Information
This setting blocks the use of resource key based authentication. The Block ResourceKey Authentication setting applies to streaming and PUSH datasets. If blocked users will not be allowed send data to streaming and PUSH datasets using the API with a resource key.
The recommended state is Enabled.
Rationale:
Resource keys are a form of authentication that allows users to access Power BI resources (such as reports, dashboards, and datasets) without requiring individual user accounts. While convenient, this method bypasses the organization's centralized identity and access management controls. Enabling ensures that access to Power BI resources is tied to the organization's authentication mechanisms, providing a more secure and controlled environment.
Impact:
Developers will need to request a special exception in order to use this feature.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Ensure ResourceKey Authentication is Enabled:
Navigate to Microsoft Fabric https://app.powerbi.com/admin-portal
Select Tenant settings.
Scroll to Developer settings.
Set Block ResourceKey Authentication to Enabled
Default Value:
Disabled for the entire organization