Forum Discussion
Power BI Security concerns
Background:
I'm working on a project for organization that embeds Power BI reports in a corporate portal (Embed for organization scenario). The workspaces containing these reports are hosted on Fabric capacity. End users only have Free Fabric licenses, which are required to access the reports on the corporate portal.
We need to prevent end users from seeing other usernames or emails within our tenant due to the organization compliance and security requirements.
Security Concerns:
In Power BI, we cannot prevent end users from logging into PowerBI.com with their AAD credentials. Login to PowerBI.com allows them to access PII (personally identifiable information) such as other users’ names and emails, which they should not have access to. 2 examples:
- After logging into PowerBI.com, end users can click the Monitor menu on the left bar and see the first and last names of the individuals who published the report datasets, the refresh status, and other details. This information should not be accessible to them.
- Users can initiate the creation of a new workspace and follow the steps to change the workspace contact. During this process, they gain access to the entire tenant user list, including first names, last names, and emails. Although they cannot complete the workspace creation process, they still access sensitive information that should not be available to them. This is a critical security vulnerability for the organization.
I would appreciate any feedback on whether there are any settings I might be missing that could prevent these issues.
4 Replies
- lbendlinSuper User
This here is the wrong place to discuss these issues. Have your legal team talk to Microsoft's legal team about this.
- lbendlinSuper User
If you have a Pro license you can open a Pro ticket at https://admin.powerplatform.microsoft.com/newsupportticket/powerbi
Otherwise you can raise an issue at https://community.fabric.microsoft.com/t5/Issues/idb-p/Issues .