rmalone
8 years agoNew Member
Status:
Completed
Approval Process for Gateways / Prevent Personal Gateways
Build an approval process for Gateways before they become Active on a tenant. The approval process would be manged by the Power BI Admin. This approval process could be a feature the Power BI Admin can enable / disable, defaulting to disabled to retrain backward compatibility. Current reality allows anyone with a Pro License to push any internal data they have access too to the service. With the right permission they can then push this data public without restrictions. This feature is a must have in an Enterprise concerned about how data is used / managed. Just because some has access to a data source doesn't mean Data Admin wan't this source to become publicly available via Power BI Service.
26 Comments
- petershNew MemberThere are a large number of governance and data security issues which need to be addressed. This was one we had not considered but is quite valid and concerning.
- noellevineNew MemberI like Casey's idea of a simple tenant setting that will enable/disable personal gateways. The individual approval process requested by Ray sounds great but I would imagine Casey's idea is faster for the Power BI team to implement.
- mark_evans1New MemberThis is a MUST for our org to use Power BI at an enterprise level. Power BI Admin console does not provide enough audit and controls for admins.
- russell_meyerNew MemberI am in the same boat as others...while office 365 auditing has kept the wolves at bay, we still need the ability to prevent personal gateways, approve who can do a gateway (or whitelist users), and be able to see settings of all gateways for reporting/auditing purposes. I know gateways are not 100% a BI resource and is available for use with other PowerApps, should it be spun off to its own team so that concerns like the ones mentioned below can be corrected? I have been waiting almost a year like Ray and no mention of these security issues being addressed.
- matthew_harris1New MemberThis is a big security hole for us. We have an enterprise gateway, which allows us to see what data sources are being accessed and control access (which is great), but this all goes out the window because anybody in the company can install a personal gateway. We don't know what data is flying around the place. Appreciate the flexibility is great for some organizations, but not ours. We please need a way to disable personal gateways at the organizational level.
- pbiideas1New MemberThis is a major data security issue. I can't believe Microsoft would release a functionality like this without giving Admin's a way to control it. This can lead to potential data leaks all over a company and has me reevaluating our Power BI Subscriptions.
- cassandra_cannoNew MemberThis really needs to be resolved. If admins cannot control this, we are risking security and data integrity issues.
- michael_ibarraNew Member'+1. This is a serious security flaw that needs at a minimum, the ability to be turned on and off at the tenant level.
- jordan14New MemberLack of this kind of feature is probably going to result in a lot of my clients just blocking the power bi service.
- bhoomi_dasariNew MemberThis admin control would be helpful, as we are supporting the organization through enterprise gateways, but once we have seen people creating personal gateways causing security and data integrity issues.
Recent ideas
Invoke Pipeline Task - Workspace Identity Authentication
Currently, the Fabric Data Factory Invoke Pipeline task uses the user's credentials who saved the pipeline to then authenticate to the Azure Data Factory to execute the ADF pipeline. When that user'...dzebrowitz4 hours agoAdvocate IPlanned1.8KViews61likes5CommentsFabric Pipeline should run as workspace identity
Currently, Microsoft Fabric pipelines run under the identity of the last user who modified them, which can cause disruptions when tenant administrators make changes to security policies, such as enab...pellitteris4 hours agoAdvocate IINew1.4KViews27likes3CommentsBring Back separating Power BI artifacts on a per web page basis
Previously, the ability to have different artifacts open on different web tabs was enabled. This was beneficial if you wanted to differentiate what environments you were in, working across three diff...zoe-dean5 hours agoNew MemberNew53Views8likes0CommentsREST API Should expose credentials used in connections
When a consultant leaves a client, it's important to clean up any connections that may have the consultants credentials embedded within. I'm able to use the Fabric CLI to get the managed connections ...PeterDaniels6 hours agoAdvocate IIINew19Views7likes0CommentsExpose full activity-level error details in Workspace Monitoring Eventhouse
Microsoft Fabric Workspace Monitoring exposes activity-level pipeline telemetry in FabricDataPipelinesActivityRunsLogs, including PipelineRunId, OperationId, ActivityIterationCount, ActivityName, Act...MarcoOnnis6 hours agoNew MemberNew3Views0likes0Comments