Supplies are limited. Contact info@espc.tech right away to save your spot before the conference sells out.
Get your discountScore big with last-minute savings on the final tickets to FabCon Vienna. Secure your discount
I posted this in the community forum and am now reposting it here at the advice of a Super User response.
While testing the "Preview" toggle of Copilot within Power BI Service, I observed that it queries the dataset directly to provide answers, unlike the previous method that relied on page visuals. This raises a potential security issue.
During today's test with a user who had Row-Level Security (RLS) applied to two reports, I noticed a concern. The user, who should only access data for a specific customer (say, Customer ABC), and whose report visuals only display data for that customer, was able to retrieve data for Customer XYZ when querying Copilot, even though they should not have access to that information.
This issue occurs only when the "Preview" toggle is active. If the toggle is off, and they inquire about Customer XYZ, there is no response. Additionally, I found that Copilot cannot utilize table relationships to identify rows related to Customer XYZ if the report lacks a customer column and instead uses an Account Number or a similar identifier. However, if a user knows the data structure in a report, they can query information they shouldn't access.
Is there an ongoing development for a solution, or is there a way to prevent this issue other than disabling Copilot at the Tenant level?
Thank you in advance for any assistance you may be able to provide us in this matter, it is greatly appreciated.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.