9.1.9 Ensure 'Block ResourceKey Authentication' is 'Enabled'

Information

This setting blocks the use of resource key based authentication. The Block ResourceKey Authentication setting applies to streaming and PUSH datasets. If blocked users will not be allowed send data to streaming and PUSH datasets using the API with a resource key.

The recommended state is Enabled.

Rationale:

Resource keys are a form of authentication that allows users to access Power BI resources (such as reports, dashboards, and datasets) without requiring individual user accounts. While convenient, this method bypasses the organization's centralized identity and access management controls. Enabling ensures that access to Power BI resources is tied to the organization's authentication mechanisms, providing a more secure and controlled environment.

Impact:

Developers will need to request a special exception in order to use this feature.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Ensure ResourceKey Authentication is Enabled:

Navigate to Microsoft Fabric https://app.powerbi.com/admin-portal

Select Tenant settings.

Scroll to Developer settings.

Set Block ResourceKey Authentication to Enabled

Default Value:

Disabled for the entire organization

See Also

https://workbench.cisecurity.org/benchmarks/15279

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: microsoft_azure

Control ID: 529c2cd5b772ecbaf6b48c45a3c2ecb43ea86a4e2925ea4707b82c9cc5aa250c