9.1.4 Ensure 'Publish to web' is restricted

Information

Power BI enables users to share reports and materials directly on the internet from both the application's desktop version and its web user interface. This functionality generates a publicly reachable web link that doesn't necessitate authentication or the need to be an AAD user in order to access and view it.

The recommended state is Enabled for a subset of the organization or Disabled.

Rationale:

When using Publish to Web anyone on the Internet can view a published report or visual. Viewing requires no authentication. It includes viewing detail-level data that your reports aggregate. By disabling the feature, restricting access to certain users and allowing existing embed codes organizations can mitigate the exposure of confidential or proprietary information.

Impact:

Depending on the organization's utilization administrators may experience more overhead managing embed codes, and requests.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Restrict Publish to web:

Navigate to Microsoft Fabric https://app.powerbi.com/admin-portal

Select Tenant settings.

Scroll to Export and Sharing settings.

Set Publish to web to one of these states:

State 1: Disabled

State 2: Enabled with Choose how embed codes work set to Only allow existing codes AND Specific security groups selected and defined

Important: If the organization doesn't actively use this feature it is recommended to keep it Disabled.

Default Value:

Enabled for the entire organization

Only allow existing codes

See Also

https://workbench.cisecurity.org/benchmarks/15279

Item Details

Category: PLANNING, SYSTEM AND SERVICES ACQUISITION

References: 800-53|PL-8, 800-53|SA-8

Plugin: microsoft_azure

Control ID: ec310bb6cbd221f6da5f9963a75fce9eadcbae44ed2ad7e295b956b8e254848a