats not listed prompts to download the option in the browser. &lt;/U&gt;The default values are jpg, jpeg, jpe, wav, bmp, pdf, img, gif, json, mp4, web, png.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 16:53:20 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Prevent-end-user-from-uploading-malicious-file-types/m-p/550081#M8600</guid>
      <dc:creator>ynt</dc:creator>
      <dc:date>2018-10-23T16:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent end-user from uploading malicious file types</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Prevent-end-user-from-uploading-malicious-file-types/m-p/550082#M8601</link>
      <description>&lt;P&gt;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="33561" data-lia-user-login="Jon-Heide" class="lia-mention lia-mention-user"&gt;Jon-Heide&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="33561" data-lia-user-login="Jon-Heide" class="lia-mention lia-mention-user"&gt;Jon-Heide&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;You can also use server permissions to disallow users from uploading content in general.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;BR /&gt;Can you please point me to this particular setting?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 16:52:50 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Prevent-end-user-from-uploading-malicious-file-types/m-p/550082#M8601</guid>
      <dc:creator>ynt</dc:creator>
      <dc:date>2018-10-23T16:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent end-user from uploading malicious file types</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Prevent-end-user-from-uploading-malicious-file-types/m-p/550127#M8602</link>
      <description>&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/sql/reporting-services/security/granting-permissions-on-a-native-mode-report-server?view=sql-server-2017&amp;nbsp;" target="_blank"&gt;https://docs.microsoft.com/en-us/sql/reporting-services/security/granting-permissions-on-a-native-mode-report-server?view=sql-server-2017&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 17:56:38 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Prevent-end-user-from-uploading-malicious-file-types/m-p/550127#M8602</guid>
      <dc:creator>Jon-Heide</dc:creator>
      <dc:date>2018-10-23T17:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent end-user from uploading malicious file types</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/Prevent-end-user-from-uploading-malicious-file-types/m-p/550328#M8603</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="33561" data-lia-user-login="Jon-Heide" class="lia-mention lia-mention-user"&gt;Jon-Heide&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/sql/reporting-services/security/granting-permissions-on-a-native-mode-report-server?view=sql-server-2017&amp;nbsp;" target="_blank"&gt;https://docs.microsoft.com/en-us/sql/reporting-services/security/granting-permissions-on-a-native-mode-report-server?view=sql-server-2017&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;For our use case, we can't disable the upload feature. We need to be able to whitelist certain file types that can be uploaded to PBI Report Server.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 22:07:15 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/Prevent-end-user-from-uploading-malicious-file-types/m-p/550328#M8603</guid>
      <dc:creator>ynt</dc:creator>
      <dc:date>2018-10-23T22:07:15Z</dc:date>
    </item>
  </channel>
</rss>

